SpotMe
Security Operations Engineer (Europe - Remote)
About this role
Mission – Why we exist, what we do, and why we need you SpotMe is a leading B2B event platform that helps enterprises increase the impact of their events by delivering CRM-connected, high-quality experiences across in-person, virtual, hybrid events, and webinars. With a strong focus on life sciences, SpotMe powers Onomi: an HCP engagement product that enables medical and commercial teams to run impactful congresses, symposia, advisory boards, and webinars. Together, SpotMe and Onomi turn events into a company’s most effective engagement channel. This role sets and runs the security configuration of the company across different tools we use. This position is the ideal role for someone who wants to raise the level of IT security in an environment where it carries real weight . Our customers are enterprises, and more than half a million healthcare professionals engage on Onomi every month. How our own accounts, laptops and tools are secured is part of that picture rather than a back-office concern. This is not about one access request or one control, it is about lifting the IT layer that everything else sits on. As a Security Operations Engineer, you will be reporting to the Chief Security and Trust Officer and you will spend roughly: 35% Identity, access and lifecycle. Joiners, movers and leavers, access requests and approvals, associate access, security hygiene across our SaaS tools, access reviews. Google Workspace is our identity layer. 20% Endpoint management and protection. Implementing both across our macOS fleet, then keeping the fleet in a known state and triaging what the tooling reports once it is live. 30% Security controls and access models inside our tools. Around a dozen SaaS applications, each with its own permission model, its own security controls, its own limits on what can actually be enforced, and its own logging capability. You will manage how each should be configured, design the role and permission structures inside them, work out what a given plan tier does and does not allow, and know where a tool is blind so we can compensate elsewhere. This also covers the alerts and logs from the tools we already have, including threat intelligence. 15% Building internal tooling. Access reporting, cross-tool investigation, and a small, deliberately tuned detection layer. Built primarily with Claude Code, jointly with the CSTO, against a written specification that already exists. This is an IT security role covering identity, device management and internal telemetry, with a real build component. It sits in security rather than IT because the work is judged on risk rather than on service. The role is both preventive and reactive. Most of it is preventive: closing gaps before anyone else finds them, and building the visibility that shows you where they are. But when a security event happens, you are part of the response, and security events do not keep office hours. This is not a shift pattern or a formal on-call rotation, and it is not frequent. Objectives