N’envoyez pas un CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.
Spiko, a Paris-based fintech, is hiring Head of Security. You will own security end-to-end across application, infrastructure and cloud, protect data and money, and define the security roadmap within the tech team.
Responsibilities include leading ISO 27001 certification, DORA implementation, managing vulnerability programs, and guiding security due diligence for partners and sales. This role blends hands-on work with strategic leadership in a fast-growing company.
Founded in 2023 by Antoine and Paul-Adrien, Spiko gives businesses, non‑profits, financial advisers, and fintechs access to institutional‑grade cash management, via app or API. We are building the full infrastructure: issuing, operating, and distributing the products ourselves.
Two years after launch, we serve thousands of organizations across Europe and process hundreds of millions of euros in flows every month.
Our ambition: become the world's leading treasury management infrastructure in a market worth trillions.
We are backed by Index Ventures, the CEO of Revolut, the founder of Kyriba, and the CTO of Wise.
Spiko runs on excellence, transparency, and straight talk.
Your core mission is simple: make our customers' data and money safe
As head of security, you own security at Spiko end to end: application, infrastructure and cloud security, identity and access, vulnerability management, pentests and AI-driven security testing, detection and incident response, and the security culture of the whole company.
You define the roadmap and set the priorities. In return, you get full ownership. This role sits within Spiko’s tech team.
Your second-order missions are:
Own our compliance framework. Bring ISO 27001 certification over the line and keep it, lead our DORA implementation, and put in place the policies, controls and evidence collection that regulators, auditors and partners expect from a company that manages client money. You work hand in hand with our legal & compliance team on this.
Support the business on security due diligence. Large partners and Spiko Embedded clients run security due diligence on us before they integrate. You work to answer their questionnaires or enable the sales team to do it, to present our security posture to their teams, and makes our security a selling point.
Cloud: AWS, GCP, Cloudflare
Infrastructure as Code: Terraform
Orchestration & Deployment: Kubernetes, Docker, Qovery
Databases: PostgreSQL
Observability: Datadog (logs, traces, metrics, RUM)
Identity & Access: Ory (Kratos, Hydra, Oathkeeper)
CI/CD: GitHub Actions
Application stack: TypeScript, NX, Effect, React
5+ years of experience in security engineering roles
Solid understanding of application security, network security, and cloud security best practices
Experience with security audit processes, vulnerability management, and compliance frameworks (ISO 27001, SOC 2, or similar)
Familiarity with CI/CD security tooling (SAST, DAST, dependency scanning, container scanning)
Experience with automated pentesting tools or AI-driven security testing
Comfortable working autonomously and defining your own roadmap
Comfortable working in an English‑speaking environment
Curious, pragmatic, and eager to learn
Experience in fintech, capital markets, or other highly regulated environments
Knowledge of blockchain infrastructure or Web3 security
Compensation: Competitive package depending on experience + Stock Options
Offices: in central Paris & London
Remote work: up to 2 days per week and one full remote week per month
The best tech for your job: latest‑generation laptops and industry‑leading software
Health insurance: 100% covered by Spiko
Monthly Budget to cover different perks of choice
Transport: 50% of public transport pass covered or the Forfait Mobilités Durables (FMD)
Referral Bonus
Social life: regular afterworks and biannual offsites
Screening Interview - 30 min screening call with Talent Acquisition
Hiring Manager Interview - 30 min with Nicolas, Tech Lead
45 min technical interview focused on infrastructure & security with one engineer (remote)
2h hands‑on technical session with two engineers (infrastructure design, security scenario) (in the office)
Final Interviews with the Founders
Reference Check: we'll reach out to your references to gather further insights
Offer