Part Time
$115
15
Jul 22, 2026
Company: Philoware Limited (Constituency.ie) •
Location: Remote (IE/UK/EU),
Commitment: 10–15 hrs/week (initial 6-month contract, extendable)
Reports to: Founder (Jason)
Works with: Backend Developer (Rab), Compliance Consultant (Jerald)
Mission
Safeguard Constituency.ie against threats and lead the practical security work required to achieve and maintain ISO/IEC 27001 certification—while supporting GDPR compliance across a cloud-hosted civic-tech platform used by citizens and public representatives.
Our environment
Frontend: JavaScript (Next.js)
Backend: Python (Django)
Database: PostgreSQL
Cloud: AWS (Ireland/eu-west-1) — EC2 (app), RDS (DB), S3 (files)
Mandatory 2FA, public/private case workflows, in-app chat, profanity/threat filtering
Key responsibilities
Security Architecture & Hardening (AWS)
Implement and maintain AWS controls: IAM least-privilege, KMS CMKs, CloudTrail, Config, GuardDuty, Security Hub, WAF, Shield (Std), S3 Block Public Access, RDS encryption & backups, VPC and security groups.
Define and monitor CSP/HTTP security headers, TLS configuration, secrets management (AWS Secrets Manager/SSM Parameter Store).
DevSecOps & SDLC
Build CI/CD checks (GitHub Actions) for SAST/DAST/dependency scanning (e.g., Bandit, Trivy, OWASP ZAP), container/image scanning (if used), pre-commit hooks.
Threat-model new features; review PRs for security implications; maintain a secure coding standard for Next.js/Django.
Vulnerability & Patch Management
Operate a monthly vulnerability cycle: triage, remediate, verify, and report on risks (OWASP Top 10, misconfigurations, dependency CVEs).
Monitoring, Detection & I
Establish centralised logging and alerting (e.g., CloudWatch / OpenSearch), define alert thresholds, create and rehearse i
Governance, Risk & Compliance
Maintain the risk register and Statement of Applicability; map controls to ISO 27001:2022 Annex A; support 27701/27017/27018 alignment.
Prepare audit evidence, assist internal audits/management reviews, coordinate external pen tests (CREST) and remediate findings.
Data Protection & GDPR
Support DPIAs (public vs private cases, ID verification, chat), data-flow mapping, access control reviews, retention & disposal schedules; advise on Data Subject Requests.
Security Awareness
Deliver short, practical training for engineering and support; run tabletop exercises twice annually.
Success criteria (first 90 days)
30 days: Baseline AWS hardening review, risk register and control roadmap delivered; CI/CD scanners running; i
60 days: Top 10 technical gaps closed; logging/alerts live; initial staff training completed.
90 days: Internal audit readiness pack compiled (evidence library), corrective actions tracked to closure.
Qualifications & experience
5+ years in cloud/application security (SaaS preferred).
Hands-on with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, CloudTrail/Config).
Strong knowledge of ISO/IEC 27001:2022 (and ideally 27701/27017/27018), plus GDPR in practice.
Comfortable in Python/Django and modern JS frameworks (Next.js) from a security perspective.
CI/CD security with GitHub Actions; familiarity with SAST/DAST and dependency scanning.
I
Excellent documentation skills; clear, calm communication with non-security stakeholders.
Nice to have: Terraform/CDK (IaC), AWS Solutions Architect/Security-Specialty, experience with Irish public-sector procurement/security expectations, NIS2 awareness.
Practical details
Engagement: Part-time contractor/consultant.
Location: Remote within IE/UK/EU time zones
Screening: Right-to-work check, references; background check may be required due to the nature of the service.
How to apply
Send a short
CV or LinkedIn, 2) two relevant projects (what you secured and how), 3) your availability per week, 4) in 6–8 bullet points, your proposed first-month security priorities for our stack.