Australia, Philippines
1 month agoJob Overview
Job Type
Part TimePay
Not disclosedJob description
- Location:
- Australia, Philippines
- Work arrangement:
- On-site
Role Summary
Arcanys is a high-growth Swiss software development partner with a 300+ person operation in the Philippines. We are looking for a Security Engineer (Fractional) to transition our security posture to "enterprise-grade".
Responsibilities
- Security Strategy
- Design a 12-month security roadmap that balances "Swiss Quality" expectations with the agility of a software outsourcing firm.
- Establish a Risk Register and prioritize remediation based on business impact.
- Mentorship & Team Elevation
- Act as the direct mentor to our IT Manager, transforming technical tasks into security controls.
- Establish "Security Office Hours" to train our lead developers on secure coding (OWASP) and DevSecOps.
- Cross-Border Compliance
- Ensure all data handling meets the European GDPR, the Philippines Data Privacy Act and the Australian Privacy Act standards, among other regulations.
- Standardize our response to client security questionnaires to accelerate the sales cycle.
- Incident & Policy Management
- Draft and implement core policies (Incident Response, Access Control, BCP/DR) that are practical, not just theoretical.
- Oversee the selection and implementation of essential security tools (EDR, SIEM, Vulnerability Scanners) without over-complicating the stack.
- Venture Portfolio Security & Advisory
- Define a "Right-Sized" security framework for Arcanys Ventures’ portfolio companies, ensuring they have essential protections without stifling their growth or speed.
- Assist the leadership team during the investment process by evaluating the technical security and data privacy risks of potential new ventures.
- Act as a fractional advisor for our startups, helping their founders establish basic security policies, data privacy compliance (GDPR/DPA), and a "Security by Design" culture from day one.
Requirements
Who you are (Requirements)
- Proven hands-on experience in security engineering, cloud security, application security, or DevSecOps, ideally in software, technology, or outsourcing environments.
- Strong technical foundation across SDLC, CI/CD security, cloud platforms (AWS/GCP), identity and access management, vulnerability management, and endpoint security.
- Able to independently assess and verify security controls, including reviewing AWS/GCP configurations, GitHub repositories, CI/CD pipelines, and security tools, and provide practical recommendations.
- Experience with client security assessments, security questionnaires, audits, or vendor assessments. Governance, risk management, SOC 2, ISO 27001, GDPR, and other compliance experience is a plus.
- Relevant security certifications such as AWS/GCP, CISSP, CISM, CISA, or equivalent are preferred.
- Experience working with distributed teams (Europe/Asia/Australia) and with early-stage startups is a plus.
- Role:
- Security Engineer (Fractional)
- Job Type:
- Part Time