573,000open jobs
23,970companies
78,613added this week
Browse all
Salary
$71k – $170k per year (Estimated)
Location
Remote/Hybrid (Montpellier, France)
Seniority
Staff
Employment
Full-Time
Overview
Company
Impact
Profile match
Swile is a Montpellier company founded in 2018 that replaced paper meal vouchers with a single smart card and mobile app. Its platform bundles meal and gift benefits, team engagement features and employee surveys for human resources departments. Backed by SoftBank, it expanded into Brazil through the acquisition of Vee Beneficios.

Build security platforms, not security processes

We are looking for a Staff Security Engineer to strengthen the security of our products, data and engineering platform.

This is a highly technical and hands-on role. You will work closely with Engineering teams to continuously harden our systems while helping design the next generation of our security architecture.

You will operate across two horizons:

  • Strengthen security today: continuously harden our applications, access controls and data-protection mechanisms against evolving threats.

  • Build the privacy architecture of tomorrow: move beyond traditional perimeter and access-control security by designing systems where sensitive data is cryptographically isolated, minimally exposed, and increasingly usable without being directly revealed.

The ultimate objective is not simply to make Swile harder to breach. It is to make a breach increasingly uninteresting, because there is less usable data available to steal.

What you will do

    We want Security Engineering to create capabilities that scale across hundreds of engineers.

    You will:

    • Identify and reduce high-impact security risks across our applications, APIs and internal tools.

    • Strengthen authentication, authorization and access controls.

    • Improve the protection of sensitive and personal data.

    • Design controls that limit the blast radius of compromised accounts, services or infrastructure.

    • Improve security monitoring, auditability and detection of suspicious access patterns.

    • Perform threat modelling and targeted security reviews.

    • Build reusable security capabilities directly into our engineering platform and development lifecycle.

    • Contribute to long-term architectures around data isolation, encryption, tokenisation and privacy-preserving systems.

    • Partner with engineering teams to address systemic security risks rather than individual findings.

    • Where possible, a security requirement should become code rather than documentation.

What we are looking for

    You are first and foremost a strong engineer.

    You have significant experience building or securing production software and distributed systems. You are comfortable reading and writing production code, designing systems and working directly with Engineering teams.

    You have deep security engineering expertise and strong experience in several of the following areas:

  • Application and Product Security

  • API Security

  • IAM, authentication and authorization

  • OAuth2 / OIDC, WebAuthn / FIDO2

  • RBAC / ABAC and privilege management

  • Cloud security

  • Cryptography, KMS / HSM and envelope encryption

  • Tokenisation and secrets management

  • Data Security and Privacy Engineering

  • Threat modelling and secure software architecture

  • Security monitoring and detection

  • Stronger attacker mindset

    You naturally ask:

  • What happens if this employee becomes malicious?

  • What happens if this backend is compromised?

  • What happens if someone dumps this database?

  • Can this endpoint be called directly?

  • How much data can one account access before we notice?

  • Where else does this information get replicated?

  • Why do we have this data at all?

  • You think in terms of attack paths, blast radius and least privilege, not just compliance requirements.

    Pragmatism

    You know that security engineering is a prioritisation problem.

    You can distinguish between:

  • something that needs to be fixed this week;

  • something that requires an architectural redesign;

  • something cryptographically elegant but operationally unnecessary.

  • You are comfortable deploying simple, high-impact controls quickly while designing stronger long-term foundations.

    What would make you stand out

    Experience with:

  • large-scale SaaS or fintech platforms;

  • highly sensitive or regulated data;

  • multi-tenant architectures;

  • insider risk or data-loss prevention;

  • advanced cryptographic or privacy-enhancing technologies.

  • What success looks like

  • Sensitive data is exposed to fewer systems and people.

  • Access to sensitive resources is increasingly scoped, attributable and auditable.

  • Compromising a single account or service has a limited blast radius.

  • Security controls are increasingly enforced by the platform rather than by process.

  • Product teams can build secure systems faster and with less friction.

  • What this role is not

    This is not primarily a GRC, SOC, compliance, policy-writing or penetration-testing role.

    Those disciplines are important, but this role exists to change how our products and systems are engineered.

    We expect this person to design systems, write code, influence architecture and ship security capabilities into production.

Localization of this position

    This position can be based at our offices in Paris, Toulouse, or Montpellier on a flex-remote basis.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
573,000 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Montpellier
$100k – $168k per year • In office • Full-Time • Jersey City • Princeton
DevOps
Rest API
Azure
AWS
IAM
Cybersecurity
Okta
CyberArk
GDPR
HIPAA
Least Privilege
Apply
$81k – $157k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree • Ireland
Python
JavaScript
PowerShell
DevOps
GCP
Azure
CI/CD
AWS
Platform Engineering
IAM
Cybersecurity
Okta
CyberArk
Least Privilege
Microsoft Entra ID
Apply
$36k – $91k per year (Estimated) • Remote • 5+ years exp
Python
Go
JavaScript
Java
TypeScript
AI/ML
Copilot
Cursor
Fine-tuning
TensorFlow
PyTorch
RAG
LLM Guardrails
Frontend
Next.js
React.js
DevOps
Terraform
GCP
CI/CD
AWS
Kubernetes
Vector
FinOps
IAM
Cybersecurity
SOC 2
Least Privilege
Apply
In office • 10+ years exp • Bachelor's Degree • Calgary
DevOps
Azure
IAM
Cybersecurity
Okta
Zero Trust
Microsoft Entra ID
Ping Identity
Auth0
Apply
$40k – $87k per year (Estimated) • In office • Full-Time • 20+ years exp • Bachelor's Degree • Pune
Python
JavaScript
TypeScript
C#
C#
ASP.NET Core
Databases
Apache Kafka
AI/ML
Hadoop
Spark
Prompt Engineering
AI Agents
Frontend
GraphQL
Angular
DevOps
Terraform
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Bicep
IAM
Management
Agile
Apply
$34k – $92k per year (Estimated) • Remote/Hybrid • Full-Time • São Paulo
Marketing
Salesforce
Apply
$34k – $93k per year (Estimated) • Remote/Hybrid • Full-Time
Marketing
Salesforce
Apply
$71k – $170k per year (Estimated) • Remote/Hybrid • Full-Time • Toulouse
DevOps
IAM
Cybersecurity
Least Privilege
Apply
$34k – $93k per year (Estimated) • Remote/Hybrid • Full-Time • Rio de Janeiro
Marketing
Salesforce
Apply
$80k – $189k per year (Estimated) • Remote/Hybrid • Full-Time • Paris
DevOps
IAM
Cybersecurity
Least Privilege
Apply
$71k – $157k per year (Estimated) • In office • Full-Time • Montpellier
JavaScript
TypeScript
Frontend
Zustand
Redux
React.js
React Query
DevOps
CI/CD
Git
QA
Cypress
Jest
Apply
$31k – $66k per year (Estimated) • In office • Internship • Montpellier
Java
Databases
Apache Kafka
DevOps
Jenkins
Docker
Kubernetes
Management
Agile
Apply
$71k – $118k per year • In office • Full-Time • 3+ years exp • Marseille • Toulouse • Montpellier
Apply
$58k – $131k per year (Estimated) • In office • Full-Time • 6+ years exp • Montpellier
Design
Figma
Apply
$57k – $128k per year (Estimated) • In office • Full-Time • 5+ years exp • Montpellier
Design
Figma
Sketch
InVision
Management
Agile
Apply
See all jobs
This is one of many
573,000 more open roles from verified company boards, updated every day.