Senior Security Engineer (EN/FR)

Semble

Paris

Hybride

EUR 90 000 - 100 000

Plein temps

14 jours+
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Avantages offerts par ce poste

Hybrid & flexible work environment
Private health insurance
Latest MacBook equipment
Central Paris office

Résumé du poste

Semble is seeking a senior security professional to lead application security, secure SDLC, and AI governance for our cloud healthcare platform. You will own a broad security portfolio, partner with engineering, and shape how we build secure features in a fast-moving startup.

The role emphasizes hands-on practice with Snyk across SCA, SAST, Container, and IaC, threat modelling, and compliance programs like ISO 27001. Hybrid France-based with occasional travel to London/Paris offices.

Qualifications

  • Minimum of 5 years in application security, product security, or related field.
  • Hands‑on experience with Snyk across SCA, SAST, Container, and IaC, including CI/CD integration.
  • Strong grounding in modern web/app security: OWASP Top 10 and API security.
  • Proven ability to embed security into Agile/DevSecOps workflows.

Responsabilités

  • Embed security into Agile development with engineering squads.
  • Define and roll out secure coding standards and patterns.
  • Run threat modelling for new features and architecture changes.
  • Own scanning pipelines (SAST, SCA, DAST, IaC) and manage vulnerabilities end-to-end.
  • Provide secure design guidance for APIs, microservices, and cloud-native patterns.
  • Develop and maintain AI governance and security programmes.

Connaissances

5+ years AppSec
Snyk across SCA/SAST/Container/IaC
CI/CD security integration
OWASP Top 10
DevSecOps tooling
Authn/Authz & secrets
ISO27001 familiarity
French language proficiency

Outils

Snyk
CI/CD tooling

Description du poste

About Semble

At Semble, we are on a mission to enable health professionals to amplify their impact. We improve the way healthcare is delivered to millions of people by providing doctors and their teams with powerful, innovative, intuitive, and secure software. Our cloud-based clinical system is already used by thousands of clinicians, making their lives easier and saving them money, while structuring their health data to help research.

  • Impact - We do work that matters
  • Collaboration - We are in it together
  • Human touch - We care deeply

We are also quick to embrace new technologies: we have rapidly adopted AI internally, and we actively look for people who are excited to augment and enhance their work with it.

About the IT Delivery & Security Services team

We believe the best IT is almost invisible. We are dedicated to building secure, intuitive systems that make self-service simple, automating routine work, streamlining complexity, and removing barriers. Many of our tools are already self-serve, and we are always pushing further. Our commitment to high standards has helped Semble achieve key security certifications and set the benchmark for best practice across the business. We champion clarity, transparency, and processes that are easy to understand and straightforward to follow.

We hold ourselves to a high standard every day. Our estate is always patched, always correctly provisioned, always documented; not because an audit is coming, but because that is simply how we work.

About the role

You will report directly to the Head of Information Security, working alongside a Senior Technical Support Engineer, and together you will form the senior backbone of the IT Delivery and Security Services team.

Security at Semble has until now been carried by a single person. This hire is about building genuine depth and maturity into the function. You will own a broad portfolio of security responsibilities, from application security and secure SDLC enablement to AI governance and security programmes, with significant autonomy to shape how that work gets done.

The product is evolving fast. AI is no longer a feature at Semble; it is becoming part of the core architecture. That means the attack surface is changing, the threat model is changing, and the skills required to stay ahead of it are changing too. We are looking for someone who is not just keeping up with that shift but is genuinely excited by it.

This is a startup environment: the work is varied, the pace is real, and you will have the opportunity to get your hands on almost everything. There is a meaningful backlog of projects to deliver as we mature the InfoSec function. If you want to define best practice rather than just follow it, this is it.

Security is hybrid within France, with occasional travel to our London and Paris office for collaboration and workshops.

What you will be doing
Application Security and Secure SDLC
  • Embed security into Agile development by partnering with engineering squads during planning, refinement, and delivery. Be the security voice in the room, not the person who reviews things after the fact.
  • Define, roll out, and continuously improve secure coding standards, secure design patterns, and developer-friendly guidance that scales across the engineering team.
  • Run threat modelling for new features and major architectural changes, capturing abuse cases and security requirements early. As Semble builds more AI-powered and agentic capabilities, apply emerging frameworks to ensure new threat surfaces are modelled and mitigated from the outset.
  • Own SAST, SCA, DAST, container, and IaC scanning pipelines, with Snyk as our primary platform (Snyk Code, Open Source, Container, and IaC). Integrate with CI/CD, manage policies, and maintain a strong focus on developer experience and false-positive reduction.
  • Triage and manage vulnerabilities end-to-end: classification, SLAs, fix validation, and reporting.
  • Build frictionless guardrails: pre-commit hooks, secure templates, reference code, and paved paths that make doing the right thing the easy thing.
  • Deliver targeted training and just-in-time enablement based on findings and stack specifics.
Security Architecture and Design
  • Advise on architecture choices for key product feature developments, including authorisation, secrets and key management, data protection, and zero-trust-aligned designs.
  • Guide secure API and microservice patterns, including input validation, rate limiting, secure session handling, and token-based security (OAuth 2.0/OIDC).
  • Review designs for cloud-native services and edge components, ensuring sensible security trade-offs aligned to product goals.
  • As agentic AI capabilities expand within the product, advise on the security architecture of agent orchestration, tool integrations, memory handling, and MCP (Model Context Protocol) server deployments.
AI Security and Governance
  • Apply and evolve Semble's approach to AI-specific threats: prompt injection, excessive agent autonomy, tool and plugin abuse, AI supply chain risks, and context manipulation. The OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications are your starting point, not your ceiling.
  • Work closely with the Head of Information Security to develop and maintain Semble's AI governance posture, aligned with ISO 42001 and the evolving regulatory landscape for AI in healthcare.
  • Assess risks associated with third-party AI integrations, AI-assisted development tooling, and agentic workflows, and implement appropriate mitigations.
Security Operations and Threat Management
  • Monitor, investigate, and respond to security alerts, incidents, and anomalous behaviour across Semble's environment.
  • Develop and mature threat intelligence capabilities, including vulnerability management, penetration testing coordination, and incident response processes.
  • Maintain and improve security tooling, logging, and detection capabilities, with an automation-first mindset.
  • Contribute to incident response runbooks for application-layer and AI-related incidents, and support blameless post-incident reviews to embed learning back into the SDLC.
  • Contribute to the ongoing improvement of Semble's overall security posture, identifying and addressing gaps proactively.
Compliance, Certification and Audit Readiness
  • Own or co-own the delivery of Semble's compliance programmes, including ISO 27001, Cyber Essentials+, NHS DSPT, and the journey towards SOC 2 readiness.
  • Support and contribute to ISO 42001 implementation as Semble's AI governance framework matures.
  • Define and track pragmatic security KPIs: time-to-remediate, coverage, percentage of criticals resolved within SLA, threat model coverage, and audit readiness indicators.
  • Maintain audit-quality documentation, evidence, and records at all times. Our standard is always audit ready, every day.
Customer and Stakeholder Engagement
  • Support the sales process by responding to customer security questionnaires and due diligence requests with accuracy and confidence.
  • Occasionally engage directly with customers on security topics, acting as a knowledgeable and credible representative of Semble's security function.
  • Work with internal stakeholders to ensure security requirements are understood and embedded across the business.
What we’re looking for
Required
  • Minimum of 5 years of experience in application security, product security, or a combination of software engineering and security with strong AppSec ownership.
  • Hands‑on experience with Snyk across SCA, SAST, Container, and IaC, including CI/CD integration and policy management.
  • Strong grounding in modern web and application security: OWASP Top 10, API Security Top 10, and an emerging understanding of the OWASP Top 10 for Agentic Applications.
  • Practical experience embedding security into Agile workflows and DevSecOps tooling.
  • Solid understanding of authn/authz patterns, secrets management, encryption, and cloud-native security controls.
  • Experience with compliance frameworks, particularly ISO 27001. Familiarity with Cyber Essentials+, NHS DSPT, or SOC 2 is a strong advantage.
  • Practical understanding of AI security risks, including prompt injection, LLM vulnerabilities, and agentic system threats, and how to address them in a product context.
  • Experience working in a SaaS environment or similarly regulated industry, with an appreciation of the product, engineering, and commercial context that security decisions sit within.
  • Ability to communicate clearly with engineers, leadership, and occasionally customers, translating complex security risk into clear, actionable language.
  • Genuine, hands‑on AI experience: not curiosity, but practice. We will ask you to speak to specific ways you are already using AI to improve security operations, detection, or engineering workflows.
  • A track record of maintaining security programmes to a continuously high standard, with audit readiness as a default rather than a periodic event.
  • A proactive, ownership mindset: you identify gaps, propose solutions, and deliver them without waiting to be told.
  • Proficiency in the French language
Desirable
  • CISSP certification (strongly preferred).
  • Experience with threat modelling methodologies such as STRIDE or attack trees, and running effective threat model sessions with engineering teams.
  • Familiarity with API gateways, container orchestration, and software supply chain security.
  • Experience securing AI-enabled features, ML pipelines, agentic workflows, or MCP-based integrations.
  • Experience building or maturing a security function within a scaling organisation.
  • Exposure to healthcare data regulations and NHS security requirements.
What you’ll get in return:
  • The great feeling coming with knowing you do something that matters: shaping the future of healthcare!
  • 90k-100k euros (based on your experience and the value you can bring)
  • Autonomy and ownership we’ll set the vision and share the context, then we trust you to run with things.
  • A generous holiday entitlement: "congés annuels" + "RTT" + "jours feriés" + 3 extra days (birthday and 'feel good' days) - that we will expect you to actually take so you can recharge and rest
  • Comprehensive health & wellbeing support - including private health insurance, and mental health support and free therapy sessions through Oli
  • Hybrid & flexible work environmen - work from anywhere in France, with also some flexibility to work across Europe
  • Get the tech you need - You will get the latest MacBook and take your pick across a wide range of equipment to set up your home office ergonomically
  • Work alongside an inspiring team - our two founders have started Semble after a successful startup exit, and your future colleagues are all knowledgeable and innovators in their field
  • Fantastic office space in Central Paris, in the quaint Cour Saint Émilion - with a roof terrace, weekly animations, loads of natural light, and cute doggies!
  • The usual free bits coming with nice offices (coffee, tea, fruits, happy hours and activities...)

We welcome applications from people of all backgrounds and walks of life, including those from groups typically underrepresented in the technology industry. We also encourage applications from disabled and neurodiverse candidates. If there are adjustments we can make to support you throughout the recruitment process, please do let us know.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Senior Security Engineer (EN/FR)
Senior Security Engineer (EN/FR)

Semble Technology Limited • France

Hybride
EUR 90 000 - 100 000
Company equity
Comprehensive health & wellbeing support
Generous holiday entitlement
+2
Senior Security Engineer
Senior Security Engineer

DataDome • France

Hybride
EUR 70 000 - 90 000
500€ stipend for workspace setup
Generous health benefits
Annual allowance for leisure activities
+2
Product Manager- AI-Native Digital Studio, Paris
Product Manager- AI-Native Digital Studio, Paris

JobEgo • Paris

Hybride
EUR 70 000 - 95 000
Hybrid work in Paris
International team
Applied AI focus
Backend Engineer
Backend Engineer

Sekoia.io • Rennes

Hybride
EUR 45 000 - 65 000
Cybersecurity Researcher (Application Security)
Cybersecurity Researcher (Application Security)

Symbiotic Security • Paris

Hybride
EUR 60 000 - 80 000
Competitive salary and equity options
Health insurance fully covered
Swile meal card for lunch breaks
+3
Security Manager
Security Manager

Helsing • Paris

Sur place
EUR 90 000 - 130 000
Relocation support
Learning allowance
Health & wellness
+4
Senior Security Engineer
Senior Security Engineer

Alice & Bob • Paris

Hybride
EUR 90 000 - 130 000
BSPCE plan
IP bonuses
Remote policy
+6
Area VP Sales, EMEA West
Area VP Sales, EMEA West

Semperis • France

Hybride
EUR 150 000 - 210 000
Senior Security Engineer
Senior Security Engineer

Jobtailor • Paris

Sur place
EUR 70 000 - 90 000
Stock ownership
100% healthcare coverage
Meal vouchers
+3
SRE Engineering Manager
SRE Engineering Manager

GitGuardian • Paris

Hybride
EUR 90 000 - 150 000
BSPCE
Lunch voucher
Sponsored Wellpass (gymlib)
+4