> Markdown version of [/jobs/ext/2323061-cybersecurity-engineer-internal-security](https://www.wearedevelopers.com/jobs/ext/2323061-cybersecurity-engineer-internal-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - Internal Security - **Company:** Stoïk - **Location:** Paris, France - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Adobe InDesign, Artificial Intelligence, Amazon Web Services, Apple Mac Systems, Software as a Service, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Identity and Access Management, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Key Management, PostgreSQL, Cloud Services, Information Security Management System, Cloud Platform System, Software Security, Gsuite, Hubspot, Terraform, Static Application Security Testing, Golang - **Published:** August 7, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=07ea85ce3c63eca2 ## About the Role * Must-Haves: + 3-5 years in security engineering, cloud / platform security, product security, or a hybrid technical + GRC role. + Solid technical foundations: cloud (AWS ideally), containers, CI/CD, identity, networking. You can script in Python or Go, not to build products, but to automate your own work and integrate tools. + The ability to hold both conversations credibly: a design review with a senior engineer in the morning, an audit finding with a director in the afternoon. + Comfortable getting hands-on with IT: endpoint and MDM management (mostly macOS), identity administration on Google Workspace and / or Entra, SaaS administration. + Fluent French and English, written and spoken. Our internal work is bilingual and our documentation exists in both. + Based in Paris, or willing to relocate. Hybrid, with regular time on site. + A working relationship with AI tooling that goes beyond curiosity. If you see AI as a threat to your craft rather than a multiplier for it, this is not the right team. * Nice-to-Haves: + Hands-on ISMS experience, ISO 27001 in particular. You have lived through an audit from the inside, not just read about one. + Exposure to insurance, financial services or another regulated sector (DORA in particular). + Detection engineering, incident response or offensive security experience. + Experience as an early security hire in a scale-up, where nothing is set up yet and that is the point. + Certifications (OSCP, CISSP, ISO 27001 Lead Implementer / Auditor, cloud security) are welcome, never a substitute for demonstrated experience., * Cultural fit with Founders (30 min each) ## Description Security at Stoïk is currently a one-person team: the CISO. This role is the second. This is a deliberately broad role. Roughly half of it sits inside the tech team as its security counterpart; the other half is running our Information Security Management System. We are not looking for someone who tolerates one half of the job to get to the other. A control written in a policy and never enforced in the pipeline is worthless, and a technical fix nobody can evidence to an auditor is only half done. You are not expected to ship product code. You are expected to read a pull request, hold your own in a technical debate with a senior engineer, script and automate your own work, and be genuinely welcome in the tech team's rituals. The security team also owns the tools the company works on every day: MDM, identity, EDR, VPN and our SaaS estate. At our size those tools are the controls, you configure them and you see the effect immediately. Technologies: Python, Go, Postgres, AWS / Terraform, CrowdStrike, FleetDM, Vanta, Google Workspace, HubSpot, Anthropic, OpenAI… we are a cloud-native company., * Security engineering with the tech team: act as the security counterpart in design and architecture reviews: threat modelling, risk framing, and recommendations engineers can actually ship. Build secure defaults and guardrails (IaC policies, hardened baselines, paved paths) so that the secure way is the easy way. * Vulnerability & exposure management: own it end to end across CI/CD, dependencies, containers, cloud workloads and our own external attack surface; triage, prioritisation, and getting fixes over the line. * Security tooling: own and tune our stack (cloud security posture, SAST / SCA, secrets management, endpoint, identity). Fewer tools, better configured, with alerts someone actually reads. * ISMS RUN: keep our ISO 27001 certification healthy day to day; control operation, evidence collection, internal audits, management reviews, corrective actions, surveillance audits. Maintain the risk register and drive remediation with the owners who are accountable for it. * Corporate & IT security: harden our identity, endpoint and SaaS estate; contribute to access management, joiner-mover-leaver and periodic access reviews; contribute to BCP / DRP testing and to security awareness. * IT platform run: administer the tools the company runs on: MDM (FleetDM), Google Workspace and Microsoft 365 / Entra, Apple Business Manager, CrowdStrike, Tailscale, Dashlane and our SaaS estate. Help colleagues when something breaks, and turn each recurring issue into an automation or a better default. * AI leverage: evidence collection, control testing, questionnaire responses, log triage, policy drafting, first-pass code review: a large share of this work can be assisted or agent-driven today. You get the tools, the budget and the mandate to build that leverage, and the judgement to know where a human still has to sign. What you'll gain in this role * High ownership & scope: you are the second security hire, and you hold the admin console. No committee between you and a fix: when you decide a control is needed, you can ship it the same afternoon, and see straight away whether it holds. What you build becomes how Stoïk does security. * Real attacker signal: we are a cyber insurer with our own CERT. You will see real incidents, real claims data and real attacker behaviour that most internal security teams never get near, and feed it straight back into our own defences. * Both halves of the craft: very few roles let you keep your hands in cloud and application security while owning an ISMS end to end. This one is designed to make you unusually complete, and to grow into a broader security leadership scope as we scale., * "Live" case on an ISMS / compliance scenario, discussed on site rather than sent as homework, 60 min ## Related Videos - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)