Technical Security Expert
Paris
Spendesk
Behalten Sie Ihre Unternehmensausgaben im Griff mit Spendesk – der Ausgabenmanagement-Lösung, die alle wichtigen Bereiche Ihres Unternehmens verknüpft.Key Responsibilities
- Support Developers Collaborate closely with development and infrastructure teams, discuss best practices, and promote a security-by-design culture in projects.
- Code Audits Conduct in-depth code reviews to identify and fix security vulnerabilities in TypeScript code produced by developers.
- Dependency Audits via Reverse Engineering Examine third-party libraries and dependencies, analyze their behavior through reverse engineering, and detect potential security flaws or backdoors.
- Infrastructure Audits Perform security audits on Infrastructure-as-Code (IaC) Terraform within a multi-tenant AWS platform.
- Tool Audits Conduct intrusion testing campaigns on the configuration of various internal company tools, including CI/CD pipelines, code management, authentication tools, etc.
- SIEM Management Oversee, configure, and maintain the SIEM system (ElasticSearch, self-hosted, multi-node) to ensure proactive threat detection and rapid security incident response.
- Penetration Testing Plan and execute penetration tests on systems and applications to assess their resistance to attacks and propose remediation strategies.
- Security Policies & Compliance Contribute to updating security policies, standards, and technical procedures to ensure compliance with best practices and regulatory requirements.Supervise their implementation and promote security best practices.
- Threat & Vulnerability Monitoring Stay up to date on emerging threats, vulnerabilities, and attack techniques and recommend appropriate defense strategies.
- Incident Detection & Response Automation Develop scripts and tools to automate security tasks, including incident detection and response.
- Training & Awareness
- Train and raise awareness among internal teams about security challenges, secure coding practices, and security tool usage.
Who we are looking for
- Minimum 10 years of experience in information security with proven technical expertise.
- Strong experience in development and code auditing, particularly in TypeScript, Node.js, and Python.
- Proficiency in ElasticSearch, with the ability to deploy and maintain a multi-node Linux infrastructure from scratch.
- Expertise in reverse engineering and analyzing minified or obfuscated code.
- Deep knowledge of decentralized web architecture (microservices) and PaaS/SaaS providers (AWS, GCP, Datadog, Snowflake, etc.).
- Experience in penetration testing and security audits.
- Strong scripting skills (Python, Bash, etc.).
- Advanced knowledge of security standards is a plus (ISO 27001, OWASP, etc.).
- Ability to work in a team and collaborate with engineers from diverse backgrounds.
- Excellent communication and teaching skills.
- Strong analytical and problem-solving mindset.
- Ability to remain calm and act decisively in crisis situations.
- Fluent English required.
- French is a plus.
About Spendesk Spendesk is the 7-in-1 spending solution built for finance teams to make faster, smarter spending decisions. Founded in 2016, Spendesk is now one of the fastest-growing fintechs in Europe, with over 4,000 customers and an international team of 300+ employees based in Paris, Berlin, London, Hamburg, and remote. We’ve raised over €260M from leading investors, and been named a French tech unicorn. And we’re not stopping there!
About our people & cultureWe believe that people do their best work when they’re given the freedom to thrive and grow. That’s why liberation is at the core of everything we do. We empower Spendeskers to take ownership of their work, to navigate ambiguity, and seize every opportunity. Spendeskers come from all over the world (35+ countries and counting!) but we have plenty in common: we're bold, ever-curious, committed to kindness, and tackle every challenge with a positive mindset.
About our benefits Our culture is built on trust, empowerment, and growth — with benefits to match!
- Lunch 60% funded by Spendesk (Swile Card) - Alan Premium health insurance - A Gymlib pass to let off steam after a productive day at work - Access to Moka.care for emotional and mental health wellbeing - Access to Vendredi allowing us to change the world - Latest Apple equipment - Great office snacks to fuel your day - A positive team to work with daily!
Diversity & InclusionAt Spendesk, we're committed to fostering an environment where all differences are encouraged, supported and celebrated. We're building our culture for everyone, with everyone. Our goal is to attract and build a diverse, equal and inclusive team, where everyone feels welcome and we truly embrace and encourage people from all backgrounds to apply.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Automation AWS Bash CI/CD Compliance Elasticsearch Finance GCP Incident response ISO 27001 Linux Microservices Monitoring Node.js OWASP PaaS Pentesting Python Reverse engineering SaaS Scripting SIEM Snowflake Teaching Terraform Threat detection TypeScript Vulnerabilities
Perks/benefits: Health care
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.