Company Description
At Fonoa, we are transforming how digital-first companies stay tax compliant. We provide simple and modular API solutions that easily integrate into any existing workflow. Through our technology-first approach, we reduce manual processes, increase compliance, and lower operational costs when transacting and scaling internationally.
We are solving one of the largest yet unsolved problems in global e-commerce. Our tax automation software enables companies such as Uber, Zoom, Booking.com, Squarespace, and Rappi to expand their international offerings more quickly and remain tax-compliant.
Position Overview
As Fonoa continues to scale globally, we are looking for a Security Engineer to take ownership of our internal security posture and help us move from foundational security practices to a more mature, proactive, and automated security function.
This role will focus on building detection and incident response capabilities, improving visibility across our systems, and embedding security best practices across IT and the wider organisation. You will work closely with IT Support, Engineering, Legal, People Ops, and other teams to ensure Fonoa’s systems, data, and people are protected.
This is a hands-on role for someone who enjoys building security programs from the ground up, taking initiative, and solving problems at their root, not just reacting to alerts or tickets.
Key Responsibilities
Security Foundations
Own and continuously improve Fonoa’s information and cybersecurity posture across endpoints, identities, and SaaS tools
Define, document, and maintain security policies, standards, and controls
Ensure strong access controls, encryption, and secure configuration baselines
Detection & Incident Response
Design, build, and maintain an end-to-end incident response framework
Develop detection and alerting capabilities across identity, endpoint, and SaaS environments
Lead or coordinate security incidents, including root cause analysis and post-incident reviews
Participation in the on-call rotation schedule
Security Automation
Implement and manage security automation and SOAR-style workflows
Reduce manual security tasks through automation and repeatable playbooks
Improve response times and consistency through tooling and process improvements
Collaboration & Enablement
Partner closely with IT Support on endpoint, device, and access security
Work with other engineering functions to support secure tooling, integrations, and practices
Support compliance activities, audits, and customer security questionnaires
Act as a security subject-matter expert for internal stakeholders
Qualifications
2+ years of hands-on experience in Information Security, Cyber Security, or a closely related role
Experience designing, implementing, or operating incident response processes
Familiarity with security detection, monitoring, and response tooling
-
Strong understanding of:
Identity and access management
Endpoint security
SaaS security best practices
Ability to work independently, take initiative, and operate in ambiguous environments
Bonus Points If You Have
Experience with security automation or SOAR tools
Scripting or automation experience (Python, Go, Shell)
Experience supporting compliance frameworks or audits
What Success Looks Like
A documented, tested, and operational incident response process is in place
Improved visibility into security risks, assets, and access with a centralised alerting system
Reduced manual security work through automation
Security is seen as a proactive, trusted partner across the company
Why Join Us
Opportunity to build and shape security at a fast-growing, global startup
High ownership and impact in a critical function
Work with a collaborative, motivated, and experienced team
Competitive compensation and benefits
Flexible working arrangements
If you’re passionate about building security the right way, enjoy taking ownership, and want to help scale a modern, security-conscious organisation, we’d love to hear from you.
As part of the recruitment process at Fonoa, we process your personal data in accordance with our Privacy Notice for Job Applicants. This notice explains how and why your data is collected and used, and how you can contact us if you have any concerns.
Sponsored