HodeiShield: The European TPRM platform with native NIS2, ENS, and DORA
> hodeitek :: talent-ops :: hiring
We're a small, senior offensive- and defensive-security team. A lean team, no filler: everyone owns their slice of the system. If you live between a C2 and a business-readable risk report, this is your place.
See open rolesEvery line is a real opening. Grouped by discipline, each with explicit mode and location.
Right now we're 4 people with 5 open roles. That's not a typo: demand for red team, SOC, and GRC work has grown faster than the team, and launching HodeiShield opened a product and AI line that didn't exist before. Each opening covers a real gap, not a headcount box to tick.
The whole team works in European time zones, with business-hours overlap for what needs real time — debriefs, on-call handoffs, client meetings — and async for the rest of the day. Hybrid roles have an on-site presence in Aretxabaleta or León depending on the role; remote roles work the same way, with no home office required.
Responsibilities
Requirements
Nice to have
Responsibilities
Requirements
Nice to have
Responsibilities
Requirements
Nice to have
Responsibilities
Requirements
Nice to have
Responsibilities
Requirements
Nice to have
Four steps, no trick tests or interview marathons. What we measure is what you'll do in the role.
30 minutes with the person who'd be your direct lead. Role context, your expectations, and questions answered both ways.
An exercise that mirrors the work: a box, a code review, or a threat-hunting case. No whiteboard puzzles or competitive algorithms.
We review your solution together, like an engagement debrief. We care about your reasoning and how you communicate risk, not just the result.
We close with a clear answer, no weeks of silence. Two to three weeks end to end.
There are no middle-management layers: whoever runs a discipline day to day — red team, SOC, GRC, or product — is who you work and learn with from the first engagement. Growth here means real exposure to full cases, from start to finish, not a career plan in a PDF.
Fewer buzzwords, more evidence. These are the signals we value, whether you're offensive, defensive, or platform.
You chain vulnerabilities to real impact and know when to stop. You've written your own exploits or tooling, not just run someone else's.
You move laterally, escalate privileges, and operate against EDR without lighting up the whole console. You understand the telemetry you leave behind.
You write Sigma/YARA rules, hunt over real data, and tell an anomaly from a false positive under pressure.
You automate the repetitive in Python or Go and leave reusable tooling after every engagement, not just a PDF.
A finding with no business narrative is useless. You explain to a CISO why it matters and what to do, without the drama.
You work in critical environments under NDA. Confidentiality and agreed scope are non-negotiable.
What people ask us before applying.
We evaluate by evidence of work — code, reports, tooling, writeups — not by background, gender, age, or disability. If you need a reasonable adjustment at any stage of the hiring process, tell us and we'll make it happen.
Before you apply, see who and what you'd work with
Whether or not there's a role with your name on it, tell us what you do well. We read every message and reply.