Cybersecurity Engineer - Internal Security
Stoïk · Paris, Ile-de-France, France
Insurance · 51-200 employees
About the role
The role involves acting as a security counterpart to the tech team for architecture reviews and threat modelling while managing the company's Information Security Management System. You will also oversee security tooling, vulnerability management, and IT platform administration to ensure a secure and compliant environment.
What they look for
Requirements
Candidates must have 3-5 years of experience in security engineering or a hybrid technical/GRC role with strong foundations in cloud, containers, and identity. Proficiency in Python or Go for automation and fluency in both English and French are required.
Full description
About us
Stoïk is a cyber insurtech company, and we insure companies up to €1B of turnover. To have better insurance results we have decided to (1) build prevention tools targeted towards the attacks we see, and (2) have our own incident response team (CERT).
We have raised €50M, protect +14000 insureds, are 175 people, and operate in France, Germany, Austria, Spain and BENELUX.
Our CERT handles +1000 incidents / year, including ransomware events and frauds. Our tech team is 45 people and we have built an EASM tool, a phishing simulation platform, AD and Cloud scans, and many more security tools.
We sell security to our insureds. That obliges us to be exemplary on our own, in front of our insureds, our brokers, our reinsurers and our regulator.
Position Overview
Security at Stoïk is currently a one-person team: the CISO. This role is the second.
This is a deliberately broad role. Roughly half of it sits inside the tech team as its security counterpart; the other half is running our Information Security Management System.
We are not looking for someone who tolerates one half of the job to get to the other. A control written in a policy and never enforced in the pipeline is worthless, and a technical fix nobody can evidence to an auditor is only half done.
You are not expected to ship product code. You are expected to read a pull request, hold your own in a technical debate with a senior engineer, script and automate your own work, and be genuinely welcome in the tech team's rituals.
The security team also owns the tools the company works on every day: MDM, identity, EDR, VPN and our SaaS estate. At our size those tools are the controls, you configure them and you see the effect immediately.
Technologies: Python, Go, Postgres, AWS / Terraform, CrowdStrike, FleetDM, Vanta, Google Workspace, HubSpot, Anthropic, OpenAI… we are a cloud-native company.
Key Responsibilities
- Security engineering with the tech team: act as the security counterpart in design and architecture reviews: threat modelling, risk framing, and recommendations engineers can actually ship. Build secure defaults and guardrails (IaC policies, hardened baselines, paved paths) so that the secure way is the easy way.
- Vulnerability & exposure management: own it end to end across CI/CD, dependencies, containers, cloud workloads and our own external attack surface; triage, prioritisation, and getting fixes over the line.
- Security tooling: own and tune our stack (cloud security posture, SAST / SCA, secrets management, endpoint, identity). Fewer tools, better configured, with alerts someone actually reads.
- ISMS RUN: keep our ISO 27001 certification healthy day to day; control operation, evidence collection, internal audits, management reviews, corrective actions, surveillance audits. Maintain the risk register and drive remediation with the owners who are accountable for it.
- Corporate & IT security: harden our identity, endpoint and SaaS estate; contribute to access management, joiner-mover-leaver and periodic access reviews; contribute to BCP / DRP testing and to security awareness.
- IT platform run: administer the tools the company runs on: MDM (FleetDM), Google Workspace and Microsoft 365 / Entra, Apple Business Manager, CrowdStrike, Tailscale, Dashlane and our SaaS estate. Help colleagues when something breaks, and turn each recurring issue into an automation or a better default.
- AI leverage: evidence collection, control testing, questionnaire responses, log triage, policy drafting, first-pass code review: a large share of this work can be assisted or agent-driven today. You get the tools, the budget and the mandate to build that leverage, and the judgement to know where a human still has to sign.
What you'll gain in this role
- High ownership & scope: you are the second security hire, and you hold the admin console. No committee between you and a fix: when you decide a control is needed, you can ship it the same afternoon, and see straight away whether it holds. What you build becomes how Stoïk does security.
- Real attacker signal: we are a cyber insurer with our own CERT. You will see real incidents, real claims data and real attacker behaviour that most internal security teams never get near, and feed it straight back into our own defences.
- Both halves of the craft: very few roles let you keep your hands in cloud and application security while owning an ISMS end to end. This one is designed to make you unusually complete, and to grow into a broader security leadership scope as we scale.
Qualifications
- Must-Haves:
- 3–5 years in security engineering, cloud / platform security, product security, or a hybrid technical + GRC role.
- Solid technical foundations: cloud (AWS ideally), containers, CI/CD, identity, networking. You can script in Python or Go, not to build products, but to automate your own work and integrate tools.
- The ability to hold both conversations credibly: a design review with a senior engineer in the morning, an audit finding with a director in the afternoon.
- Comfortable getting hands-on with IT: endpoint and MDM management (mostly macOS), identity administration on Google Workspace and / or Entra, SaaS administration.
- Fluent French and English, written and spoken. Our internal work is bilingual and our documentation exists in both.
- Based in Paris, or willing to relocate. Hybrid, with regular time on site.
- A working relationship with AI tooling that goes beyond curiosity. If you see AI as a threat to your craft rather than a multiplier for it, this is not the right team.
- Nice-to-Haves:
- Hands-on ISMS experience, ISO 27001 in particular. You have lived through an audit from the inside, not just read about one.
- Exposure to insurance, financial services or another regulated sector (DORA in particular).
- Detection engineering, incident response or offensive security experience.
- Experience as an early security hire in a scale-up, where nothing is set up yet and that is the point.
- Certifications (OSCP, CISSP, ISO 27001 Lead Implementer / Auditor, cloud security) are welcome, never a substitute for demonstrated experience.
Hiring Process
- Call with the CISO, 30 min
- On-site technical interview: cloud & application security, threat modelling, with the CISO and a Tech Lead, 60 min
- "Live" case on an ISMS / compliance scenario, discussed on site rather than sent as homework, 60 min
- Cultural fit with Founders (30 min each)