Security Operations Engineer (Europe - Remote)
Mission – Why we exist, what we do, and why we need you
SpotMe is a leading B2B event platform that helps enterprises increase the impact of their events by delivering CRM-connected, high-quality experiences across in-person, virtual, hybrid events, and webinars. With a strong focus on life sciences, SpotMe powers Onomi: an HCP engagement product that enables medical and commercial teams to run impactful congresses, symposia, advisory boards, and webinars. Together, SpotMe and Onomi turn events into a company’s most effective engagement channel.
This role sets and runs the security configuration of the company across different tools we use.
This position is the ideal role for someone who wants to raise the level of IT security in an environment where it carries real weight. Our customers are enterprises, and more than half a million healthcare professionals engage on Onomi every month. How our own accounts, laptops and tools are secured is part of that picture rather than a back-office concern. This is not about one access request or one control, it is about lifting the IT layer that everything else sits on.
As a Security Operations Engineer, you will be reporting to the Chief Security and Trust Officer and you will spend roughly:
- 35% Identity, access and lifecycle. Joiners, movers and leavers, access requests and approvals, associate access, security hygiene across our SaaS tools, access reviews. Google Workspace is our identity layer.
- 20% Endpoint management and protection. Implementing both across our macOS fleet, then keeping the fleet in a known state and triaging what the tooling reports once it is live.
- 30% Security controls and access models inside our tools. Around a dozen SaaS applications, each with its own permission model, its own security controls, its own limits on what can actually be enforced, and its own logging capability. You will manage how each should be configured, design the role and permission structures inside them, work out what a given plan tier does and does not allow, and know where a tool is blind so we can compensate elsewhere. This also covers the alerts and logs from the tools we already have, including threat intelligence.
- 15% Building internal tooling. Access reporting, cross-tool investigation, and a small, deliberately tuned detection layer. Built primarily with Claude Code, jointly with the CSTO, against a written specification that already exists.
This is an IT security role covering identity, device management and internal telemetry, with a real build component. It sits in security rather than IT because the work is judged on risk rather than on service.
The role is both preventive and reactive. Most of it is preventive: closing gaps before anyone else finds them, and building the visibility that shows you where they are. But when a security event happens, you are part of the response, and security events do not keep office hours. This is not a shift pattern or a formal on-call rotation, and it is not frequent.
Objectives - The problems you will solve
In your first 1 month:
- You have a complete inventory of our tools and of how access to each one is granted and removed.
- You know which accounts exist across those tools and which of them map to a real person.
- You run onboarding, offboarding and access requests independently, without escalation.
- You have given us your first read on the environment: the three or four things you would fix first, why each one matters, and what it would take.
After 3 months:
- You have a view of the security settings in each cloud/SaaS tool we use, what each is capable of enforcing, and what it currently enforces.
- You have recommended the changes worth making in priority order, and the first of them are already applied.
- You have produced the plan and the recommendation for the new endpoint management and protection: the options, the obstacles we will hit, and how you would get past them.
After 6 months:
- New endpoint management and protection are running across the fleet and you can report coverage.
- There is one place that shows who has access to what across all tools, and access reviews run from it and produce the evidence export.
- The new Security Dashboard is built to the point where a real investigation can be done in it.
What you need to be great at:
- Working across multiple areas of security rather than specialising in one, in combination with “standard IT activities”. Identity, endpoints, tool configuration and logging all sit in this role, and none of them get a dedicated person.
- Judging the balance between security that limits people and what the business actually needs to get done. Knowing which control is worth the friction and which one will simply be worked around.
- Because of our business, users often need immediate action. Some tickets can wait a week and some arrive as a Slack message because a customer event is happening now. Judging which is which, without treating everything as urgent or making people escalate to get attention, is a daily call.
- Google Workspace as an identity platform, including SSO and SAML app integration, groups and org units, admin roles and delegation, context-aware access, the security and admin audit logs and the alerts built on them
- Understanding the usage of APIs, minimally knowledge around REST and HTTP methods status codes, authentication via API keys, OAuth 2.0
What we are most curious about:
- How you decide between buying and building, what you base it on, and how the decision survives in real life.
- Where you think the effort really belongs when it comes to security settings and capabilities, and which attack vectors matter most for a company like ours.
- Your process for choosing security tools, what you rule out early, and what you insist on testing before anything gets signed.
- How you adapt your views and actions based on publicly known security incidents and breaches.
- How you handle the human pressure to override security requirements.
- A detection or an alert you switched off, and what convinced you.
SpotMe recruits, compensates, and promotes regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, parental status, or veteran status.