Jobs Companies Swile Staff Security Engineer

À propos de ce poste Staff Security Engineer chez Swile

Swile · Hybride · Montpellier, France

Build security platforms, not security processes

We are looking for a Staff Security Engineer to strengthen the security of our products, data and engineering platform.

This is a highly technical and hands-on role. You will work closely with Engineering teams to continuously harden our systems while helping design the next generation of our security architecture.

You will operate across two horizons:

  • Strengthen security today: continuously harden our applications, access controls and data-protection mechanisms against evolving threats.

  • Build the privacy architecture of tomorrow: move beyond traditional perimeter and access-control security by designing systems where sensitive data is cryptographically isolated, minimally exposed, and increasingly usable without being directly revealed.

The ultimate objective is not simply to make Swile harder to breach. It is to make a breach increasingly uninteresting, because there is less usable data available to steal.

What you will do

We want Security Engineering to create capabilities that scale across hundreds of engineers.

You will:

  • Identify and reduce high-impact security risks across our applications, APIs and internal tools.

  • Strengthen authentication, authorization and access controls.

  • Improve the protection of sensitive and personal data.

  • Design controls that limit the blast radius of compromised accounts, services or infrastructure.

  • Improve security monitoring, auditability and detection of suspicious access patterns.

  • Perform threat modelling and targeted security reviews.

  • Build reusable security capabilities directly into our engineering platform and development lifecycle.

  • Contribute to long-term architectures around data isolation, encryption, tokenisation and privacy-preserving systems.

  • Partner with engineering teams to address systemic security risks rather than individual findings.

  • Where possible, a security requirement should become code rather than documentation.

What we are looking for

You are first and foremost a strong engineer.

You have significant experience building or securing production software and distributed systems. You are comfortable reading and writing production code, designing systems and working directly with Engineering teams.

You have deep security engineering expertise and strong experience in several of the following areas:

  • Application and Product Security

  • API Security

  • IAM, authentication and authorization

  • OAuth2 / OIDC, WebAuthn / FIDO2

  • RBAC / ABAC and privilege management

  • Cloud security

  • Cryptography, KMS / HSM and envelope encryption

  • Tokenisation and secrets management

  • Data Security and Privacy Engineering

  • Threat modelling and secure software architecture

  • Security monitoring and detection

  • Stronger attacker mindset

    You naturally ask:

  • What happens if this employee becomes malicious?

  • What happens if this backend is compromised?

  • What happens if someone dumps this database?

  • Can this endpoint be called directly?

  • How much data can one account access before we notice?

  • Where else does this information get replicated?

  • Why do we have this data at all?

  • You think in terms of attack paths, blast radius and least privilege, not just compliance requirements.

    Pragmatism

    You know that security engineering is a prioritisation problem.

    You can distinguish between:

  • something that needs to be fixed this week;

  • something that requires an architectural redesign;

  • something cryptographically elegant but operationally unnecessary.

  • You are comfortable deploying simple, high-impact controls quickly while designing stronger long-term foundations.

    What would make you stand out

    Experience with:

  • large-scale SaaS or fintech platforms;

  • highly sensitive or regulated data;

  • multi-tenant architectures;

  • insider risk or data-loss prevention;

  • advanced cryptographic or privacy-enhancing technologies.

  • What success looks like

  • Sensitive data is exposed to fewer systems and people.

  • Access to sensitive resources is increasingly scoped, attributable and auditable.

  • Compromising a single account or service has a limited blast radius.

  • Security controls are increasingly enforced by the platform rather than by process.

  • Product teams can build secure systems faster and with less friction.

  • What this role is not

    This is not primarily a GRC, SOC, compliance, policy-writing or penetration-testing role.

    Those disciplines are important, but this role exists to change how our products and systems are engineered.

    We expect this person to design systems, write code, influence architecture and ship security capabilities into production.

    Localization of this position

    This position can be based at our offices in Paris, Toulouse, or Montpellier on a flex-remote basis.
    Prêt à postuler chez Swile ?
    Postuler chez Swile

    Emplois similaires

    Appvia
    Senior Cloud Network Engineer - Active UK Government Security Clearance Required
    Appvia
    ⚡ Postuler tôt London, England, United Kingdo... Sur site
    ● Nouveau 👁 Vu ✓ Postulé il y a 1 h
    Scaleway
    Security Engineer - Pentester
    Scaleway
    ⚡ Postuler tôt Paris Hybride
    ● Nouveau 👁 Vu ✓ Postulé il y a 1 h
    Scaleway
    DevOps Cybersecurity Engineer
    Scaleway
    ⚡ Postuler tôt Paris Hybride
    ● Nouveau 👁 Vu ✓ Postulé il y a 1 h
    Dijital Team Pty Ltd
    L3 Systems Engineer (Systems, Networking & Security)
    Dijital Team Pty Ltd
    ⚡ Postuler tôt Sri Lanka · lieu restreint
    ● Nouveau 👁 Vu ✓ Postulé il y a 2 h
    Bee Talents
    Security & Compliance Engineer/Officer | Bnewable [30-40 EUR/h B2B]
    Bee Talents
    ⚡ Postuler tôt Wrocław Hybride
    ● Nouveau 👁 Vu ✓ Postulé il y a 2 h
    MetroStar
    Cybersecurity Engineer II (6708)
    MetroStar
    ⚡ Postuler tôt Tysons Corner, VA Sur site $166,000–$202,000
    ● Nouveau 👁 Vu ✓ Postulé il y a 2 h
    MetroStar
    Sr. Cybersecurity Engineer II (6708)
    MetroStar
    ⚡ Postuler tôt Herndon, VA Sur site $166,000–$202,000
    ● Nouveau 👁 Vu ✓ Postulé il y a 2 h
    MetroStar
    Cybersecurity Engineer II (6708)
    MetroStar
    ⚡ Postuler tôt Washington, DC Sur site $166,000–$202,000
    ● Nouveau 👁 Vu ✓ Postulé il y a 2 h
    Brainlabs
    Security Operations, Engineer
    Brainlabs
    ⚡ Postuler tôt United Kingdom Sur site
    ● Nouveau 👁 Vu ✓ Postulé il y a 3 h

    Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

    Plus d’emplois chez Swile

    Voir tous les emplois chez Swile →

    Postuler maintenant
    🤖

    Doucement — un instant

    JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

    Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

    Catch your next role the second it’s posted.

    Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

    Create free account

    Free forever · takes 30 seconds · already have one?

    Prenez une longueur d’avance dans votre recherche d’emploi.

    Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

    Rejoindre le canal — c’est gratuit