Security Engineer (Fractional)

location_onUnited Kingdomschedule4 hours ago
homeWork style:Remote
badgeEmployment:Part-time
Apply Nowopen_in_new

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer (Fractional) based in United Kingdom.

This is a part-time security engineering opportunity focused on elevating an established technology organization toward an enterprise-grade security posture.

You will shape the security strategy, establish practical controls, and prioritize initiatives according to business risk and impact.

The role combines hands-on cloud and application security with compliance, incident readiness, policy development, and security governance.

You will work closely with IT leadership and engineering teams, providing mentorship and helping developers adopt secure coding and DevSecOps practices.

You will also support cross-border privacy and security requirements across European, Asian, and Australian operations.

Beyond the core organization, you will advise early-stage ventures on right-sized security frameworks and help assess security risks during investment processes.

This role is ideal for an experienced security professional who can operate independently, translate technical risks into practical actions, and balance strong security standards with business agility.

Accountabilities

  • Develop and maintain a 12-month security roadmap that balances enterprise-grade security expectations with the speed and flexibility of a technology-focused organization.
  • Establish and maintain a security risk register, assessing risks based on business impact and prioritizing remediation efforts accordingly.
  • Mentor the IT Manager and help translate day-to-day technical activities into measurable security controls and improvements.
  • Establish security office hours and provide practical guidance to engineering teams on secure coding, OWASP principles, DevSecOps, and security best practices.
  • Assess and strengthen security controls across cloud infrastructure, development environments, repositories, CI/CD pipelines, identity and access management, and endpoint environments.
  • Ensure data-handling practices align with applicable privacy and security regulations, including GDPR, the Philippines Data Privacy Act, and the Australian Privacy Act.
  • Standardize and improve responses to client security questionnaires, audits, and vendor assessments to support efficient business development and sales processes.
  • Develop and implement practical security policies covering areas such as incident response, access control, business continuity, and disaster recovery.
  • Guide the selection and implementation of essential security technologies, including endpoint detection and response, SIEM, vulnerability management, and related security tooling.
  • Establish a right-sized security framework for early-stage portfolio companies, helping founders implement foundational controls without unnecessarily slowing growth.
  • Evaluate technical security, privacy, and data protection risks during assessments of potential new ventures and investment opportunities.
  • Act as a fractional security advisor to startups, supporting GDPR and data privacy compliance, security policies, and the development of a security-by-design culture.
  • Requirements

    • Proven hands-on experience in security engineering, cloud security, application security, DevSecOps, or a closely related discipline, ideally within software, technology, SaaS, or outsourcing environments.
    • Strong technical understanding of the software development lifecycle, CI/CD security, cloud platforms such as AWS and GCP, identity and access management, vulnerability management, and endpoint security.
    • Ability to independently assess and validate security controls, including cloud configurations, GitHub repositories, CI/CD pipelines, and security tooling.
    • Strong ability to translate technical findings into practical, prioritized recommendations that teams can realistically implement.
    • Experience handling client security assessments, security questionnaires, audits, vendor assessments, or similar external security reviews.
    • Knowledge of governance, risk management, SOC 2, ISO 27001, GDPR, and related compliance frameworks is highly valuable.
    • Relevant security certifications such as AWS or GCP certifications, CISSP, CISM, CISA, or equivalent credentials are preferred.
    • Experience working with geographically distributed teams across Europe, Asia, and Australia is an advantage.
    • Previous experience supporting early-stage startups or high-growth environments is a plus.
    • Strong communication, mentoring, and stakeholder-management skills, with the ability to work effectively with technical teams, leadership, and business stakeholders.
    • Comfortable working independently in a fractional capacity, prioritizing high-impact security initiatives without unnecessary complexity.
    • Benefits

      • Fully remote working arrangement.
      • Part-time, fractional engagement designed to provide flexibility.
      • Opportunity to shape and elevate an organization's security posture toward enterprise-grade standards.
      • Broad exposure across cloud security, application security, DevSecOps, privacy, compliance, governance, and incident management.
      • Opportunity to mentor engineering and IT professionals and influence security culture across distributed teams.
      • Exposure to startup environments and the opportunity to advise early-stage ventures on practical security foundations.
      • Opportunity to contribute to security assessments of potential investment opportunities.
      • Flexible, autonomy-focused working culture built around trust and meaningful contribution.
      • International collaboration across Europe, Asia, and Australia.
      • Opportunity to balance robust security practices with practical business and engineering needs.
How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

Skills mentioned


Recruitment
United Kingdom

Jobgether is a Belgium-based, AI-powered remote-work job platform founded in 2020 in Brussels. It aggregates and enriches large volumes of remote and flexible job listings from many employers and matches candidates to roles; it is a job aggregator rather than the hiring employer.

Apply for this job

Use the application link supplied with this listing to apply to jobgether. Check the destination before entering personal information.

Apply Nowopen_in_new