Back to jobsRemote
Security Engineer (Fractional)
ArcanysRemoteAugust 19, 2026
Skills
awscicdgcpgdpriso27001soc2
Job Description
Arcanys is a high-growth Swiss software development partner with a 300+ person operation in the Philippines. We are looking for a Security Engineer (Fractional) to transition our security posture to "enterprise-grade". Who you are (Requirements): 1. Proven hands-on experience in security engineering, cloud security, application security, or DevSecOps, ideally in software, technology, or outsourcing environments. 2. Strong technical foundation across SDLC, CI/CD security, cloud platforms (AWS/GCP), identity and access management, vulnerability management, and endpoint security. 3. Able to independently assess and verify security controls, including reviewing AWS/GCP configurations, GitHub repositories, CI/CD pipelines, and security tools, and provide practical recommendations. 4. Experience with client security assessments, security questionnaires, audits, or vendor assessments. Governance, risk management, SOC 2, ISO 27001, GDPR, and other compliance experience is a plus. 5. Relevant security certifications such as AWS/GCP, CISSP, CISM, CISA, or equivalent are preferred. 6. Experience working with distributed teams (Europe/Asia/Australia) and with early-stage startups is a plus. Key Responsibilities: 1. Security Strategy Design a 12-month security roadmap that balances "Swiss Quality" expectations with the agility of a software outsourcing firm. Establish a Risk Register and prioritize remediation based on business impact. 2. Mentorship & Team Elevation Act as the direct mentor to our IT Manager, transforming technical tasks into security controls. Establish "Security Office Hours" to train our lead developers on secure coding (OWASP) and DevSecOps. 3. Cross-Border Compliance Ensure all data handling meets the European GDPR, the Philippines Data Privacy Act and the Australian Privacy Act standards, among other regulations. Standardize our response to client security questionnaires to accelerate the sales cycle. 4. Incident & Policy Management Draft and implement core policies (Incident Response, Access Control, BCP/DR) that are practical, not just theoretical. Oversee the selection and implementation of essential security tools (EDR, SIEM, Vulnerability Scanners) without over-complicating the stack. 5. Venture Portfolio Security & Advisory Define a "Right-Sized" security framework for Arcanys Ventures’ portfolio companies, ensuring they have essential protections without stifling their growth or speed. Assist the leadership team during the investment process by evaluating the technical security and data privacy risks of potential new ventures. Act as a fractional advisor for our startups, helping their founders establish basic security policies, data privacy compliance (GDPR/DPA), and a "Security by Design" culture from day one. Originally posted on Himalayas
Apply for this role
You'll be redirected to the company's application page