Cyber Security Lead

Please login or register as jobseeker to apply for this job.

TYPE OF WORK

Part Time

WAGE / SALARY

$115

HOURS PER WEEK

15

DATE UPDATED

Jul 22, 2026

JOB OVERVIEW

Company: Philoware Limited (Constituency.ie) •
Location: Remote (IE/UK/EU),
Commitment: 10–15 hrs/week (initial 6-month contract, extendable)
Reports to: Founder (Jason)
Works with: Backend Developer (Rab), Compliance Consultant (Jerald)

Mission

Safeguard Constituency.ie against threats and lead the practical security work required to achieve and maintain ISO/IEC 27001 certification—while supporting GDPR compliance across a cloud-hosted civic-tech platform used by citizens and public representatives.

Our environment

Frontend: JavaScript (Next.js)

Backend: Python (Django)

Database: PostgreSQL

Cloud: AWS (Ireland/eu-west-1) — EC2 (app), RDS (DB), S3 (files)

Mandatory 2FA, public/private case workflows, in-app chat, profanity/threat filtering

Key responsibilities

Security Architecture & Hardening (AWS)

Implement and maintain AWS controls: IAM least-privilege, KMS CMKs, CloudTrail, Config, GuardDuty, Security Hub, WAF, Shield (Std), S3 Block Public Access, RDS encryption & backups, VPC and security groups.

Define and monitor CSP/HTTP security headers, TLS configuration, secrets management (AWS Secrets Manager/SSM Parameter Store).

DevSecOps & SDLC

Build CI/CD checks (GitHub Actions) for SAST/DAST/dependency scanning (e.g., Bandit, Trivy, OWASP ZAP), container/image scanning (if used), pre-commit hooks.

Threat-model new features; review PRs for security implications; maintain a secure coding standard for Next.js/Django.

Vulnerability & Patch Management

Operate a monthly vulnerability cycle: triage, remediate, verify, and report on risks (OWASP Top 10, misconfigurations, dependency CVEs).

Monitoring, Detection & I ---------- Response

Establish centralised logging and alerting (e.g., CloudWatch / OpenSearch), define alert thresholds, create and rehearse i ---------- runbooks (P1–P3), lead post-i ---------- reviews.

Governance, Risk & Compliance

Maintain the risk register and Statement of Applicability; map controls to ISO 27001:2022 Annex A; support 27701/27017/27018 alignment.

Prepare audit evidence, assist internal audits/management reviews, coordinate external pen tests (CREST) and remediate findings.

Data Protection & GDPR

Support DPIAs (public vs private cases, ID verification, chat), data-flow mapping, access control reviews, retention & disposal schedules; advise on Data Subject Requests.

Security Awareness

Deliver short, practical training for engineering and support; run tabletop exercises twice annually.

Success criteria (first 90 days)

30 days: Baseline AWS hardening review, risk register and control roadmap delivered; CI/CD scanners running; i ---------- runbook drafted.

60 days: Top 10 technical gaps closed; logging/alerts live; initial staff training completed.

90 days: Internal audit readiness pack compiled (evidence library), corrective actions tracked to closure.

Qualifications & experience

5+ years in cloud/application security (SaaS preferred).

Hands-on with AWS security services (IAM, KMS, GuardDuty, Security Hub, WAF, CloudTrail/Config).

Strong knowledge of ISO/IEC 27001:2022 (and ideally 27701/27017/27018), plus GDPR in practice.

Comfortable in Python/Django and modern JS frameworks (Next.js) from a security perspective.

CI/CD security with GitHub Actions; familiarity with SAST/DAST and dependency scanning.

I ---------- response leadership and pen-test coordination experience.

Excellent documentation skills; clear, calm communication with non-security stakeholders.

Nice to have: Terraform/CDK (IaC), AWS Solutions Architect/Security-Specialty, experience with Irish public-sector procurement/security expectations, NIS2 awareness.

Practical details

Engagement: Part-time contractor/consultant.

Location: Remote within IE/UK/EU time zones

Screening: Right-to-work check, references; background check may be required due to the nature of the service.



How to apply

Send a short email with:

CV or LinkedIn, 2) two relevant projects (what you secured and how), 3) your availability per week, 4) in 6–8 bullet points, your proposed first-month security priorities for our stack.

SKILL REQUIREMENT
VIEW OTHER JOB POSTS FROM:
SHARE THIS POST
facebook linkedin