
About the Role
Pencil is looking for a Security & Trust Specialist / Security Engineer to join at a pivotal moment of growth. This is a hands-on, technical role for someone with a background in desktop support, IT systems administration, or a similar technical operations role who is building a career in security.
You will own the day-to-day security operations that keep Pencil safe — endpoints, identity and access management, cloud, and SaaS security — while lending a hand with practical IT and device issues when needed. You will work directly with the Head of Security & Trust, who will support your growth into audit, compliance, and vendor-risk management over time.
Key Responsibilities
- Administer and secure endpoints (MDM/Intune, patching, encryption, device compliance), assisting with practical desktop support and device issues as needed.
- Own day-to-day identity and access management (IAM): joiner/mover/leaver processes, least-privilege access, and quarterly access reviews across Google Workspace, Microsoft 365, GCP, and other SaaS tools.
- Monitor security alerts and logs, escalate promptly, and investigate/document security events (suspicious logins, compromised credentials, device loss, cloud misconfigurations).
- Support compliance evidence collection in Vanta for SOC 2, ISO 27001, and ISO 42001 alongside the Head of Security & Trust.
- Gather evidence for vendor and customer security questionnaires and escalate issues when appropriate.
- Identify and implement practical improvements to monitoring, alerting, and access controls across cloud and endpoint tooling.
Qualifications
- Background in desktop support, IT systems administration, or a technical operations role, transitioning into or already doing blended IT/security work.
- Hands-on experience with endpoint management (Intune or similar MDM) and Google Workspace or Microsoft 365 administration.
- Familiarity with cloud basics (GCP, AWS, or Azure IAM) and an eagerness to learn cloud security.
- Foundational security certification such as CompTIA Security+, ISC2 Certified in Cybersecurity, or Microsoft SC-900 (or clear evidence of self-directed learning).
- A pragmatic, helpful approach and willingness to alternate between security tasks and hands-on IT troubleshooting.
- Prior exposure to compliance or audit evidence gathering (e.g., Vanta) is a plus.
KPIs & Success Measures
- Access reviews and joiner/mover/leaver tasks completed within SLA with zero access-control audit findings.
- High endpoint compliance rate (encryption, patching, MDM enrollment) across the fleet.
- Swift time-to-close on security incidents and IT/device support requests.
- Quality and completeness of evidence contributed to Vanta and vendor assessments.
Benefits
- 25 days PTO plus public holidays (with a Flexible Time Off scheme)
- Health insurance / private medical cover
- Monthly stipend towards wellness, fitness, and learning and development
- Remote flexibility within your home country in EMEA
- Enhanced parental leave policies (birth, adoption, or surrogacy)
- Access to the Pencil office in The Shard, London (for UK employees)
- Flexible working hours
Timezone overlap
UTC+0–+3
Open to
Europe
Sign in to track applications and earn points.