--- title: 'Senior Software Engineer, Security at Hoxhunt' canonical: 'https://feeny.ai/job/senior-software-engineer-security-hoxhunt-helsinki-ydy0k6n2nr8m' type: 'job' last_seen: '2026-09-07' --- # Senior Software Engineer, Security at Hoxhunt - **Company:** Hoxhunt - **Location:** Helsinki, Finland - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-09-02 - **Last confirmed live:** 2026-09-07 - **Apply:** https://jobs.ashbyhq.com/hoxhunt/f41ac394-307d-4a29-ab7a-4d0d79c0ba58 ## Job description ## OUR MISSION AND WHY IT MATTERS We are on a mission to make humans the strongest security layer. Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations. We don't just simulate risks. We build the tools that detect and stop them. ## WHY THIS ROLE MATTERS We're growing fast, over 50% year over year, and our security has to scale with the product: through tooling and code, not headcount. There is no manned SOC here and no plans for one. You will build our security observability: the pipeline that collects, processes and routes security events and logs across our Google Cloud platform, and the detections, alerting and dashboards on top of it. You won't start from zero. Dashboards, audit logging, alerting and a SIEM build-out are underway, and you inherit working security automation: an automated vulnerability triager covering our npm, Maven, Go and Python ecosystems, remediation nudging with CI tests, and the scanning-stack integrations around them. Your job is to take all of it from working to excellent. ## WHAT YOU'LL OWN AND DRIVE - Own the architecture and outcomes of our security event and log pipeline on GCP, and the detections, alerting and dashboards on top of it, engineered as code: reviewed, tested, deployed through CI/CD. - Own and extend our security automation: the vulnerability triager, the remediation nudging automation, and our scanning-stack integrations (GitHub Advanced Security, dependency ownership, issue sync). - Build and improve the tooling our GRC function relies on every day. - Turn recurring manual security work into code, for example automating our churned-customer data-removal monitoring end to end. - Harden our cloud security architecture together with SRE/Platform: trust boundaries, IAM and least privilege, network egress, secrets, infrastructure-as-code. - Drive technical decisions and mentor through code review: act as a multiplier who raises the bar on how security software gets built here. - Contribute to our agentic security tooling (AI-assisted PR review and security review) alongside the team. ## WHAT MAKES YOU THRIVE HERE You'll probably have at least five years of experience building production software, but we care less about how long you've been active and more about what you've built, how it was built, and why it worked. You are comfortable owning outcomes at system scale, turning ambiguous problems into shipped systems, and influencing how adjacent teams build securely. You have - deep, hands-on experience with Google Cloud: IAM, networking, logging and eventing services, containers and Kubernetes. - production experience in at least one of TypeScript, Python or Go, and no fear of the other two. We work in a large monorepo spanning all three. - experience building data or event pipelines, observability systems, or detection tooling, and the instinct to treat all of it as software: version-controlled, reviewed, tested. - a genuine pull toward security. A security title is not required; an engineer who wants their work to protect things is. - AI agents in your daily workflow. We expect you to use modern AI tools everywhere to expand and scale your reach. ## WHO YOU'LL WORK WITH You'll join the Product Security team: a small, high-leverage group whose job is to address any security concern a product team or customer raises. You build the platforms; your teammates run the programs on top of them and cover application security and compliance. You'll work daily with SRE/Platform and the product engineering teams. ## WHAT YOU CAN EXPECT FROM US - Compensation: monthly salary of €6,000–7,500 depending on your experience. You may notice varying salary ranges for roles with similar titles across Hoxhunt; this is because each range is grounded in our role leveling and reflects the seniority, scope, and impact expectations required for that specific role and team, and we operate with a low hierarchy. - Working ways: flexible, hybrid. You are expected to visit the Helsinki office weekly. - High performance meets high humanity: driven, high-impact work with egos left at the door, surrounded by wildly talented colleagues in an environment built on kindness, support, and psychological safety. - Authentic trust and autonomy: we hire great people and trust them to do great work. Real ownership over how our security automation gets built, and the space to decide what's worth automating first. - A product you can be proud of: Hoxhunt's own products are security products. Building security tooling at a company that ships security tooling means your internal work and the product sharpen each other. - The perks that matter: extensive healthcare and our fresh office in Helsinki, complete with a gym and swimming pool. ## RECRUITMENT PROCESS 1. Interview with Talent Acquisition (30 min) 2. Hiring Manager interview with the Director of Product Security (45–60 min) 3. Technical assignment and panel interview (60–90 min) 4. Meeting with the VP of Engineering (30 min) 5. Reference checks and final offer ## ABOUT HOXHUNT Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc. As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day. Be among the first to know about our open positions. Drop your details in our Talent Community, and we will reach out when there is a match! ## About Hoxhunt ## Company Overview - **One-liner**: Hoxhunt provides an AI-powered human risk management platform that transforms employees into a company’s strongest defense against cyber threats through personalized phishing simulations, security awareness training, and incident orchestration. - **Entity Type**: Private (Raised $42.9M total; Series B in 2022) - **Headquarters**: Helsinki, Finland (additional hubs in Minneapolis, USA and Singapore) - **Founded**: 2016 - **Founders**: Mika Aalto (CEO), Pasi Salo, Karri Kurunmäki, Pyry Åvist (CTO) ## Core Business - **Primary Industry**: Cybersecurity – Human Risk Management / Security Awareness Training - **Target Customers**: B2B Enterprise (notable customers include DocuSign, Airbus, AES, Schindler, Nokia) - **Mission**: “To protect individuals and organizations by focusing on the largest risks causing cyber breaches and incidents.” Their core belief: “Security Starts With People.” ## Products & Services - **Human Risk Management Platform** – An AI-native, integrated suite that combines: - **Security Awareness & Phishing Training**: Automated, gamified micro-trainings delivered via email, Slack, or Teams. - **Phishing Simulations**: AI-generated, personalized simulations that mimic real-world attacks. - **Incident Orchestration (SOC Automation)**: AI-powered analysis and triage of user-reported phishing threats, reducing false-positive workload for security teams. - **Analytics & Dashboarding**: Measures behavior change, engagement rates, and risk reduction across the organization. ## Market Standing - **Valuation**: Not disclosed - **Key Metrics**: - **Total Funding**: $42.9M (Series A $3M from Dawn Capital & Icebreaker in 2018; Series B $40M from Level Equity Management in 2022) - **Annual Revenue (FY 2024)**: €15.2M (per Craft.co) - **Users**: 4M+ globally (as of 2026) - **Monthly Activities**: 7M simulations, 500k analyzed threats - **Engagement Rate**: 90%+ | **Failure Reduction**: 75% lower failure rates | **Detect Rate**: 20%+ - **Notable Investors/Partners**: Level Equity Management, Dawn Capital, Icebreaker - **Growth Signals**: - Deloitte Fast50: 4,284% growth over four years (2021) - Named G2 Enterprise Grid Leader (2025), Gartner Representative Provider for SBCP, Frost & Sullivan Competitive Strategy Leadership Award - 40+ internal promotions in one year - Headcount: 270+ employees (20+ nationalities) across three continents ## Competitive Advantages - **Category Pioneer**: Co-created the Security Behavior Change and Human Risk Management category, moving beyond traditional SAT (Security Awareness Training). - **High Engagement**: Gamified, personalized training achieves 90%+ engagement rates, far exceeding industry averages. - **AI-Native Platform**: Automates simulation generation, threat analysis, and training delivery, reducing manual effort for security teams. - **Enterprise Credibility**: Trusted by global brands like Airbus, Nokia, and DocuSign. ## Strategic Focus - **Current Priorities**: Scaling the Human Risk Management platform, expanding into new geographies (notably APAC with a new Singapore hub), and deepening AI capabilities to stay ahead of evolving phishing tactics. - **Growth Direction**: Continue to lead the security behavior change category, drive measurable risk reduction for large enterprises, and grow the user base (targeting millions more users). ## Why Work Here - **Culture**: “High performance, without the sharp edges. High ambition, without the ego.” Emphasis on autonomy, trust, radical candor, and continuous learning. - **Work Setup**: Hybrid/remote varies by role and location; most roles include regular weekly office time. Main hubs in Helsinki, Minneapolis, and a growing APAC hub in Singapore. - **Office Perks (Helsinki)**: Office dogs, coffee bar, building gym & pool, sauna, and social activities (Padel, Dungeons & Dragons, Hoxfit). - **Career Growth**: 40+ promotions in the last year; strong internal mobility and learning culture. - **Hiring Process**: Typically includes an initial chat with Talent Acquisition, a meeting with the Hiring Manager, and a final panel interview (often on-site). Some roles include a take-home assignment. Process aims to be efficient and transparent. ## Sources 1. [hoxhunt.com/careers](https://hoxhunt.com/careers) 2. [hoxhunt.com/about](https://hoxhunt.com/about) 3. [hoxhunt.com/](https://hoxhunt.com/) 4. [craft.co/hoxhunt](https://craft.co/hoxhunt) 5. [topworkplaces.com/company/hoxhunt](https://topworkplaces.com/company/hoxhunt) ## Other roles at Hoxhunt - [Account Executive, DACH (German-speaking)](https://feeny.ai/job/account-executive-dach-german-speaking-hoxhunt-helsinki-xa55pxeq6xks) — Helsinki, Finland - [Senior Software Engineer, New product, Threat Detection, Full-stack](https://feeny.ai/job/senior-software-engineer-new-product-threat-detection-full-stack-hoxhunt-41sd52d3yfw5) — Helsinki, Finland - [Senior Software Engineer, Gamified Phishing Training](https://feeny.ai/job/senior-software-engineer-gamified-phishing-training-hoxhunt-helsinki-0hmt07ky5enx) — Helsinki, Finland - [Software Engineer, Security](https://feeny.ai/job/software-engineer-security-hoxhunt-helsinki-8apnxzjpgdfg) — Helsinki, Finland - [Junior Security Engineer, GRC](https://feeny.ai/job/junior-security-engineer-grc-hoxhunt-helsinki-5k1kh29n956t) — Helsinki, Finland - [Customer Success Manager, Mid-Market](https://feeny.ai/job/customer-success-manager-mid-market-hoxhunt-minneapolis-3w9eha15f2fh) — Minneapolis, MN - [Customer Success Manager, SMB](https://feeny.ai/job/customer-success-manager-smb-hoxhunt-minneapolis-psmz5qgknj3s) — Minneapolis, MN - [Associate Customer Success Manager](https://feeny.ai/job/associate-customer-success-manager-hoxhunt-minneapolis-56fbeb8xqk6e) — Minneapolis, MN - [Senior Product Designer](https://feeny.ai/job/senior-product-designer-hoxhunt-helsinki-7rc4j8b6n88f) — Helsinki, Finland - [Senior Software Engineer, New product, Human Risk, Full-stack](https://feeny.ai/job/senior-software-engineer-new-product-human-risk-full-stack-hoxhunt-helsinki-zbwfg738zxyp) — Helsinki, Finland