2 часа назад
Cybersecurity Engineer - Internal Security (Cloud/ISO 27001)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity Engineer - Internal Security (Cloud/ISO 27001): Building secure cloud, application, identity, endpoint, and SaaS controls while running Stoïk's ISO 27001 ISMS with an accent on AWS, CI/CD security, vulnerability management, and audit evidence. Focus on designing secure defaults, automating security operations with Python or Go, driving remediation, and balancing technical engineering with governance requirements.
Location: Paris, France; hybrid with regular time on site. Candidates must be based in Paris or willing to relocate to France.
Company
is a cyber insurtech company providing insurance, prevention tools, and incident response services for businesses, with operations across France, Germany, Austria, Spain, and Benelux.
What you will do
- Act as the security counterpart in technology design and architecture reviews, including threat modeling, risk framing, secure defaults, IaC policies, and hardened baselines.
- Own vulnerability and exposure management across CI/CD, dependencies, containers, cloud workloads, and the external attack surface.
- Configure and tune cloud security, SAST/SCA, secrets management, endpoint, and identity tooling.
- Run the ISO 27001 ISMS, including control operations, evidence collection, internal audits, management reviews, corrective actions, surveillance audits, risk management, and remediation.
- Harden identity, endpoints, MDM, SaaS, and access-management processes, while supporting business continuity, disaster recovery, and security awareness.
- Administer company platforms including FleetDM, Google Workspace, Microsoft 365/Entra, Apple Business Manager, CrowdStrike, Tailscale, Dashlane, and the wider SaaS estate; automate recurring support and control tasks with AI where appropriate.
Requirements
- 3–5 years of experience in security engineering, cloud or platform security, product security, or a hybrid technical and GRC role.
- Strong foundations in cloud, ideally AWS, containers, CI/CD, identity, and networking; ability to script in Python or Go for automation and tool integration.
- Ability to communicate credibly with senior engineers on technical designs and directors on audit findings.
- Hands-on experience with endpoint and MDM management, primarily macOS, Google Workspace and/or Entra identity administration, and SaaS administration.
- Fluent French and English, written and spoken, are required.
- Based in Paris or willing to relocate to France; hybrid work with regular on-site presence is required.
Nice to have
- Hands-on ISMS and ISO 27001 experience, including participation in an audit.
- Experience in insurance, financial services, or another regulated sector, especially DORA.
- Detection engineering, incident response, or offensive security experience.
- Experience as an early security hire in a scale-up.
- OSCP, CISSP, ISO 27001 Lead Implementer/Auditor, or cloud security certifications.
Culture & Benefits
- High ownership as the second security hire, with direct access to administrative consoles and the ability to implement controls quickly.
- Exposure to real attacker behavior, incidents, and claims data through 's CERT.
- Opportunity to combine cloud and application security engineering with end-to-end ISMS ownership.
- Access to AI tooling, budget, and autonomy to automate evidence collection, control testing, questionnaire responses, log triage, policy drafting, and code review.
Hiring process
- 30-minute call with the CISO.
- 60-minute on-site technical interview covering cloud and application security and threat modeling with the CISO and a Tech Lead.
- 60-minute on-site live ISMS/compliance case, followed by 30-minute cultural-fit meetings with each founder.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 часа назад
Senior Security Engineer (Cybersecurity)
37 секунд назад
Senior Infrastructure Security Engineer (Cybersecurity)
60 500 - 85 800€
3 дня назад
Senior Security Engineer (SaaS)
Nebius
2 дня назад
Security Solutions Engineer (Cloud Security)
11 часов назад
Application Security Engineer (AI)
7 дней назад