Security Engineer

Yousign

Paris

Hybride

EUR 47 000 - 79 000

Plein temps

14 jours+
Générateur de candidature

N’envoyez pas un CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.

Passez les filtres ATS

Avantages offerts par ce poste

Stock options BSPCE
Meal vouchers Swile
Life & disability insurance
Wellbeing: Axomove & Moka.care
Transport reimbursement
Leeto employee discounts
RTT days & parental benefits
Volunteering day
Learning & development budget

Résumé du poste

Youtrust, a European Digital Trust provider, is seeking a Security Engineer to partner with Product as an embedded security advisor. You will lead the end-to-end security review cycle for new features, own BugBounty programs, and drive risk-based decisions.

You will contribute to regulatory compliance (eIDAS, NIS2, ISO 27001), help secure the Trusted Zone, and build automation while balancing security with business velocity.

Qualifications

  • Hands-on expertise in web application and API security.
  • Ability to run threat modeling sessions and produce clear decisions.
  • Experience managing vulnerabilities across a product perimeter.
  • Participation in or leadership of BugBounty programs and triage workflows.
  • Using AI to automate security tasks and integrate into workflows.
  • Comfort working across domains: product security, compliance, fraud prevention.

Responsabilités

  • Lead end-to-end security review cycle for all product features.
  • Own and operate Youtrust's BugBounty program: triage reports, remediation, rewards.
  • Identify, prioritize, and track remediation of vulnerabilities across product and infrastructure.
  • Contribute to security of the Trusted Zone and fraud detection efforts.
  • Support regulatory compliance (eIDAS, NIS2, ISO 27001): translate requirements into controls.
  • Extend security expertise across the company; assess risks and guidance.
  • Participate in weekly on-call rotation and build automation to reduce toil.
  • Raise security awareness and coach teams on secure-by-design practices.

Connaissances

Web security
API security
Threat modeling
BugBounty programs
AI tooling
Secure-by-design

Outils

n8n

Description du poste

About Youtrust

Youtrust is a European Digital Trust provider, fully compliant with eIDAS and the highest European standards. Our three modules – electronic signatures, identity and document verification, and e-seals – can be used independently or combined within sector‑specific workflows, ensuring simple, secure and legally compliant processes for SMEs and mid‑sized companies.
Hosted and processed entirely in Europe, we guarantee sovereignty, transparency and reliability. As a certified B‑Corp, we combine innovation with responsibility – building trust at the heart of every digital exchange.
We are entering a key moment as we expand from eSignature to the full Digital Trust chain.

Your Role

As a Security Engineer at Youtrust, you are the embedded security partner for the entire company, with Product as your primary internal client. You lead Youtrust's security review cycle end-to-end on prioritized initiatives: from understanding the context of a new feature or project, to issuing your requirements and guidance, supporting implementation, and unblocking through risk management when needed.

You own and operate the pentest and BugBounty programs and ensure consistent, pragmatic security coverage across all team initiatives, from Engineering and Product to cross-functional projects company‑wide.

You also step into the topics that make Youtrust a Digital Trust provider: the security of our Trusted Zone, our fraud detection and prevention efforts, and our regulatory compliance (eIDAS, NIS2, ISO 27001). You won't own every one of these, but you contribute wherever the team needs you — your specialization defines where you spend most of your time, not a silo you stay inside.

Your Responsibilities
  • Lead the end-to-end security review cycle for all product features: context intake, Decision Records, implementation support, and risk-based unblocking.

  • Own and operate Youtrust's BugBounty program: triage reports, drive remediation, and manage reward decisions.

  • Identify, prioritise, and track remediation of vulnerabilities across Youtrust's product and infrastructure perimeter.

  • Contribute to the security of the Trusted Zone, and to fraud detection and prevention, alongside the Security & Compliance team.

  • Support regulatory compliance (eIDAS, NIS2, ISO 27001): help translate requirements into technical controls, and contribute to audits and remediation when needed.

  • Extend security expertise beyond Product to all company initiatives: assess risks, issue guidance, and maintain a consistent security posture company‑wide.

  • Take part in the team's weekly on‑call ("doctor") rotation, and build automation (n8n, AI tooling, alerting) to reduce manual toil.

  • Raise the security bar across Engineering and beyond: share knowledge, coach teams on secure‑by‑design practices, and build security awareness.

Your Profile
  • You have deep, hands‑on expertise in web application and API security, you know attack and defense mechanisms inside out and can spot a vulnerability in a PR or architecture diagram.

  • You are able to independently run threat modeling sessions, produce clear Decision Records, and translate security risks into actionable requirements for engineering teams.

  • You have experience managing vulnerabilities across a product perimeter: triaging, prioritising, tracking remediation, and knowing when to accept risk versus escalating.

  • You have participated in or run BugBounty programs. You understand triage workflows, reward logic, and how to communicate decisions clearly to researchers.

  • You use AI actively to automate parts of your security work, CVE monitoring, BugBounty triage, report generation, and you think critically about how to integrate AI into existing workflows rather than simply adding tools.

  • You are comfortable working across domains. Your core is product security, but you are happy to contribute to compliance topics (eIDAS, NIS2, ISO 27001), to fraud detection and prevention, and to the security of a Trusted Zone. Prior exposure to a regulated or Digital Trust environment is a strong plus.

  • You are genuinely self‑sufficient: you pick up a brief, define the scope, and deliver without hand‑holding. You are comfortable in ambiguous, fast‑moving environments.

  • You are pragmatic by nature. You do not block for the sake of blocking. You find the right balance between security rigour and business velocity, and you know when to elevate versus when to accept risk.

  • You communicate clearly and simply. You can explain a complex vulnerability to a non‑security engineer in two minutes, and you coach without being preachy.

  • You are genuinely curious: you follow threat intel, participate in CTFs, and keep your technical edge sharp because you care about the craft.

  • French at a native or near‑native level (C2) is required. English at a professional working level (B2) is required for security research, technical documentation, and communication with international BugBounty researchers.

Recruitment Process
  1. R1 — TAM Interview with Guillhem Cambiganu (30 min)

  2. R2 — Hiring Manager Interview with Tony Belot (45–60 min)

  3. R3 — Technical Interview: slide deck presentation + peer discussion with Tony Belot and a member of the Security & Compliance team (1H)

  4. R4 — Director Interview with Kevin Dubourg (30 min)

Benefits
  • Salary: 53 000 – 79 000 EUR

  • Stock options - BSPCE

  • Meal vouchers (Swile): 10.50 EUR/day, 50% covered by Youtrust

  • Youtrust

  • Life & disability insurance: 100% employer‑covered

  • Wellbeing: Axomove (4 physio sessions) and Moka.care (6 therapy/coaching sessions)

  • Transportation: 50% reimbursement for public transport for hybrid workers

  • Leeto: Access to numerous employee discounts

  • Time off: 10 RTT days/year, plus menstrual leave, parenthood benefits, seniority days

  • 1 volunteering day/year, learning & development budget, and more

Why join Youtrust now?
  • A mission that matters in a world challenged by AI‑driven fraud

  • A vision built on integrity

  • A European & sovereign platform

  • A certified B Corp

  • The golden age of Youtrust

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Engineer
Security Engineer

Yousign • Paris

Sur place
EUR 53 000 - 79 000
Stock options BSPCE
Meal vouchers Swile
Life & disability insurance
+5
Security Engineer
Security Engineer

Youtrust • Paris

Hybride
EUR 53 000 - 79 000
Stock options
Meal vouchers
Insurance
+4
Compliance Engineer
Compliance Engineer

Youtrust • Paris

Sur place
EUR 64 000 - 79 000
Stock options - BSPCE
Meal vouchers (Swile)
Health insurance (Alan)
+3
Brand & Content Manager - CDI (h/f/x)
Brand & Content Manager - CDI (h/f/x)

Yousign • Paris

Sur place
EUR 50 000 - 60 000
Salary package 50k-60k
Stock options
Meal vouchers
+2
Account Executive
Account Executive

Youtrust • Paris

Sur place
EUR 75 000 - 132 000
Swile card
Alan health insurance
Transport benefits
+1
Head of Legal
Head of Legal

Youtrust • Caen

Sur place
EUR 140 000 - 200 000
BSPCE
Meal vouchers
Health insurance
+5
Head of Legal
Head of Legal

Youtrust • Bordeaux

Sur place
EUR 120 000 - 180 000
BSPCE
Meal vouchers (Swile)
Health insurance (Alan)
+5
Brand & Content Manager - CDI (h/f/x)
Brand & Content Manager - CDI (h/f/x)

Youtrust • Paris

Sur place
EUR 50 000 - 60 000
Meal vouchers
Health insurance
Life & disability insurance
+5
International Account Executive - Italian Market (Paris or Barcelona)
International Account Executive - Italian Market (Paris or Barcelona)

Yousign • Paris

Hybride
EUR 65 000 - 90 000
Endenred / Swile lunch vouchers
Health insurance
Public transport discounts
+3
Engineering Manager M/F/Mx
Engineering Manager M/F/Mx

Trustpair • Les Ulis

Sur place
EUR 70 000 - 90 000
Collaborative environment
Career opportunities internationally
Flexible remote policy