Назад
Company hidden
2 часа назад

Cybersecurity Engineer - Internal Security (Cloud/ISO 27001)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
France/Spain/Netherlands +4 еще
Релокация
France
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Engineer - Internal Security (Cloud/ISO 27001): Building secure cloud, application, identity, endpoint, and SaaS controls while running Stoïk's ISO 27001 ISMS with an accent on AWS, CI/CD security, vulnerability management, and audit evidence. Focus on designing secure defaults, automating security operations with Python or Go, driving remediation, and balancing technical engineering with governance requirements.

Location: Paris, France; hybrid with regular time on site. Candidates must be based in Paris or willing to relocate to France.

Company

hirify.global is a cyber insurtech company providing insurance, prevention tools, and incident response services for businesses, with operations across France, Germany, Austria, Spain, and Benelux.

What you will do

  • Act as the security counterpart in technology design and architecture reviews, including threat modeling, risk framing, secure defaults, IaC policies, and hardened baselines.
  • Own vulnerability and exposure management across CI/CD, dependencies, containers, cloud workloads, and the external attack surface.
  • Configure and tune cloud security, SAST/SCA, secrets management, endpoint, and identity tooling.
  • Run the ISO 27001 ISMS, including control operations, evidence collection, internal audits, management reviews, corrective actions, surveillance audits, risk management, and remediation.
  • Harden identity, endpoints, MDM, SaaS, and access-management processes, while supporting business continuity, disaster recovery, and security awareness.
  • Administer company platforms including FleetDM, Google Workspace, Microsoft 365/Entra, Apple Business Manager, CrowdStrike, Tailscale, Dashlane, and the wider SaaS estate; automate recurring support and control tasks with AI where appropriate.

Requirements

  • 3–5 years of experience in security engineering, cloud or platform security, product security, or a hybrid technical and GRC role.
  • Strong foundations in cloud, ideally AWS, containers, CI/CD, identity, and networking; ability to script in Python or Go for automation and tool integration.
  • Ability to communicate credibly with senior engineers on technical designs and directors on audit findings.
  • Hands-on experience with endpoint and MDM management, primarily macOS, Google Workspace and/or Entra identity administration, and SaaS administration.
  • Fluent French and English, written and spoken, are required.
  • Based in Paris or willing to relocate to France; hybrid work with regular on-site presence is required.

Nice to have

  • Hands-on ISMS and ISO 27001 experience, including participation in an audit.
  • Experience in insurance, financial services, or another regulated sector, especially DORA.
  • Detection engineering, incident response, or offensive security experience.
  • Experience as an early security hire in a scale-up.
  • OSCP, CISSP, ISO 27001 Lead Implementer/Auditor, or cloud security certifications.

Culture & Benefits

  • High ownership as the second security hire, with direct access to administrative consoles and the ability to implement controls quickly.
  • Exposure to real attacker behavior, incidents, and claims data through hirify.global's CERT.
  • Opportunity to combine cloud and application security engineering with end-to-end ISMS ownership.
  • Access to AI tooling, budget, and autonomy to automate evidence collection, control testing, questionnaire responses, log triage, policy drafting, and code review.

Hiring process

  • 30-minute call with the CISO.
  • 60-minute on-site technical interview covering cloud and application security and threat modeling with the CISO and a Tech Lead.
  • 60-minute on-site live ISMS/compliance case, followed by 30-minute cultural-fit meetings with each founder.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →