
Security Engineer – Fractional
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in Philippines, +1 more country.
• Create a comprehensive 12-month security roadmap that balances enterprise-level expectations with the agility of software outsourcing.
• Develop and prioritize a risk register informed by business impact.
• Guide the IT Manager and transform technical responsibilities into effective security controls.
• Set up security office hours and provide training for lead developers on secure coding practices, OWASP standards, and DevSecOps methodologies.
• Ensure compliance with data handling regulations such as GDPR, the Philippines Data Privacy Act, and the Australian Privacy Act.
• Standardize the approach to client security questionnaires.
• Compose and enact policies for Incident Response, Access Control, and Business Continuity/Disaster Recovery (BCP/DR).
• Supervise the selection and implementation of Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), and vulnerability scanning tools.
• Define an appropriately scaled security framework for the portfolio companies of Arcanys Ventures.
• Assess technical security and data privacy risks associated with potential venture investments.
• Provide guidance to startups on security policies, data privacy compliance, and the principles of Security by Design.
• Demonstrated hands-on expertise in security engineering, cloud security, application security, or DevSecOps.
• Ideally experienced in software, technology, or outsourcing sectors.
• Strong technical background across the Software Development Life Cycle (SDLC), CI/CD security, AWS/GCP, identity and access management, vulnerability management, and endpoint security.
• Capability to independently evaluate and verify security controls, AWS/GCP configurations, GitHub repositories, CI/CD pipelines, and security tools.
• Experience in providing actionable security recommendations.
• Familiarity with client security assessments, security questionnaires, audits, or vendor evaluations.
• Experience with governance, risk management, SOC 2, ISO 27001, GDPR compliance, and related areas is advantageous.
• Preferred security certifications include AWS/GCP, CISSP, CISM, CISA, or equivalents.
• Experience collaborating with distributed teams across Europe, Asia, and Australia, as well as working with early-stage startups is a plus.
• Support for well-being.
• Trust and autonomy in your work.
• Engage exclusively in projects that the company is passionate about.
GardaWorld Federal Services
Cherokee Federal
Foundant Technologies
FRSecure
Get handpicked remote jobs straight to your inbox weekly.