← All jobs

Security & Compliance Engineer

About the role

• Support and continuously improve the ISMS, including compliance activities, audit preparation, evidence collection, risk tracking, and remediation follow-up
• Translate security and compliance requirements into practical technical controls and verify their effectiveness
• Implement and operate core security controls in the Microsoft / Entra environment, including MFA, Conditional Access, role-based access, privileged access practices, access reviews, endpoint security, and hardening
• Coordinate operational security activities such as Cyber Defence Center investigations, vulnerability and patch management, incident response, backup/restore security, ransomware resilience, and restore-test evidence
• Integrate security into IT operations, change/release processes, and service management
• Report the security posture using KPIs such as MFA coverage, device compliance, patch status, critical risks, and restore-test success
• Work closely with global IT colleagues, the Cyber Defence Center, and business stakeholders

• Hands-on experience in IT security, M365/Entra administration, endpoint management, IT operations, or a comparable technical role
• Good understanding of Microsoft security concepts, especially identity and access management, endpoint protection, and cloud security
• Basic to solid understanding of ISO 27001 concepts such as risk-based controls, policies, evidence, and audit readiness
• Technical knowledge in several areas such as IAM, endpoint security, secure access, vulnerability management, logging/SIEM, or backup/recovery
• Proactive, structured, and pragmatic working style
• Ability to document clearly and communicate across IT and business
• Ability to follow topics through to closure

• Full-time employment
• Remote work arrangement