Logo for SpotMe

Security Operations Engineer (Europe - Remote)

Role overview

Qualifications

  • Experience with identity and access management in SaaS environments
  • Knowledge of endpoint protection and management
  • Familiarity with security controls and configuration in various tools
  • Understanding of APIs and basic programming knowledge

Responsibilities

  • Manage identity, access, and lifecycle for SaaS tools
  • Implement and maintain endpoint management and protection for macOS fleet
  • Configure security controls and access models inside various SaaS applications
  • Build internal tooling for access reporting and detection measures

Key facts

  • Remote from: Europe
  • Full time
  • Security Operations Engineer
  • English

Hard skills

Other skills

  • Decision Making
  • Problem Solving

About the company

SpotMe  logo

SpotMe

Computer Software / SaaS

Trusted by Fortune 500 and leading companies, SpotMe is a B2B hybrid and virtual event marketing platform with the tools & production to build amazing customer relationships. With over 2 million users and 400+ customers, G2 and Forrester say they are one of the key contenders in this space. Brands like SAP, Pfizer, and KPMG use SpotMe to drive demand, build connections and grow revenue. The company created in 2001, currently has about 100 employees within its rapidly growing teams. Though headquartered in Lausanne, Switzerland, the team is truly remote with members in more than 58 cities from 10+ different countries. They go to great lengths to make sure everyone is not just online but connected to each other for real. They believe this kind of trust empowers their people to work and live to thrive. What they are looking for They certainly have a hiring bias: they are looking for people who are curious and have grit. These are two core values that they are very deliberate about when bringing new talents on board. And when the entire team has curiosity and grit, everything flows from there.

Company details

Company typeSME
IndustryComputer Software / SaaS
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Mission – Why we exist, what we do, and why we need you

SpotMe is a leading B2B event platform that helps enterprises increase the impact of their events by delivering CRM-connected, high-quality experiences across in-person, virtual, hybrid events, and webinars. With a strong focus on life sciences, SpotMe powers Onomi: an HCP engagement product that enables medical and commercial teams to run impactful congresses, symposia, advisory boards, and webinars. Together, SpotMe and Onomi turn events into a company’s most effective engagement channel. 

This role sets and runs the security configuration of the company across different tools we use. 

This position is the ideal role for someone who wants to raise the level of IT security in an environment where it carries real weight. Our customers are enterprises, and more than half a million healthcare professionals engage on Onomi every month. How our own accounts, laptops and tools are secured is part of that picture rather than a back-office concern. This is not about one access request or one control, it is about lifting the IT layer that everything else sits on.

As a Security Operations Engineer, you will be reporting to the Chief Security and Trust Officer and you will spend roughly:

  • 35% Identity, access and lifecycle. Joiners, movers and leavers, access requests and approvals, associate access, security hygiene across our SaaS tools, access reviews. Google Workspace is our identity layer.
  • 20% Endpoint management and protection. Implementing both across our macOS fleet, then keeping the fleet in a known state and triaging what the tooling reports once it is live.
  • 30% Security controls and access models inside our tools. Around a dozen SaaS applications, each with its own permission model, its own security controls, its own limits on what can actually be enforced, and its own logging capability. You will manage how each should be configured, design the role and permission structures inside them, work out what a given plan tier does and does not allow, and know where a tool is blind so we can compensate elsewhere. This also covers the alerts and logs from the tools we already have, including threat intelligence.
  • 15% Building internal tooling. Access reporting, cross-tool investigation, and a small, deliberately tuned detection layer. Built primarily with Claude Code, jointly with the CSTO, against a written specification that already exists.

This is an IT security role covering identity, device management and internal telemetry, with a real build component. It sits in security rather than IT because the work is judged on risk rather than on service.

The role is both preventive and reactive. Most of it is preventive: closing gaps before anyone else finds them, and building the visibility that shows you where they are. But when a security event happens, you are part of the response, and security events do not keep office hours. This is not a shift pattern or a formal on-call rotation, and it is not frequent.

Objectives - The problems you will solve

In your first 1 month:

  • You have a complete inventory of our tools and of how access to each one is granted and removed.
  • You know which accounts exist across those tools and which of them map to a real person.
  • You run onboarding, offboarding and access requests independently, without escalation.
  • You have given us your first read on the environment: the three or four things you would fix first, why each one matters, and what it would take.

After 3 months:

  • You have a view of the security settings in each cloud/SaaS tool we use, what each is capable of enforcing, and what it currently enforces.
  • You have recommended the changes worth making in priority order, and the first of them are already applied.
  • You have produced the plan and the recommendation for the new endpoint management and protection: the options, the obstacles we will hit, and how you would get past them.

After 6 months:

  • New endpoint management and protection are running across the fleet and you can report coverage.
  • There is one place that shows who has access to what across all tools, and access reviews run from it and produce the evidence export.
  • The new Security Dashboard is built to the point where a real investigation can be done in it.

What you need to be great at:

  • Working across multiple areas of security rather than specialising in one, in combination with “standard IT activities”. Identity, endpoints, tool configuration and logging all sit in this role, and none of them get a dedicated person.
  • Judging the balance between security that limits people and what the business actually needs to get done. Knowing which control is worth the friction and which one will simply be worked around.
  • Because of our business, users often need immediate action. Some tickets can wait a week and some arrive as a Slack message because a customer event is happening now. Judging which is which, without treating everything as urgent or making people escalate to get attention, is a daily call.
  • Google Workspace as an identity platform, including SSO and SAML app integration, groups and org units, admin roles and delegation, context-aware access, the security and admin audit logs and the alerts built on them
  • Understanding the usage of APIs, minimally knowledge around REST and HTTP methods status codes, authentication via API keys, OAuth 2.0

What we are most curious about:

  • How you decide between buying and building, what you base it on, and how the decision survives in real life.
  • Where you think the effort really belongs when it comes to security settings and capabilities, and which attack vectors matter most for a company like ours.
  • Your process for choosing security tools, what you rule out early, and what you insist on testing before anything gets signed.
  • How you adapt your views and actions based on publicly known security incidents and breaches.
  • How you handle the human pressure to override security requirements.
  • A detection or an alert you switched off, and what convinced you.

SpotMe recruits, compensates, and promotes regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, parental status, or veteran status.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Operations Engineer Related jobs

Other jobs at SpotMe

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.