> Markdown version of [/jobs/ext/725616-senior-security-engineer-en-fr](https://www.wearedevelopers.com/jobs/ext/725616-senior-security-engineer-en-fr). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer (EN/FR) - **Company:** Semble - **Location:** Paris, France (Remote available) - **Experience:** Expert - **Salary:** €90,000.0 - €100,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Software System Penetration Testing, Software as a Service, Cloud Computing Security, Cyber Security, Continuous Integration, Data Validation, Medical Software, Intrusion Detection and Prevention, Key Management, OAuth, Open Source Technology, OpenID, Open Web Application Security, Systems Development Life Cycle, Zero Trust Network Access, Software Engineering, Systems Integration, Software Vulnerability Management, Data Logging, Large Language Models, Software Security, Kubernetes, Machine Learning Operations, Api Gateway, Devsecops, Serverless Computing, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 29, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=2398adbfd0f8d5af ## About the Role Do you have experience in Security?, Are you a hands-on security professional ready to define what application security looks like in the age of agentic AI? Do you want to work somewhere that treats security as a genuine competitive advantage and a core part of building trustworthy healthcare software? Excited by the challenge of evolving security practice at pace, in an industry where the stakes are real?, * Minimum of 5 years of experience in application security, product security, or a combination of software engineering and security with strong AppSec ownership. * Hands-on experience with Snyk across SCA, SAST, Container, and IaC, including CI/CD integration and policy management. * Strong grounding in modern web and application security: OWASP Top 10, API Security Top 10, and an emerging understanding of the OWASP Top 10 for Agentic Applications. * Practical experience embedding security into Agile workflows and DevSecOps tooling. * Solid understanding of authn/authz patterns, secrets management, encryption, and cloud-native security controls. * Experience with compliance frameworks, particularly ISO 27001. Familiarity with Cyber Essentials+, NHS DSPT, or SOC 2 is a strong advantage. * Practical understanding of AI security risks, including prompt injection, LLM vulnerabilities, and agentic system threats, and how to address them in a product context. * Experience working in a SaaS environment or similarly regulated industry, with an appreciation of the product, engineering, and commercial context that security decisions sit within. * Ability to communicate clearly with engineers, leadership, and occasionally customers, translating complex security risk into clear, actionable language. * Genuine, hands-on AI experience: not curiosity, but practice. We will ask you to speak to specific ways you are already using AI to improve security operations, detection, or engineering workflows. * A track record of maintaining security programmes to a continuously high standard, with audit readiness as a default rather than a periodic event. * A proactive, ownership mindset: you identify gaps, propose solutions, and deliver them without waiting to be told. * Proficiency in the French language (nice-to-have, not mandatory). Desirable * CISSP certification (strongly preferred). * Experience with threat modelling methodologies such as STRIDE or attack trees, and running effective threat model sessions with engineering teams. * Familiarity with API gateways, container orchestration, and software supply chain security. * Experience securing AI-enabled features, ML pipelines, agentic workflows, or MCP-based integrations. * Experience building or maturing a security function within a scaling organisation. * Exposure to healthcare data regulations and NHS security requirements. ## Description You will report directly to the Head of Information Security, working alongside a Senior Technical Support Engineer, and together you will form the senior backbone of the IT Delivery and Security Services team. Security at Semble has until now been carried by a single person. This hire is about building genuine depth and maturity into the function. You will own a broad portfolio of security responsibilities, from application security and secure SDLC enablement to AI governance and security programmes, with significant autonomy to shape how that work gets done. The product is evolving fast. AI is no longer a feature at Semble; it is becoming part of the core architecture. That means the attack surface is changing, the threat model is changing, and the skills required to stay ahead of it are changing too. We are looking for someone who is not just keeping up with that shift but is genuinely excited by it. This is a startup environment: the work is varied, the pace is real, and you will have the opportunity to get your hands on almost everything. There is a meaningful backlog of projects to deliver as we mature the InfoSec function. If you want to define best practice rather than just follow it, this is it. This role is hybrid within France, with occasional travel to our London and Paris office for collaboration and workshops. What you will be doing Application Security and Secure SDLC * Embed security into Agile development by partnering with engineering squads during planning, refinement, and delivery. Be the security voice in the room, not the person who reviews things after the fact. * Define, roll out, and continuously improve secure coding standards, secure design patterns, and developer-friendly guidance that scales across the engineering team. * Run threat modelling for new features and major architectural changes, capturing abuse cases and security requirements early. As Semble builds more AI-powered and agentic capabilities, apply emerging frameworks to ensure new threat surfaces are modelled and mitigated from the outset. * Own SAST, SCA, DAST, container, and IaC scanning pipelines, with Snyk as our primary platform (Snyk Code, Open Source, Container, and IaC). Integrate with CI/CD, manage policies, and maintain a strong focus on developer experience and false-positive reduction. * Triage and manage vulnerabilities end-to-end: classification, SLAs, fix validation, and reporting. * Build frictionless guardrails: pre-commit hooks, secure templates, reference code, and paved paths that make doing the right thing the easy thing. * Deliver targeted training and just-in-time enablement based on findings and stack specifics. Security Architecture and Design * Advise on architecture choices for key product feature developments, including authorisation, secrets and key management, data protection, and zero-trust-aligned designs. * Guide secure API and microservice patterns, including input validation, rate limiting, secure session handling, and token-based security (OAuth 2.0/OIDC). * Review designs for cloud-native services and edge components, ensuring sensible security trade-offs aligned to product goals. * As agentic AI capabilities expand within the product, advise on the security architecture of agent orchestration, tool integrations, memory handling, and MCP (Model Context Protocol) server deployments. AI Security and Governance * Apply and evolve Semble's approach to AI-specific threats: prompt injection, excessive agent autonomy, tool and plugin abuse, AI supply chain risks, and context manipulation. The OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications are your starting point, not your ceiling. * Work closely with the Head of Information Security to develop and maintain Semble's AI governance posture, aligned with ISO 42001 and the evolving regulatory landscape for AI in healthcare. * Assess risks associated with third-party AI integrations, AI-assisted development tooling, and agentic workflows, and implement appropriate mitigations. Security Operations and Threat Management * Monitor, investigate, and respond to security alerts, incidents, and anomalous behaviour across Semble's environment. * Develop and mature threat intelligence capabilities, including vulnerability management, penetration testing coordination, and incident response processes. * Maintain and improve security tooling, logging, and detection capabilities, with an automation-first mindset. * Contribute to incident response runbooks for application-layer and AI-related incidents, and support blameless post-incident reviews to embed learning back into the SDLC. * Contribute to the ongoing improvement of Semble's overall security posture, identifying and addressing gaps proactively. Compliance, Certification and Audit Readiness * Own or co-own the delivery of Semble's compliance programmes, including ISO 27001, Cyber Essentials+, NHS DSPT, and the journey towards SOC 2 readiness. * Support and contribute to ISO 42001 implementation as Semble's AI governance framework matures. * Define and track pragmatic security KPIs: time-to-remediate, coverage, percentage of criticals resolved within SLA, threat model coverage, and audit readiness indicators. * Maintain audit-quality documentation, evidence, and records at all times. Our standard is always audit ready, every day. Customer and Stakeholder Engagement * Support the sales process by responding to customer security questionnaires and due diligence requests with accuracy and confidence. * Occasionally engage directly with customers on security topics, acting as a knowledgeable and credible representative of Semble's security function. * Work with internal stakeholders to ensure security requirements are understood and embedded across the business. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Best Companies to Work For in Paris: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/190-best-companies-to-work-for-in-paris-top-25-companies-in-2023)