Cybersecurity Engineer - Internal Security

Stoïk

Paris

Hybride

EUR 90 000 - 125 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Stoïk is seeking a senior security professional to join as the second security hire, reporting into the CISO. The role blends security engineering with ISMS leadership, operating across cloud, identity, and governance.

You will read pull requests, automate your work, and engage with engineers in a bilingual, hybrid Paris environment. You will own threat modelling, risk framing, secure defaults, and guardrails, while maintaining ISO 27001 certification and leading security tooling and end‑to‑end

Qualifications

  • 3–5 years in security engineering, cloud/platform security, product security, or hybrid technical + GRC roles.
  • Solid foundations in cloud (AWS preferred), containers, CI/CD, identity and networking.
  • Ability to discuss designs credibly with engineers and auditors.
  • Hands-on IT: endpoint/MDM management and identity administration in SaaS platforms (Google Workspace / Entra).
  • Fluent French and English, written and spoken; based in Paris with hybrid on-site work.

Responsabilités

  • Act as security counterpart in design/architecture reviews; model threats, frame risks, and propose ship-ready safeguards.
  • Own vulnerability/exposure management end-to-end across CI/CD, dependencies, containers, cloud workloads, and external attack surface.
  • Own and tune security tooling: cloud security posture, SAST/SCA, secrets management, endpoint, identity; optimize toolset.
  • Maintain ISMS and ISO 27001 certification with operations, audits, management reviews, and risk register updates.
  • Harden identity, endpoint, and SaaS estate; contribute to access management, joiner-mover-leaver, and annual security reviews.
  • Administer IT tools (MDM fleets, Google Workspace, Entra, Microsoft 365, CrowdStrike, Tailscale, Dashlane); drive automation for recurring issues.
  • AI leverage: data collection, policy drafting, log triage, and code-review support; scale security through tooling.

Connaissances

Security engineering
Cloud security
Containers
CI/CD
Identity
Networking
Python/Go scripting
Fluent French & English

Outils

AWS
Terraform
CrowdStrike
FleetDM
Vanta

Description du poste

About us

Stoïk is a cyber insurtech company, and we insure companies up to €1B of turnover. To have better insurance results we have decided to (1) build prevention tools targeted towards the attacks we see, and (2) have our own incident response team (CERT).

We have raised €50M, protect +14000 insureds, are 175 people, and operate in France, Germany, Austria, Spain and BENELUX.

Our CERT handles +1000 incidents / year, including ransomware events and frauds. Our tech team is 45 people and we have built an EASM tool, a phishing simulation platform, AD and Cloud scans, and many more security tools.

We sell security to our insureds. That obliges us to be exemplary on our own, in front of our insureds, our brokers, our reinsurers and our regulator.

Position Overview

Security at Stoïk is currently a one-person team: the CISO. This role is the second.

This is a deliberately broad role. Roughly half of it sits inside the tech team as its security counterpart; the other half is running our Information Security Management System.

We are not looking for someone who tolerates one half of the job to get to the other. A control written in a policy and never enforced in the pipeline is worthless, and a technical fix nobody can evidence to an auditor is only half done.

You are not expected to ship product code. You are expected to read a pull request, hold your own in a technical debate with a senior engineer, script and automate your own work, and be genuinely welcome in the tech team's rituals.

The security team also owns the tools the company works on every day: MDM, identity, EDR, VPN and our SaaS estate. At our size those tools are the controls, you configure them and you see the effect immediately.

Technologies: Python, Go, Postgres, AWS / Terraform, CrowdStrike, FleetDM, Vanta, Google Workspace, HubSpot, Anthropic, OpenAI… we are a cloud-native company.

Key Responsibilities
  • Security engineering with the tech team: act as the security counterpart in design and architecture reviews: threat modelling, risk framing, and recommendations engineers can actually ship. Build secure defaults and guardrails (IaC policies, hardened baselines, paved paths) so that the secure way is the easy way.
  • Vulnerability & exposure management: own it end to end across CI/CD, dependencies, containers, cloud workloads and our own external attack surface; triage, prioritisation, and getting fixes over the line.
  • Security tooling: own and tune our stack (cloud security posture, SAST / SCA, secrets management, endpoint, identity). Fewer tools, better configured, with alerts someone actually reads.
  • ISMS RUN: keep our ISO 27001 certification healthy day to day; control operation, evidence collection, internal audits, management reviews, corrective actions, surveillance audits. Maintain the risk register and drive remediation with the owners who are accountable for it.
  • Corporate & IT security: harden our identity, endpoint and SaaS estate; contribute to access management, joiner-mover-leaver and periodic access reviews; contribute to BCP / DRP testing and to security awareness.
  • IT platform run: administer the tools the company runs on: MDM (FleetDM), Google Workspace and Microsoft 365 / Entra, Apple Business Manager, CrowdStrike, Tailscale, Dashlane and our SaaS estate. Help colleagues when something breaks, and turn each recurring issue into an automation or a better default.
  • AI leverage: evidence collection, control testing, questionnaire responses, log triage, policy drafting, first-pass code review: a large share of this work can be assisted or agent-driven today. You get the tools, the budget and the mandate to build that leverage, and the judgement to know where a human still has to sign.
What you'll gain in this role
  • High ownership & scope: you are the second security hire, and you hold the admin console. No committee between you and a fix: when you decide a control is needed, you can ship it the same afternoon, and see straight away whether it holds. What you build becomes how Stoïk does security.
  • Real attacker signal: we are a cyber insurer with our own CERT. You will see real incidents, real claims data and real attacker behaviour that most internal security teams never get near, and feed it straight back into our own defences.
  • Both halves of the craft: very few roles let you keep your hands in cloud and application security while owning an ISMS end to end. This one is designed to make you unusually complete, and to grow into a broader security leadership scope as we scale.
Qualifications

Must-Haves

  • 3-5 years in security engineering, cloud / platform security, product security, or a hybrid technical + GRC role.
  • Solid technical foundations: cloud (AWS ideally), containers, CI/CD, identity, networking. You can script in Python or Go, not to build products, but to automate your own work and integrate tools.
  • The ability to hold both conversations credibly: a design review with a senior engineer in the morning, an audit finding with a director in the afternoon.
  • Comfortable getting hands-on with IT: endpoint and MDM management (mostly macOS), identity administration on Google Workspace and / or Entra, SaaS administration.
  • Fluent French and English, written and spoken. Our internal work is bilingual and our documentation exists in both.
  • Based in Paris, or willing to relocate. Hybrid, with regular time on site.
  • A working relationship with AI tooling that goes beyond curiosity. If you see AI as a threat to your craft rather than a multiplier for it, this is not the right team.

Nice-to-Haves

  • Hands-on ISMS experience, ISO 27001 in particular. You have lived through an audit from the inside, not just read about one.
  • Exposure to insurance, financial services or another regulated sector (DORA in particular).
  • Detection engineering, incident response or offensive security experience.
  • Experience as an early security hire in a scale-up, where nothing is set up yet and that is the point.
  • Certifications (OSCP, CISSP, ISO 27001 Lead Implementer / Auditor, cloud security) are welcome, never a substitute for demonstrated experience.
Hiring Process
  • Call with the CISO, 30 min
  • On-site technical interview: cloud & application security, threat modelling, with the CISO and a Tech Lead, 60 min
  • "Live" case on an ISMS / compliance scenario, discussed on site rather than sent as homework, 60 min
  • Cultural fit with Founders (30 min each)
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Deal Desk Manager Customer Success · Paris, Stoïk Headquarters · Hybrid
Deal Desk Manager Customer Success · Paris, Stoïk Headquarters · Hybrid

Stoïk • Paris

Hybride
EUR 90 000 - 120 000
Account Executive (DACH)
Account Executive (DACH)

STOIK Software Ltd. • Paris

Hybride
EUR 60 000 - 90 000
Internal Security Engineer: ISMS & Cloud Defenses
Internal Security Engineer: ISMS & Cloud Defenses

Stoïk • Paris

Hybride
EUR 90 000 - 125 000
RevOps Engineer Operations · Paris, Stoïk Headquarters · Hybrid
RevOps Engineer Operations · Paris, Stoïk Headquarters · Hybrid

Stoïk • Paris

Hybride
EUR 85 000 - 120 000
Competitive salary
Comprehensive benefits
Hybrid work model
+1
Product Manager Product · Paris, Stoïk Headquarters · Hybrid
Product Manager Product · Paris, Stoïk Headquarters · Hybrid

Stoïk • Paris

Hybride
EUR 90 000 - 120 000
Staff Security Operations Engineer
Staff Security Operations Engineer

INKcredible Design & Printing • Paris

Sur place
EUR 90 000 - 140 000
Senior Security Evaluation & Certification Consultant
Senior Security Evaluation & Certification Consultant

Internet of Trust • Paris

Hybride
EUR 90 000 - 120 000
Meal vouchers €9.50 (half funded)
Hybrid working model
Paris office location
Marketing Manager France Marketing · Paris, Stoïk Headquarters · Hybrid
Marketing Manager France Marketing · Paris, Stoïk Headquarters · Hybrid

Stoïk • Paris

Hybride
EUR 70 000 - 110 000
BSPCEs
Super locaux
Account Executive, Mid-market, Spain - Sales
Account Executive, Mid-market, Spain - Sales

Riot Security Inc. • Paris

Hybride
EUR 75 000 - 105 000
OTE 75K–105K€ uncapped
Customer Care Specialist (Technical Support)
Customer Care Specialist (Technical Support)

Tryriot • Paris

Sur place
EUR 40 000 - 55 000
Healthy-financial company
Strong vision and high ambitions
Canal Saint Martin office in Paris