Senior Security Engineer

Spendesk

Paris

Hybride

EUR 90 000 - 130 000

Plein temps

Il y a 6 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature complète en une minute — CV personnalisé et lettre de motivation, prêts à envoyer.

Passez les filtres ATS

Résumé du poste

Spendesk is building a dedicated Security Engineering function. As the first senior hire, you will shape how we protect the platform, respond to threats, and foster a security-aware engineering culture from within.

You will own the technical security roadmap, partnering with compliance to identify risks, and translating findings into engineering-native tools and processes to drive remediation across the organisation.

Qualifications

  • Must-have: track record of owning security outcomes end to end; hands-on experience across at least three areas: code auditing, infrastructure security (AWS/Linux).

Responsabilités

  • Own and operate bug bounty program: platform, escalation thresholds, strategic improvements.
  • Lead security incident response: triage, forensics, remediation, post-mortem.
  • Own SIEM platform architecture, detections, and runbooks; ensure coverage scales with engineering growth.
  • Own IAM implementation and operations for product and infra systems; SSO/MFA configuration, access reviews, secrets rotation.
  • Embed security into development lifecycle: threat modelling, secure-code patterns, CI/CD hardening.
  • Coordinate penetration tests and security audits with auditors; drive post-audit action plans.

Description du poste

At Spendesk, we're building the leading spend management platform for modern businesses, processing billions of euros across Europe and beyond. Security is at the heart of what we do: our customers trust us to safeguard their financial data, and we're committed to raising the bar for security in fintech.

We're creating a dedicated Security Engineering function. You'll be the first senior hire in this space, shaping how we protect our platform, how we respond to threats, and how we build a security-aware engineering culture from the inside.

Your Mission

You'll be the security conscience for engineering: building tooling, training developers, and partnering with Infrastructure on secure-by-default solutions. You own the technical security roadmap: partnering with the compliance team to identify risks, translating findings into actionable engineering-native tools and processes, driving remediation, and raising the bar across the organisation.

This is a pure engineering role, not governance or compliance: a separate team owns policy and risk frameworks. It's an individual contributor track with high influence, focused on technical depth, not people management. You'll mentor an Associate Security Engineer, shape practices across squads, and be the go-to person when engineering teams need security guidance.

You'll be hands-on across the full security surface from day one. As the team grows, you'll move from day-to-day operations toward architecture, strategy, and mentoring, acting as the escalation point for the Associate Security Engineer.

Key Responsibilities

Vulnerability & incident management

  • Own and operate our bug bounty program: manage the platform, set escalation thresholds, and drive strategic improvements.

  • Act as escalation point for vulnerability triage, taking the lead on complex or high-severity findings.

  • Lead security incident response: qualification, forensics (including fraud investigations), fix coordination, post-mortem, and resolution tracking.

Detection & SIEM

  • Own our SIEM platform (ElasticSearch, multi-node Linux): architecture, detection rules, and indicators of compromise.

  • Build and evolve detection coverage, focusing on signal quality over manual toil.

  • Build and maintain security runbooks and operational documentation.

Identity & access management

  • Own IAM implementation and operations for product and infrastructure systems, downstream of corporate IT: SSO/MFA configuration, role and access-rights implementation, periodic permission reviews, and secrets rotation.

  • Work within the authentication standards set by the security governance team.

Secure development & audits

  • Embed security into the development lifecycle: threat modelling, secure code patterns, CI/CD hardening.

  • Conduct technical security reviews of code (TypeScript, Node.js, Python), infrastructure-as-code (Terraform), and multi-tenant AWS environments.

  • Drive security tooling in CI/CD: design and own the automated gate suite (SAST, SCA, container scanning, AI-generated code risk detection) and ensure pipeline coverage scales with engineering growth.

  • Assess and govern AI tooling adoption across engineering: define security standards for code assistants and LLM-powered workflows, and conduct AI-specific threat modelling.

  • Coordinate and execute penetration tests and security audits: prepare environments, manage auditor relationships, drive post-audit action plans.

  • Drive remediation within the qualification rules and timeframes set by the security governance team.

Education & influence

  • Coach engineers on secure development through workshops, secure-code guidance, and design reviews.

  • Surface security risks and recommendations to engineering leadership; own the security backlog and roadmap.

  • Partner with Infrastructure on secure-by-default solutions.

What We're Looking For

Must-haves:

  • A track record of owning security outcomes end to end, with hands-on experience across at least three of: code auditing, infrastructure security (AWS/Linux

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Security Engineer
Senior Security Engineer

Spendesk • Paris

Sur place
EUR 90 000 - 140 000
Senior Security Engineer — Secure-by-Design Platform
Senior Security Engineer — Secure-by-Design Platform

Spendesk • Paris

Sur place
EUR 90 000 - 140 000
Associate Security Engineer
Associate Security Engineer

Spendesk • Paris

Sur place
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2
Senior Security Engineer: Build & Defend Fintech Platform
Senior Security Engineer: Build & Defend Fintech Platform

Spendesk • Paris

Hybride
EUR 90 000 - 130 000
Associate Security Engineer — Hands-On Growth & Remote
Associate Security Engineer — Hands-On Growth & Remote

Spendesk • Paris

Hybride
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2
Staff Security Engineer
Staff Security Engineer

Swile • Paris

Hybride
EUR 120 000 - 180 000
Head of Engineering
Head of Engineering

Spendesk • Paris

Hybride
EUR 140 000 - 190 000
Latest Apple equipment
Moka.care
Wellbeing and snacks
DevSecOps Engineer
DevSecOps Engineer

London Stock Exchange Group • France

Sur place
EUR 65 000 - 85 000
Senior Security Engineer
Senior Security Engineer

Triwill Group • France

Hybride
EUR 90 000 - 130 000
Senior Security Engineer
Senior Security Engineer

Adrixis • Paris

Sur place
EUR 90 000 - 130 000