Cybersecurity Engineer - Internal Security

Stoïk
Paris

About us

Stoïk is a cyber insurtech company, and we insure companies up to €1B of turnover. To have better insurance results we have decided to (1) build prevention tools targeted towards the attacks we see, and (2) have our own incident response team (CERT).

We have raised €50M, protect +14000 insureds, are 175 people, and operate in France, Germany, Austria, Spain and BENELUX.

Our CERT handles +1000 incidents / year, including ransomware events and frauds. Our tech team is 45 people and we have built an EASM tool, a phishing simulation platform, AD and Cloud scans, and many more security tools.

We sell security to our insureds. That obliges us to be exemplary on our own, in front of our insureds, our brokers, our reinsurers and our regulator.

Position Overview

Security at Stoïk is currently a one-person team: the CISO. This role is the second.

This is a deliberately broad role. Roughly half of it sits inside the tech team as its security counterpart; the other half is running our Information Security Management System.

We are not looking for someone who tolerates one half of the job to get to the other. A control written in a policy and never enforced in the pipeline is worthless, and a technical fix nobody can evidence to an auditor is only half done.

You are not expected to ship product code. You are expected to read a pull request, hold your own in a technical debate with a senior engineer, script and automate your own work, and be genuinely welcome in the tech team's rituals.

The security team also owns the tools the company works on every day: MDM, identity, EDR, VPN and our SaaS estate. At our size those tools are the controls, you configure them and you see the effect immediately.

Technologies: Python, Go, Postgres, AWS / Terraform, CrowdStrike, FleetDM, Vanta, Google Workspace, HubSpot, Anthropic, OpenAI… we are a cloud-native company.

Key Responsibilities

  1. Security engineering with the tech team: act as the security counterpart in design and architecture reviews: threat modelling, risk framing, and recommendations engineers can actually ship. Build secure defaults and guardrails (IaC policies, hardened baselines, paved paths) so that the secure way is the easy way.

  2. Vulnerability & exposure management: own it end to end across CI/CD, dependencies, containers, cloud workloads and our own external attack surface; triage, prioritisation, and getting fixes over the line.

  3. Security tooling: own and tune our stack (cloud security posture, SAST / SCA, secrets management, endpoint, identity). Fewer tools, better configured, with alerts someone actually reads.

  4. ISMS RUN: keep our ISO 27001 certification healthy day to day; control operation, evidence collection, internal audits, management reviews, corrective actions, surveillance audits. Maintain the risk register and drive remediation with the owners who are accountable for it.

  5. Corporate & IT security: harden our identity, endpoint and SaaS estate; contribute to access management, joiner-mover-leaver and periodic access reviews; contribute to BCP / DRP testing and to security awareness.

  6. IT platform run: administer the tools the company runs on: MDM (FleetDM), Google Workspace and Microsoft 365 / Entra, Apple Business Manager, CrowdStrike, Tailscale, Dashlane and our SaaS estate. Help colleagues when something breaks, and turn each recurring issue into an automation or a better default.

  7. AI leverage: evidence collection, control testing, questionnaire responses, log triage, policy drafting, first-pass code review: a large share of this work can be assisted or agent-driven today. You get the tools, the budget and the mandate to build that leverage, and the judgement to know where a human still has to sign.

What you'll gain in this role

  1. High ownership & scope: you are the second security hire, and you hold the admin console. No committee between you and a fix: when you decide a control is needed, you can ship it the same afternoon, and see straight away whether it holds. What you build becomes how Stoïk does security.

  2. Real attacker signal: we are a cyber insurer with our own CERT. You will see real incidents, real claims data and real attacker behaviour that most internal security teams never get near, and feed it straight back into our own defences.

  3. Both halves of the craft: very few roles let you keep your hands in cloud and application security while owning an ISMS end to end. This one is designed to make you unusually complete, and to grow into a broader security leadership scope as we scale.

Qualifications

  • Must-Haves:

    • 3–5 years in security engineering, cloud / platform security, product security, or a hybrid technical + GRC role.

    • Solid technical foundations: cloud (AWS ideally), containers, CI/CD, identity, networking. You can script in Python or Go, not to build products, but to automate your own work and integrate tools.

    • The ability to hold both conversations credibly: a design review with a senior engineer in the morning, an audit finding with a director in the afternoon.

    • Comfortable getting hands-on with IT: endpoint and MDM management (mostly macOS), identity administration on Google Workspace and / or Entra, SaaS administration.

    • Fluent French and English , written and spoken. Our internal work is bilingual and our documentation exists in both.

    • Based in Paris, or willing to relocate. Hybrid, with regular time on site.

    • A working relationship with AI tooling that goes beyond curiosity. If you see AI as a threat to your craft rather than a multiplier for it, this is not the right team.

  • Nice-to-Haves:

    • Hands-on ISMS experience, ISO 27001 in particular. You have lived through an audit from the inside, not just read about one.

    • Exposure to insurance, financial services or another regulated sector (DORA in particular).

    • Detection engineering, incident response or offensive security experience.

    • Experience as an early security hire in a scale-up, where nothing is set up yet and that is the point.

    • Certifications (OSCP, CISSP, ISO 27001 Lead Implementer / Auditor, cloud security) are welcome, never a substitute for demonstrated experience.

Hiring Process

  • Call with the CISO, 30 min

  • On-site technical interview: cloud & application security, threat modelling, with the CISO and a Tech Lead, 60 min

  • "Live" case on an ISMS / compliance scenario, discussed on site rather than sent as homework, 60 min

  • Cultural fit with Founders (30 min each)

Publié le 2026-08-07

Emplois Recommandés

Document Controller F/H

ARKADIA Group
Paris 2e

Basée sur des valeurs humaines fortes et une intégration profonde dans les processus décisionnels de ses clients, ARKADIA se développe et recrute un Document Controller pour intervenir en support proj…

Voir les Détails
Publié le 2026-07-17

Ergothérapeute H/F temps partiel 80%

Association Chemins d'Espérance
Paris

Ergothérapeute H/F temps partiel 80% stp25ag6t3 La direction recherche un (e) ergothérapeute pour l’EHPAD Amitié et Partage. Sous la responsabilité de l'infirmière coordinatrice, les missions sont le…

Voir les Détails
Publié le 2026-07-12

CONTROLEUR DE GESTION (H/F) - ALTERNANCE

WONDERBOX
Paris

Rejoindre la Wonder Aventure, c'est intégrer un Groupe leader européen des solutions cadeaux qui propose des expériences clés en mains dans l'univers du sport, du bien-être, de la gastronomie et du s…

Voir les Détails
Publié le 2026-07-21

Data Engineer Microsoft Fabric - Freelance

Collective.work
Paris

Taux journalier (TJM): 450 Nous recherchons pour un de nos clients un Data Engineer Microsoft Fabric Compétences obligatoires Microsoft Fabric (2 ans d'expérience minimum ) PySpark Lakeh…

Voir les Détails
Publié le 2026-07-24

Ingénieur Qualification Validation - H/F

NEO2 Consultant
Paris

L'ENTREPRISE Créé en 2008, NEO2 est une société de conseil et d'assistance technique, spécialisée dans les métiers de l’ingénierie de process et des infrastructures industrielles. Notre groupe …

Voir les Détails
Publié le 2026-06-16

Tax Manager (Malta)

TechBiz Global GmbH
Paris

At TechBiz Global, we are providing recruitment service to our TOP clients from our portfolio. We are currently seeking an Tax Manager specialist to join one of our clients ' teams. If you're lo…

Voir les Détails
Publié le 2026-05-23

Econome H/F - PARIS SOCIETY

The Hoxton
Paris

Description de l'entreprise Notre histoire : Avec un catalogue de plus de cinquante lieux, le groupe Paris Society, fondé en 2008 par Laurent de GOURCUFF, est un acteur incontournable de l’hos…

Voir les Détails
Publié le 2026-08-01

Animateur en centre d'hébergement F/H

Ville de Paris
Paris 19e

Détails de l'offre Famille de métiers Autonomie et aide à domicile Accueil et accompagnement …

Voir les Détails
Publié le 2026-08-03

Responsable développement commercial (H/F)

Partnaire
Paris

Description de l'offre PARTNAIRE, Cabinet de Recrutement, recherche pour son client, expert en conception d'outillages et injection plastique, un Responsable Développement Commercial (H/F), en CDI…

Voir les Détails
Publié le 2026-07-31

Préparateur en Pharmacie Hospitalière (H/F)

Hôpital Paris Saint-Joseph
Paris

Description de l'entreprise Les Hôpitaux Paris Saint-Joseph (Paris 14e) et Marie-Lannelongue (Le Plessis-Robinson - 92) forment un groupement hospitalier privé à but non lucratif, rattaché à …

Voir les Détails
Publié le 2026-07-24