Software Engineer (Security)

Alan Sa.
Spain
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Continuous Integration Github Python (Programming Language) PostgreSQL Redis TypeScript Software Vulnerability Management Datadog Okta Large Language Models
+4 more
Kubernetes Cloudflare Software Coding Terraform

Job description

Python/Flask, TypeScript, React, React Native, on the coding side. AWS, GCP, Kubernetes, Keycloak, PostgreSQL, Redis, Terraform/Terramate, Datadog, Cloudflare, GitHub Actions on the platform side, all in a monorepo. We deploy daily and believe in distributed ownership - you build it, you own it., 1. Authentication - design, build and operate the authentication stack on top of our self-hosted identity provider. Our goal is to go passwordless with great UX and unblock strategic initiatives relying on this stack.

  1. Encryption - build, evolve and operate our end-to-end encryption component used by our Alan Clinic while keeping it delightful and frictionless for our members.
  2. Security platforms
  3. Secure file exchange - evolve and operate our secure file exchange platform to unblock product/ops teams while bringing support when relevant.
  4. Secure enclave for medical secrecy - contribute to the foundations to isolate and protect highly sensitive medical data without sacrificing usability or delivery speed.
  5. Contribute to engineering-wide security practices by building tools and patterns that help every engineer ship safely (secure CI/CD, vulnerability remediation tooling, AI/LLM safety, etc.).

Requirements

  • 3+ years in full-stack software engineering roles
  • Experience designing systems, APIs, libraries, or frameworks used by other engineers
  • You’ve shipped, owned, and operated production systems (rollouts, on-call, incidents)
  • You’ve shipped secure features, fixed vulnerabilities, designed auth/crypto flows, or championed secure-by-default patterns in past teams
  • You love turning complex problems into elegant secure solutions
  • You care about creating secure-by-design products while keeping delightful experiences

Mindset we value

  • You treat security engineering as product work: engineers and members are your customers, and security should feel effortless.
  • You’re hands-on: writing code is the bulk of the job (Python, TypeScript, Terraform). You ship what you write to production yourself, then operate it: rollouts, alerting, on-call, incident response.
  • You design and communicate: you framing and diagrams, and align product crews on an auth migration as you code. You make complex security tradeoffs legible to non-security engineers.
  • You’re an enabler: you measure your impact by how fast product crews ship secure features without ever consulting you.
  • You build reusable patterns: guardrails, libraries, and secure-by-default abstractions that prevent vulnerabilities at scale.
  • You’re fluent in English (French is not required).

About the company

Alan exists to end the wait. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way.

We are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience.

We are on an incredible journey to build a global leading company, with a unique culture. We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR.

Prevention as the new norm. That’s what we’re building with our team of 800+ people. If it speaks to you, we’re hiring across France, Spain, Belgium, and Canada. And beyond., 2. Application Security is one of its crews. Its mission: build, evolve and operate the foundational security building blocks and secure-by-default patterns that make Alan’s products safe by design, highly available, and easy to ship, while partnering with product teams and Security Operations to reduce real risk without turning security into a bottleneck.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobleads.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters ¡ WWC 2023

3:55 min

Demonstrating semantic routing thresholds with the Redis vector library

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 ¡ LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle ¡ Coffee With Developers

3:42 min

Comparing in-memory and Redis storage for cache scalability

Simone Sanfratello ¡ WWC 2022

Videos

See all

Related articles

See all