Cybersecurity Engineer - Internal Security

Stoïk
Paris, France
about 1 month ago
Apply on fr.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Languages
English, French
Job source

Tech stack

Microsoft Windows Adobe InDesign Artificial Intelligence Amazon Web Services Apple Mac Systems Software as a Service Cloud Computing Security Code Review Cyber Security Continuous Integration Identity and Access Management Intrusion Detection and Prevention
+13 more
Virtual Private Networks (VPN) Python (Programming Language) Key Management PostgreSQL Cloud Services Information Security Management System Cloud Platform System Software Security Gsuite Hubspot Terraform Static Application Security Testing Golang

Job description

Security at Stoïk is currently a one-person team: the CISO. This role is the second.

This is a deliberately broad role. Roughly half of it sits inside the tech team as its security counterpart; the other half is running our Information Security Management System.

We are not looking for someone who tolerates one half of the job to get to the other. A control written in a policy and never enforced in the pipeline is worthless, and a technical fix nobody can evidence to an auditor is only half done.

You are not expected to ship product code. You are expected to read a pull request, hold your own in a technical debate with a senior engineer, script and automate your own work, and be genuinely welcome in the tech team’s rituals.

The security team also owns the tools the company works on every day: MDM, identity, EDR, VPN and our SaaS estate. At our size those tools are the controls, you configure them and you see the effect immediately.

Technologies: Python, Go, Postgres, AWS / Terraform, CrowdStrike, FleetDM, Vanta, Google Workspace, HubSpot, Anthropic, OpenAI… we are a cloud-native company., * Security engineering with the tech team: act as the security counterpart in design and architecture reviews: threat modelling, risk framing, and recommendations engineers can actually ship. Build secure defaults and guardrails (IaC policies, hardened baselines, paved paths) so that the secure way is the easy way.

  • Vulnerability & exposure management: own it end to end across CI/CD, dependencies, containers, cloud workloads and our own external attack surface; triage, prioritisation, and getting fixes over the line.
  • Security tooling: own and tune our stack (cloud security posture, SAST / SCA, secrets management, endpoint, identity). Fewer tools, better configured, with alerts someone actually reads.
  • ISMS RUN: keep our ISO 27001 certification healthy day to day; control operation, evidence collection, internal audits, management reviews, corrective actions, surveillance audits. Maintain the risk register and drive remediation with the owners who are accountable for it.
  • Corporate & IT security: harden our identity, endpoint and SaaS estate; contribute to access management, joiner-mover-leaver and periodic access reviews; contribute to BCP / DRP testing and to security awareness.
  • IT platform run: administer the tools the company runs on: MDM (FleetDM), Google Workspace and Microsoft 365 / Entra, Apple Business Manager, CrowdStrike, Tailscale, Dashlane and our SaaS estate. Help colleagues when something breaks, and turn each recurring issue into an automation or a better default.
  • AI leverage: evidence collection, control testing, questionnaire responses, log triage, policy drafting, first-pass code review: a large share of this work can be assisted or agent-driven today. You get the tools, the budget and the mandate to build that leverage, and the judgement to know where a human still has to sign.

What you’ll gain in this role

  • High ownership & scope: you are the second security hire, and you hold the admin console. No committee between you and a fix: when you decide a control is needed, you can ship it the same afternoon, and see straight away whether it holds. What you build becomes how Stoïk does security.
  • Real attacker signal: we are a cyber insurer with our own CERT. You will see real incidents, real claims data and real attacker behaviour that most internal security teams never get near, and feed it straight back into our own defences.
  • Both halves of the craft: very few roles let you keep your hands in cloud and application security while owning an ISMS end to end. This one is designed to make you unusually complete, and to grow into a broader security leadership scope as we scale., * “Live” case on an ISMS / compliance scenario, discussed on site rather than sent as homework, 60 min

Requirements

  • Must-Haves:
  • 3-5 years in security engineering, cloud / platform security, product security, or a hybrid technical + GRC role.
  • Solid technical foundations: cloud (AWS ideally), containers, CI/CD, identity, networking. You can script in Python or Go, not to build products, but to automate your own work and integrate tools.
  • The ability to hold both conversations credibly: a design review with a senior engineer in the morning, an audit finding with a director in the afternoon.
  • Comfortable getting hands-on with IT: endpoint and MDM management (mostly macOS), identity administration on Google Workspace and / or Entra, SaaS administration.
  • Fluent French and English, written and spoken. Our internal work is bilingual and our documentation exists in both.
  • Based in Paris, or willing to relocate. Hybrid, with regular time on site.
  • A working relationship with AI tooling that goes beyond curiosity. If you see AI as a threat to your craft rather than a multiplier for it, this is not the right team.
  • Nice-to-Haves:
  • Hands-on ISMS experience, ISO 27001 in particular. You have lived through an audit from the inside, not just read about one.
  • Exposure to insurance, financial services or another regulated sector (DORA in particular).
  • Detection engineering, incident response or offensive security experience.
  • Experience as an early security hire in a scale-up, where nothing is set up yet and that is the point.
  • Certifications (OSCP, CISSP, ISO 27001 Lead Implementer / Auditor, cloud security) are welcome, never a substitute for demonstrated experience., * Cultural fit with Founders (30 min each)

About the company

Stoïk is a cyber insurtech company, and we insure companies up to €1B of turnover. To have better insurance results we have decided to (1) build prevention tools targeted towards the attacks we see, and (2) have our own incident response team (CERT).

We have raised €50M, protect +14000 insureds, are 175 people, and operate in France, Germany, Austria, Spain and BENELUX.

Our CERT handles +1000 incidents / year, including ransomware events and frauds. Our tech team is 45 people and we have built an EASM tool, a phishing simulation platform, AD and Cloud scans, and many more security tools.

We sell security to our insureds. That obliges us to be exemplary on our own, in front of our insureds, our brokers, our reinsurers and our regulator.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on fr.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:20 min

Automating lead generation with HubSpot CRM integration

Felix Augenstein · LIVE

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:10 min

Transitioning agile recruiting teams away from manual spreadsheet management

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · World Congress 2026 Europe

Videos

See all

Related articles

See all