The role
Security is close to the core of what airlock sells. We're looking for someone who can help us strengthen that foundation, hands-on.
This is our first dedicated security role, working directly with the founders and our external compliance partner.
Not advisory. Not a full-time security function squeezed into one day.
What you'll own
First priorities
- Get us ready for ISO 27001 certification.
- Review our identity and authorization surface.
- Check tenant isolation and key security assumptions.
- Scope and coordinate our first independent penetration test.
Ongoing
- Triage security findings and benchmark drift.
- Run recurring ISMS controls and access reviews.
- Support security questionnaires and selected customer security calls.
- Help us improve our security posture as the platform grows.
Later topics may include
- AI-agent and MCP-specific threat modeling.
- Network controls.
- BYOK.
- SOC 2 readiness.
- DORA readiness, for our customers in financial services.
What success looks like
- 3 months: the ISO 27001 gap analysis is done, the risk register is live, and the identity and authorization review is finished with findings ranked.
- 6 months: internal audit done, first independent pen test run, critical findings fixed, and we're ready for the certification audit.
- Ongoing: security questionnaires answered within 5 working days, from an answer library you keep current.
We can answer customers and auditors with confidence, without overselling where we are.
You
- Strong security engineering background, not just compliance.
- Hands-on ISO 27001 experience.
- Strong AWS security knowledge, especially IAM and KMS.
- Comfortable with OAuth 2.0 and OpenID Connect.
- Able to read infrastructure-as-code.
- Comfortable owning work independently in a small team.
Experience with AI-agent security, MCP, penetration test scoping, SOC 2 or DORA is a plus.
Why airlock
You're joining early enough to have real influence on how we build security into the company and product.
Small team. Real customers. High trust.
You help us build security we can actually defend in front of a CISO.
Practical
- Commitment
- 1 day/week
- Location
- Belgium preferred, remote-friendly
- Reports to
- Founders
- Structure
- Fractional contractor or part-time
- Compensation
- To be discussed
- Start
- To be discussed