> Markdown version of [/jobs/ext/430467-security-engineer-yousign-h-f](https://www.wearedevelopers.com/jobs/ext/430467-security-engineer-yousign-h-f). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Yousign H/F - **Company:** Yousign - **Location:** Paris, France - **Salary:** €53,000.0 - €79,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Build Automation, Fraud Prevention and Detection, Web Applications, Software Security - **Published:** June 19, 2026 - **Apply:** https://www.hellowork.com/fr-fr/emplois/80376791.html ## About the Role You have deep, hands-on expertise in web application and API security, you know attack and defense mechanisms inside out and can spot a vulnerability in a PR or architecture diagram. - You are able to independently run threat modeling sessions, produce clear Decision Records, and translate security risks into actionable requirements for engineering teams. - You have experience managing vulnerabilities across a product perimeter: triaging, prioritising, tracking remediation, and knowing when to accept risk versus escalate. - You have participated in or run BugBounty programs. You understand triage workflows, reward logic, and how to communicate decisions clearly to researchers. - You use AI actively to automate parts of your security work, CVE monitoring, BugBounty triage, report generation, and you think critically about how to integrate AI into existing workflows rather than simply adding tools. - You are comfortable working across domains. Your core is product security, but you are happy to contribute to compliance topics (eIDAS, NIS2, ISO 27001), to fraud detection and prevention, and to the security of a Trusted Zone. Prior exposure to a regulated or Digital Trust environment is a strong plus. - You are genuinely self-sufficient: you pick up a brief, define the scope, and deliver without hand-holding. You are comfortable in ambiguous, fast-moving environments. - You are pragmatic by nature. You do not block for the sake of blocking. You find the right balance between security rigour and business velocity, and you know when to escalate versus when to accept risk. - You communicate clearly and simply. You can explain a complex vulnerability to a non-security engineer in two minutes, and you coach without being preachy. - You are genuinely curious: you follow threat intel, participate in CTFs, and keep your technical edge sharp because you care about the craft. - French at a native or near-native level (C2) is required. English at a professional working level (B2) is required for security research, technical documentation, and communication with international BugBounty researchers., You have deep, hands-on expertise in web application and API security, you know attack and defense mechanisms inside out and can spot a vulnerability in a PR or architecture diagram. - You are able to independently run threat modeling sessions, produce clear Decision Records, and translate security risks into actionable requirements for engineering teams. - You have experience managing vulnerabilities across a product perimeter: triaging, prioritising, tracking remediation, and knowing when to accept risk versus escalate. - You have participated in or run BugBounty programs. You understand triage workflows, reward logic, and how to communicate decisions clearly to researchers. - You use AI actively to automate parts of your security work, CVE monitoring, BugBounty triage, report generation, and you think critically about how to integrate AI into existing workflows rather than simply adding tools. - You are comfortable working across domains. Your core is product security, but you are happy to contribute to compliance topics (eIDAS, NIS2, ISO 27001), to fraud detection and prevention, and to the security of a Trusted Zone. Prior exposure to a regulated or Digital Trust environment is a strong plus. - You are genuinely self-sufficient: you pick up a brief, define the scope, and deliver without hand-holding. You are comfortable in ambiguous, fast-moving environments. - You are pragmatic by nature. You do not block for the sake of blocking. You find the right balance between security rigour and business velocity, and you know when to escalate versus when to accept risk. - You communicate clearly and simply. You can explain a complex vulnerability to a non-security engineer in two minutes, and you coach without being preachy. - You are genuinely curious: you follow threat intel, participate in CTFs, and keep your technical edge sharp because you care about the craft. - French at a native or near-native level (C2) is required. English at a professional working level (B2) is required for security research, technical documentation, and communication with international BugBounty researchers. You have deep, hands-on expertise in web application and API security, you know attack and defense mechanisms inside out and can spot a vulnerability in a PR or architecture diagram. You are able to independently run threat modeling sessions, produce clear Decision Records, and translate security risks into actionable requirements for engineering teams. You have experience managing vulnerabilities across a product perimeter: triaging, prioritising, tracking remediation, and knowing when to accept risk versus escalate. You have participated in or run BugBounty programs. You understand triage workflows, reward logic, and how to communicate decisions clearly to researchers. You use AI actively to automate parts of your security work, CVE monitoring, BugBounty triage, report generation, and you think critically about how to integrate AI into existing workflows rather than simply adding tools. You are comfortable working across domains. Your core is product security, but you are happy to contribute to compliance topics (eIDAS, NIS2, ISO 27001), to fraud detection and prevention, and to the security of a Trusted Zone. Prior exposure to a regulated or Digital Trust environment is a strong plus. You are genuinely self-sufficient: you pick up a brief, define the scope, and deliver without hand-holding. You are comfortable in ambiguous, fast-moving environments. You are pragmatic by nature. You do not block for the sake of blocking. You find the right balance between security rigour and business velocity, and you know when to escalate versus when to accept risk. You communicate clearly and simply. You can explain a complex vulnerability to a non-security engineer in two minutes, and you coach without being preachy. You are genuinely curious: you follow threat intel, participate in CTFs, and keep your technical edge sharp because you care about the craft. French at a native or near-native level (C2) is required. English at a professional working level (B2) is required for security research, technical documentation, and communication with international BugBounty researchers. R1 - TAM Interview with Guillhem Cambiganu (30 min) ## Description Lead the end-to-end security review cycle for all product features: context intake, Decision Records, implementation support, and risk-based unblocking. - Own and operate Yousign's BugBounty program: triage reports, drive remediation, and manage reward decisions. - Identify, prioritise, and track remediation of vulnerabilities across Yousign's product and infrastructure perimeter. - Contribute to the security of the Trusted Zone, and to fraud detection and prevention, alongside the Security & Compliance team. - Support regulatory compliance (eIDAS, NIS2, ISO 27001): help translate requirements into technical controls, and contribute to audits and remediation when needed. - Extend security expertise beyond Product to all company initiatives: assess risks, issue guidance, and maintain a consistent security posture company-wide. - Take part in the team's weekly on-call ("doctor") rotation, and build automation (n8n, AI tooling, alerting) to reduce manual toil. - Raise the security bar across Engineering and beyond: share knowledge, coach teams on secure-by-design practices, and build security awareness., Lead the end-to-end security review cycle for all product features: context intake, Decision Records, implementation support, and risk-based unblocking. - Own and operate Yousign's BugBounty program: triage reports, drive remediation, and manage reward decisions. - Identify, prioritise, and track remediation of vulnerabilities across Yousign's product and infrastructure perimeter. - Contribute to the security of the Trusted Zone, and to fraud detection and prevention, alongside the Security & Compliance team. - Support regulatory compliance (eIDAS, NIS2, ISO 27001): help translate requirements into technical controls, and contribute to audits and remediation when needed. - Extend security expertise beyond Product to all company initiatives: assess risks, issue guidance, and maintain a consistent security posture company-wide. - Take part in the team's weekly on-call ("doctor") rotation, and build automation (n8n, AI tooling, alerting) to reduce manual toil. - Raise the security bar across Engineering and beyond: share knowledge, coach teams on secure-by-design practices, and build security awareness. Lead the end-to-end security review cycle for all product features: context intake, Decision Records, implementation support, and risk-based unblocking. Own and operate Yousign's BugBounty program: triage reports, drive remediation, and manage reward decisions. Identify, prioritise, and track remediation of vulnerabilities across Yousign's product and infrastructure perimeter. Contribute to the security of the Trusted Zone, and to fraud detection and prevention, alongside the Security & Compliance team. Support regulatory compliance (eIDAS, NIS2, ISO 27001): help translate requirements into technical controls, and contribute to audits and remediation when needed. Extend security expertise beyond Product to all company initiatives: assess risks, issue guidance, and maintain a consistent security posture company-wide. Take part in the team's weekly on-call ("doctor") rotation, and build automation (n8n, AI tooling, alerting) to reduce manual toil. Raise the security bar across Engineering and beyond: share knowledge, coach teams on secure-by-design practices, and build security awareness. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The perfect CI/CD React Native pipeline with Fastlane](https://www.wearedevelopers.com/videos/556-the-perfect-ci-cd-react-native-pipeline-with-fastlane) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)