Staff Security Engineer
3 дн. назад
FranceEuropeLeadHybrid
security architecturedata-protectionaccess control
Staff Security Engineer role focused on strengthening security of products, data, and engineering platforms with a hands-on technical approach.
О компании
- Build security platforms, not security processes We are looking for a Staff Security Engineer to strengthen the security of our products, data and engineering platform. This is a highly technical and hands-on role. You will work closely with Engineering teams to continuously harden our systems while helping design the next generation of our security architecture. You will operate across two horizons: Strengthen security today: continuously harden our applications, access controls and data-protection mechanisms against evolving threats. Build the privacy architecture of tomorrow: move beyond traditional perimeter and access-control security by designing systems where sensitive data is cryptographically isolated, minimally exposed, and increasingly usable without being directly reveale
Обязанности
- Identify and reduce high-impact security risks across our applications, APIs and internal tools.
- Strengthen authentication, authorization and access controls.
- Improve the protection of sensitive and personal data.
- Design controls that limit the blast radius of compromised accounts, services or infrastructure.
- Improve security monitoring, auditability and detection of suspicious access patterns.
- Perform threat modelling and targeted security reviews.
- Build reusable security capabilities directly into our engineering platform and development lifecycle.
- Contribute to long-term architectures around data isolation, encryption, tokenisation and privacy-preserving systems.
- Partner with engineering teams to address systemic security risks rather than individual findings.
Требования
- Application and Product Security
- API Security
- IAM, authentication and authorization
- OAuth2 / OIDC, WebAuthn / FIDO2
- RBAC / ABAC and privilege management
- Cloud security
- Cryptography, KMS / HSM and envelope encryption
- Tokenisation and secrets management
- Data Security and Privacy Engineering
- Threat modelling and secure software architecture
- Security monitoring and detection
- What happens if this employee becomes malicious?
- What happens if this backend is compromised?
- What happens if someone dumps this database?
- Can this endpoint be called directly?
- How much data can one account access before we notice?
- Where else does this information get replicated?
- Why do we have this data at all?
- something that needs to be fixed this week;
- something that requires an architectural redesign;
- something cryptographically elegant but operationally unnecessary.
- large-scale SaaS or fintech platforms;
- highly sensitive or regulated data;
- multi-tenant architectures;
- insider risk or data-loss prevention;
- advanced cryptographic or privacy-enhancing technologies.
- Sensitive data is exposed to fewer systems and people.
- Access to sensitive resources is increasingly scoped, attributable and auditable.
- Compromising a single account or service has a limited blast radius.
- Security controls are increasingly enforced by the platform rather than by process.
- Product teams can build secure systems faster and with less friction.
Другое
- This position can be based at our offices in Paris, Toulouse, or Montpellier on a flex-remote basis.