Security Engineer
We're a product-first team on a mission to help grow the cybersecurity culture
We want to instill cybersecurity good practices to employees in a way that's actually effective, and entertaining enough so that employees don't feel like they're working. Think Duolingo but for cybersecurity.
We created a platform to easily rollout a cybersecurity awareness program: the platform sends chat-based 4‑minutes long courses to teams. Following the courses, the other side of the platform simulates phishing attacks, to prepare employees to face hackers, but in a safe environment.
Created in 2020, Riot has raised $45m with leading investors (Y Combinator, Left Lane, Base10, Funders Club and Frst Capital) and is now protecting more than 2 millions employees in over 2,000 companies (including Intercom, Deel, and Deezer) all over the world.
Cybersecurity is everywhere. It's impacting everyone, everyday, and it's becoming the number one risk to any organization, whether it's a small business or a big firm. Yet, the cybersecurity culture in most companies is a disaster. Hackers are leveraging this by targeting the weakest link: the employees. We're on a mission to fix that.
As the second security member in our organization, you will help us reach the next milestone in our security governance strategy, risk management and compliance requirements.
As Riot is aiming to be ISO 27001 and ACN certified in 2026, you will play a crucial role in our compliance strategy and making security a business accelerator .
What you will do
- Build and maintain our GRC framework, including policies, procedures, risk registers, and controls.
- Conduct risk assessments, vendor security reviews, and internal audits.
- Prepare the organization for external audits and certifications (SOC 2, ISO 27001, ACN...), including evidence collection and remediation tracking.
- Provide guidance and awareness to teams on security and compliance best practices.
- Additional security technical projects may be added depending on company needs and growth.