Staff Security Engineer

Swile

Paris

Hybride

EUR 110 000 - 150 000

Plein temps

Il y a 19 heures
Soyez parmi les premiers à postuler

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Swile is seeking a Staff Security Engineer to strengthen the security of its products, data and engineering platform. This is a highly technical, hands-on role. You will work closely with Engineering teams to continuously harden our systems and help design the next generation of our security architecture.

You will operate across two horizons: today’s security—hardening applications, access controls and data-protection; tomorrow’s privacy architecture—cryptographic isolation and minimal exposure.

Qualifications

  • You are a strong engineer with significant experience building or securing production software and distributed systems.
  • Deep security engineering expertise across multiple domains (application security, API security, IAM, cryptography).
  • Experience designing and shipping security capabilities into production and influencing architecture.

Responsabilités

  • Identify and reduce high-impact security risks across applications, APIs and internal tools.
  • Strengthen authentication, authorization and access controls.
  • Improve protection of sensitive data and data privacy engineering.
  • Design controls to limit blast radius of compromised accounts, services or infrastructure.
  • Improve security monitoring, auditing, and detection of suspicious access patterns.
  • Perform threat modelling and secure software architecture reviews.
  • Build reusable security capabilities into the engineering platform and lifecycle.
  • Partner with engineering teams to address systemic security risks.

Connaissances

Security engineering
Distributed systems security
OAuth2 / OIDC
WebAuthn / FIDO2
Cryptography
Threat modelling
Security monitoring
Access controls
Data security
Encryption

Description du poste

Build security platforms, not security processes

We are looking for a Staff Security Engineer to strengthen the security of our products, data and engineering platform.

This is a highly technical and hands‑on role. You will work closely with Engineering teams to continuously harden our systems while helping design the next generation of our security architecture.

You will operate across two horizons:

  • Strengthen security today: continuously harden our applications, access controls and data‑protection mechanisms against evolving threats.
  • Build the privacy architecture of tomorrow: move beyond traditional perimeter and access‑control security by designing systems where sensitive data is cryptographically isolated, minimally exposed, and increasingly usable without being directly revealed.

The ultimate objective is not simply to make Swile harder to breach. It is to make a breach increasingly uninteresting, because there is less usable data available to steal.

What you will do

We want Security Engineering to create capabilities that scale across hundreds of engineers.

You will:

  • Identify and reduce high‑impact security risks across our applications, APIs and internal tools.
  • Strengthen authentication, authorization and access controls.
  • Improve the protection of sensitive and personal data.
  • Design controls that limit the blast radius of compromised accounts, services or infrastructure.
  • Improve security monitoring, auditability and detection of suspicious access patterns.
  • Perform threat modelling and targeted security reviews.
  • Build reusable security capabilities directly into our engineering platform and development lifecycle.
  • Contribute to long‑term architectures around data isolation, encryption, tokenisation and privacy‑preserving systems.
  • Partner with engineering teams to address systemic security risks rather than individual findings.

Where possible, a security requirement should become code rather than documentation.

What we are looking for

You are first and foremost a strong engineer.

You have significant experience building or securing production software and distributed systems. You are comfortable reading and writing production code, designing systems and working directly with Engineering teams.

You have deep security engineering expertise and strong experience in several of the following areas:

  • Application and Product Security
  • API Security
  • IAM, authentication and authorization
  • OAuth2 / OIDC, WebAuthn / FIDO2
  • RBAC / ABAC and privilege management
  • Cryptography, KMS / HSM and envelope encryption
  • Tokenisation and secrets management
  • Data Security and Privacy Engineering
  • Threat modelling and secure software architecture
  • Security monitoring and detection

You naturally ask:

  • What happens if this employee becomes malicious?
  • What happens if this backend is compromised?
  • What happens if someone dumps this database?
  • Can this endpoint be called directly?
  • How much data can one account access before we notice?
  • Where else does this information get replicated?
  • Why do we have this data at all?

You think in terms of attack paths, blast radius and least privilege, not just compliance requirements.

Pragmatism

You know that security engineering is a prioritisation problem.

  • something that needs to be fixed this week;
  • something that requires an architectural redesign;
  • something cryptographically elegant but operationally unnecessary.
What would make you stand out

Experience with:

  • large‑scale SaaS or fintech platforms;
  • highly sensitive or regulated data;
  • insider risk or data‑loss prevention;
  • advanced cryptographic or privacy‑enhancing technologies.
What success looks like
  • Sensitive data is exposed to fewer systems and people.
  • Access to sensitive resources is increasingly scoped, attributable and auditable.
  • Compromising a single account or service has a limited blast radius.
  • Security controls are increasingly enforced by the platform rather than by process.
  • Product teams can build secure systems faster and with less friction.
What this role is not

This is not primarily a GRC, SOC, compliance, policy‑writing or penetration‑testing role.

Those disciplines are important, but this role exists to change how our products and systems are engineered.

We expect this person to design systems, write code, influence architecture and ship security capabilities into production.

This position can be based at our offices in Paris, Toulouse, or Montpellier on a flex‑remote basis.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Staff Security Engineer - Remote-ready Platform & Data Privacy
Staff Security Engineer - Remote-ready Platform & Data Privacy

Swile • Paris

Hybride
EUR 110 000 - 150 000
Senior Security Engineer
Senior Security Engineer

Spendesk • Paris

Sur place
EUR 90 000 - 140 000
Associate Security Engineer
Associate Security Engineer

Spendesk • Paris

Sur place
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2
Security Engineer – Full Remote (France) or Hybrid
Security Engineer – Full Remote (France) or Hybrid

Voyage Privé • France

Hybride
EUR 55 000 - 75 000
On-site fitness center
Padel matches
Annual conventions
+1
Senior Software Engineer - Toulouse
Senior Software Engineer - Toulouse

Swile • Toulouse

Sur place
EUR 45 000 - 65 000
Competitive salary and benefits package
Professional development opportunities
Collaborative work environment
Cyber Security Engineer
Cyber Security Engineer

Leap29 • France

Sur place
EUR 70 000 - 100 000
Remote work in France
On-call rotation pay
Senior Software Engineer
Senior Software Engineer

Swile • Montpellier

Sur place
EUR 60 000 - 90 000
DevOps Cybersecurity Engineer
DevOps Cybersecurity Engineer

Jobtailor • Paris

Sur place
EUR 70 000 - 90 000
Hybrid work
Office spaces near public transit
Healthy meal service
+3
Senior Site Reliability Engineer (SRE)
Senior Site Reliability Engineer (SRE)

Swile • Montpellier

Sur place
EUR 50 000 - 80 000
Competitive salary and benefits
Professional development opportunities
Collaborative work environment
Senior Software Engineer
Senior Software Engineer

Swile • Toulouse

Sur place
EUR 65 000 - 90 000
Competitive salary