Senior Security Engineer
Название откроется после отклика или сразу в Pro
Описание от работодателя
ABOUT [компания]
Founded in 2013, [компания] is a tech company that creates mobile games and apps with a mission to entertain the world. Gathering 800 employees, 7 billion downloads, and over 200 million active users, [компания] is the #3 mobile publisher worldwide in terms of downloads after Google and Meta. Our portfolio includes chart-topping games like Mob Control and Block Jam, alongside popular apps such as BeReal and Wizz.
TEAM
The Engineering & Data team builds innovative tech products and platforms to support the impressive growth of their gaming and consumer apps which allow [компания] to stay at the forefront of the mobile industry. The Engineering & Data team plays a key role in [компания]'s long-term strategy. It enables [компания] to both accelerate product diversification and provide a state of the art growth-engine to distribute and scale our games. They create innovative solutions that drive growth with a pragmatic approach, ranging from simple searching to complex machine learning systems.
ROLE
We’re looking for a Senior Security Engineer to join our Engineering & Data team. In this role, you’ll be responsible for a wide variety of topics:
- Security Engineering & Guardrails: Architect, construct, and maintain automated security guardrails and paved paths to foster secure-by-default development environments.
- Shift-Left Architecture Guidance: Collaborate with development teams during the early ideation and design phases to embed secure coding practices and architecture from inception.
- Continuous & Automated Assessment: Develop automated, continuous assessment capabilities that replace manual reviews and scale seamlessly across the business unit.
- Hands-on Code Contribution: Work directly alongside engineers to contribute code for security fixes and paved-path solutions, ensuring security remains the simplest route.
- Self-Service Tooling: Partner with developers to build scalable, self-service security tools that empower teams to detect and remediate risks independently.
- Preventive & Detective Controls: Implement robust preventive and detective controls to deliver ongoing assurance rather than point-in-time security checks.
- Strategic Collaboration & Incident Response: Drive long-term security strategy with key stakeholders while actively participating in periodic on-call rotations for incident support.
- AI-Driven Security Innovation: Utilize AI technologies and methodologies to streamline threat detection, accelerate security evaluations, and advance scalable system protection.
PROFILE (MUST HAVE)
- 5+ years of experience troubleshooting systems, analyzing logs, and automating complex tasks via command-line tools
- 5+ years of experience identifying security vulnerabilities, assessing risks, and constructing mitigation strategies
- 5+ years of hands-on experience with scripting, software development, and security-focused code reviews across standard programming languages
- Demonstrated expertise in recognizing industry-standard security vulnerabilities, understanding threat vector patterns, and applying effective remediation techniques
- Proven track record in a leadership or guidance role, such as a technical lead, mentor, or engineering team lead
- Proficiency in applying threat modeling and comprehensive risk identification methodologies
- Proven track record securing microservices, service-oriented architectures, and web services
- Experience with identity provider servers and authentication protocols (such as OAuth2, OIDC, SAML)
- Experience with penetration testing (pentest) and vulnerability assessments
- Self-starter with strong ownership, accountability, and ability to work autonomously and collaboratively across teams and organizations in a fast-paced environment.
PROFILE (NICE TO HAVE)
- Advocate for security standards with clarity and empathy.
- Familiarity with AI/ML workflows and agents.
OUR STACK
Terraform, Kubernetes, Prometheus, ArgoCD, CircleCI, GitHub Actions, Atlantis, Grafana, Claude Code, Trivy, Conftest / OPA, AWS IAM Identity Center (SSO), Okta, AWS Secrets Manager, AWS KMS, AWS WAFv2, AWS Shield, AWS ACM, AWS GuardDuty, Sealed Secrets, Kyverno, cert-manager
BENEFITS
- Competitive salary based on experience
- Swile Lunch voucher
- Gymlib (100% covered by [компания])
- Premium healthcare coverage with SideCare, 100% covered for you and your family
- Wellness activities in our Paris office
- Remote Fridays