Senior Security Engineer

Spendesk

Paris

Sur place

EUR 80 000 - 100 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care
Great office snacks
Location-specific benefits

Résumé du poste

Spendesk is seeking a Senior Security Engineer in Paris to lead the security engineering function. This role is crucial in building tooling, training developers, and establishing a security-aware culture.

The ideal candidate will have hands-on experience with security outcomes from code auditing to incident response, excellent communication skills, and a deep understanding of modern web architectures.

We appreciate diverse experiences and encourage all to apply!

Qualifications

  • Track record of owning security outcomes end to end.
  • Experience across code auditing, incident response, and penetration testing.
  • Ability to own a roadmap and communicate with non-specialists.

Responsabilités

  • Own the technical security roadmap and manage vulnerability responses.
  • Build security practices embedded into the development lifecycle.
  • Coach engineers on secure development.

Connaissances

Hands-on security experience
Scripting and automation (Python, Bash)
Communication skills

Formation

Experience in infrastructure security

Outils

ElasticSearch / ELK stack

Description du poste

At Spendesk, we’re building the leading spend management platform for modern businesses, processing billions of euros across Europe and beyond. Security is at the heart of what we do: our customers trust us to safeguard their financial data, and we’re committed to raising the bar for security in fintech.

We’re creating a dedicated Security Engineering function. You’ll be the first senior hire in this space, shaping how we protect our platform, how we respond to threats, and how we build a security‑aware engineering culture from the inside.

Your Mission

You’ll be the security conscience for engineering: building tooling, training developers, and partnering with Infrastructure on secure‑by‑default solutions. You own the technical security roadmap: partnering with the compliance team to identify risks, translating findings into actionable engineering‑native tools and processes, driving remediation, and raising the bar across the organisation.

This is a pure engineering role, not governance or compliance: a separate team owns policy and risk frameworks. It’s an individual contributor track with high influence, focused on technical depth, not people management. You’ll mentor an Associate Security Engineer, shape practices across squads, and be the go‑to person when engineering teams need security guidance.

You’ll be hands‑on across the full security surface from day one. As the team grows, you’ll move from day‑to‑day operations toward architecture, strategy, and mentoring, acting as the escalation point for the Associate Security Engineer.

Key Responsibilities
Vulnerability & incident management
  • Own and operate our bug bounty program: manage the platform, set escalation thresholds, and drive strategic improvements.
  • Act as escalation point for vulnerability triage, taking the lead on complex or high‑severity findings.
  • Lead security incident response: qualification, forensics (including fraud investigations), fix coordination, post‑mortem, and resolution tracking.
Detection & SIEM
  • Own our SIEM platform (ElasticSearch, multi‑node Linux): architecture, detection rules, and indicators of compromise.
  • Build and evolve detection coverage, focusing on signal quality over manual toil.
  • Build and maintain security runbooks and operational documentation.
Identity & access management
  • Own IAM implementation and operations for product and infrastructure systems, downstream of corporate IT: SSO/MFA configuration, role and access‑rights implementation, periodic permission reviews, and secrets rotation.
  • Work within the authentication standards set by the security governance team.
Secure development & audits
  • Embed security into the development lifecycle: threat modelling, secure code patterns, CI/CD hardening.
  • Conduct technical security reviews of code (TypeScript, Node.js, Python), infrastructure‑as‑code (Terraform), and multi‑tenant AWS environments.
  • Define and implement security analysis and testing procedures integrated into deployment pipelines.
  • Coordinate and execute penetration tests and security audits: prepare environments, manage auditor relationships, drive post‑audit action plans.
  • Drive remediation within the qualification rules and timeframes set by the security governance team.
Education & influence
  • Coach engineers on secure development through workshops, secure‑code guidance, and design reviews.
  • Surface security risks and recommendations to engineering leadership; own the security backlog and roadmap.
  • Partner with Infrastructure on secure‑by‑default solutions.
What We’re Looking For
Must‑haves
  • A track record of owning security outcomes end to end, with hands‑on experience across at least three of: code auditing, infrastructure security (AWS/Linux), penetration testing, SIEM operations, incident response.
  • Ability to own a roadmap: identify priorities, build a plan, execute autonomously, and communicate progress to non‑specialists.
  • Deep understanding of modern web architectures (microservices, cloud‑native, PaaS/SaaS) and where they break.
  • Strong scripting and automation ability (Python, Bash, or similar).
  • Experience mentoring other engineers or security practitioners.
  • Excellent communication: you can explain a CVSS 9.8 to a PM and get them to prioritise it.
Nice‑to‑haves
  • Experience with ElasticSearch / ELK stack in production.
  • Familiarity with AWS, GCP, Snowflake, Datadog, Okta.
  • Knowledge of security standards and frameworks (ISO 27001, OWASP, SOC 2, PCI‑DSS).
  • Experience in a regulated fintech or payments environment.
  • Reverse engineering and analysis of minified/obfuscated code.

Not ticking every box? We’d still love to hear from you. At Spendesk, we value skills, potential, and diverse experiences. If this role excites you and you believe you could contribute, we encourage you to apply.

About Our Benefits

Flexible on‑site and remote policy

Latest Apple equipment – the tools you need to excel

Access to Moka.care – for emotional and mental health wellbeing

Great office snacks – to fuel your day

A positive team to work with daily!

We also offer location‑specific benefits tailored to each market, including health insurance, wellness allowances, commuter support, meal vouchers, and gym memberships – ensuring you’re well supported wherever you’re based.

Diversity & Inclusion

At Spendesk, we’re committed to fostering an environment where all differences are encouraged, supported and celebrated. We’re building our culture for everyone, with everyone. Our goal is to attract and build a diverse, equal and inclusive team, where everyone feels welcome and we truly embrace and encourage people from all backgrounds to apply.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Senior Security Engineer
Senior Security Engineer

Spendesk • Paris

Sur place
EUR 90 000 - 140 000
Software Engineer - Paris/London
Software Engineer - Paris/London

Spendesk • Paris

Hybride
EUR 50 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+1
Senior Software Engineer - KYC
Senior Software Engineer - KYC

Spendesk • Paris

Hybride
EUR 90 000 - 120 000
Flexible on-site and remote policy
Latest Apple equipment
Mental health support (Moka.care)
Backend Software Engineer (AI Squad)
Backend Software Engineer (AI Squad)

Spendesk • Paris

Hybride
EUR 70 000 - 110 000
Flexible on-site and remote policy
Latest Apple equipment
Moka.care
+2
Compliance Business Officer - Payments & Customer Protection
Compliance Business Officer - Payments & Customer Protection

Spendesk • Paris

Hybride
EUR 70 000 - 95 000
Flexible on-site policy
Lunch 60% funded by Spendesk
Alan Premium health insurance
+5
Cybersecurity Analyst GRC
Cybersecurity Analyst GRC

Spendesk • Paris

Hybride
EUR 55 000 - 75 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care
+2
Customer Success Manager - French & Spanish Markets
Customer Success Manager - French & Spanish Markets

Spendesk • Paris

Hybride
EUR 55 000 - 75 000
Flexible on-site policy
Lunch funded
Health insurance
+4
Associate Security Engineer
Associate Security Engineer

Spendesk • Paris

Sur place
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2
GTM Ops Lead
GTM Ops Lead

Spendesk • Paris

Sur place
EUR 90 000 - 130 000
Software Engineer AI - Paris/London/Barcelona
Software Engineer AI - Paris/London/Barcelona

Spendesk • Paris

Hybride
EUR 60 000 - 80 000
Health insurance
Wellness allowances
Commuter support
+5