Staff Security Engineer
Swile · Paris, France
- Location
- Paris, France
- Level
- Staff
- Posted
- Today
About a minute 500 free credits No card
- I read this posting
- Rewrite your resume against it
- Draft the cover letter, score the fit
Prefer Swile’s own form? Open the original posting
About this role
Build security platforms, not security processes
We are looking for a Staff Security Engineer to strengthen the security of our products, data and engineering platform.
This is a highly technical and hands-on role. You will work closely with Engineering teams to continuously harden our systems while helping design the next generation of our security architecture.
You will operate across two horizons:
Strengthen security today: continuously harden our applications, access controls and data-protection mechanisms against evolving threats.
Build the privacy architecture of tomorrow: move beyond traditional perimeter and access-control security by designing systems where sensitive data is cryptographically isolated, minimally exposed, and increasingly usable without being directly revealed.
The ultimate objective is not simply to make Swile harder to breach. It is to make a breach increasingly uninteresting, because there is less usable data available to steal.
What you will do
Identify and reduce high-impact security risks across our applications, APIs and internal tools.
Strengthen authentication, authorization and access controls.
Improve the protection of sensitive and personal data.
Design controls that limit the blast radius of compromised accounts, services or infrastructure.
Improve security monitoring, auditability and detection of suspicious access patterns.
Perform threat modelling and targeted security reviews.
Build reusable security capabilities directly into our engineering platform and development lifecycle.
Contribute to long-term architectures around data isolation, encryption, tokenisation and privacy-preserving systems.
Partner with engineering teams to address systemic security risks rather than individual findings.
We want Security Engineering to create capabilities that scale across hundreds of engineers.
You will:
Where possible, a security requirement should become code rather than documentation.
What we are looking for
Application and Product Security
API Security
IAM, authentication and authorization
OAuth2 / OIDC, WebAuthn / FIDO2
RBAC / ABAC and privilege management
Cloud security
Cryptography, KMS / HSM and envelope encryption
Tokenisation and secrets management
Data Security and Privacy Engineering
Threat modelling and secure software architecture
Security monitoring and detection
What happens if this employee becomes malicious?
What happens if this backend is compromised?
What happens if someone dumps this database?
Can this endpoint be called directly?
How much data can one account access before we notice?
Where else does this information get replicated?
Why do we have this data at all?
something that needs to be fixed this week;
something that requires an architectural redesign;
something cryptographically elegant but operationally unnecessary.
large-scale SaaS or fintech platforms;
highly sensitive or regulated data;
multi-tenant architectures;
insider risk or data-loss prevention;
advanced cryptographic or privacy-enhancing technologies.
Sensitive data is exposed to fewer systems and people.
Access to sensitive resources is increasingly scoped, attributable and auditable.
Compromising a single account or service has a limited blast radius.
Security controls are increasingly enforced by the platform rather than by process.
Product teams can build secure systems faster and with less friction.
You are first and foremost a strong engineer.
You have significant experience building or securing production software and distributed systems. You are comfortable reading and writing production code, designing systems and working directly with Engineering teams.
You have deep security engineering expertise and strong experience in several of the following areas:
Stronger attacker mindset
You naturally ask:
You think in terms of attack paths, blast radius and least privilege, not just compliance requirements.
Pragmatism
You know that security engineering is a prioritisation problem.
You can distinguish between:
You are comfortable deploying simple, high-impact controls quickly while designing stronger long-term foundations.
What would make you stand out
Experience with:
What success looks like
What this role is not
This is not primarily a GRC, SOC, compliance, policy-writing or penetration-testing role.
Those disciplines are important, but this role exists to change how our products and systems are engineered.
We expect this person to design systems, write code, influence architecture and ship security capabilities into production.
Localization of this position
- This position can be based at our offices in Paris, Toulouse, or Montpellier on a flex-remote basis.
As published by Swile. Applications are handled on their site.
One click, then it is written
Apply to Swile with a resume written for this role.
Queue Staff Security Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Swile’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 500 free credits
- No card
- Nothing sent until you say so
More roles at Swile
See all- 2 weeks ago
- 3 weeks ago
- 5 weeks ago
- 2 months ago
- 2 months ago
- 2 months ago
Similar roles elsewhere
See more- Today
- Today
Senior Forward Deployed Engineer - Full stack
DatabricksParis, France
$75k - $125k/yrSeniorEngineering - Yesterday
Intern Technology & Management Consulting (Value Engineering)
CelonisParis, France
InternshipEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Swile publishes. Refolk is not the employer and does not handle their hiring. Applications go to Swile directly.