Senior Application Security Engineer

il y a 3 jours


Paris, France Pennylane Temps plein

Are you looking to have an impact on the daily life of millions of entrepreneurs in France (and tomorrow in Europe)?Are you looking for a work environment that values trust, proactivity, and autonomy?Are our Engineering principles aligned with your vision?Then Pennylane is the right place for you Our visionWe aim to become the most beloved financial Operating System of French SMEs and Accounting Firms (and soon, European ones).We help entrepreneurs rid themselves of time-consuming tasks related to accounting and finance while providing them with access to key financial information to assist in making the best decisions for their business.About usPennylane is one of the fastest growing Fintechs in France (and soon to be in Europe)In 5 years of existence, we’ve managed to : Make ourselves known as a groundbreaking accounting and financial software for small businesses and their accountants Raise a total of €225 millions, including from Sequoia, the famous fund from the Silicon Valley who invested early in companies like Google, Facebook, Airbnb, Stripe, Paypal and much more... ‍ ‍ ‍ Grow from 7 cofounders to 900 happy Pennylaners : we’re now recognized as one of the greatest places to work in France (and also remotely), with a 4.6/5 rating on Glassdoor. Build an international environment with more than 25 nationalities, with a strong remote-friendly culture, where 30% of the employees are already working from all parts of Europe Earn the trust of thousands of customers and accounting firms and obtain outstanding ratings  Already more than 700,000 small and medium-sized enterprises (SMEs) and over 5000 accounting firms use Pennylane in France Team and environmentAs we keep on growing (+500 people joined Pennylane in 2025), we're seeking an Application Security Engineer to join Louis's team of 4. Reporting to Guillaume, our Head of Information Security, you'll handle all technical security matters, support ISO 27001 compliance, and advise employees—especially developers—on security best practices.The technical security team manages security issues from detection to resolution, collaborating with developers and Security Champions when needed. Your tasksSecurity by design: - Ensure the security of Pennylane’s application and infrastructure- Engage with Product Team to integrate security in our features from design to delivery - Ensure the security of the main Web application written in Ruby on Rails and ReactJS: its dependencies, its code, its infrastructure and its configuration- Conducting code reviews from a secure development point of view (about 80 releases per day).- Detect vulnerability and propose associated patches- Raise the security level of our CI/CD configuration- With the DevOps team, secure our AWS infrastructure, including its Kubernetes environmentVulnerability Management:- Conduct and perform regular security assessments (internally or by an external companies) on the applications (code reviews/pentests/bug bounty in particular) and the infrastructure- Strengthen the current means of detecting malicious attempts- Be involved in all security incidents, investigate logs, block attacks, and propose corrective measures to prevent future threats.Compliance & awareness:- Ensure compliance with ISO 27001 controls (processes) related to development (mandatory code practices, validation, patch management, vulnerability management, etc.) by training developers, monitoring projects, conducting regular internal audits and managing tech non-conformities- Build/Improve secure development training materials and conduct regular training sessions with the developers. Engaging them in our Security Champions program- Improve the security awareness through the company- Contribute to tenders to explain our security policies and provide the necessary technical detailsThese missions are not exhaustive and remain evolving. You’re the right candidate ifYou ideally have the following skills/experience:- Able to perform offensive security assessments on an infrastructure and an application- You know how to exploit and fix a wide range of Web vulnerabilities and are able to explain them to non-technical person (not just the OWASP top 10)- You already have an experience in a programming language (Ruby, Python, JavaScript), either for quick and dirty scripting to exploit a vulnerability or for larger projects- You have an experience in cloud infrastructure security- You are able to popularize technical terms to facilitate the adoption of security measures within projects or to broadcast messages to Pennylaners- You are fluent in French and/or English (both oral and written)Your soft skills :- You are humble- You are a team player, and working with remote colleagues is not an issue for you- You are proactive and organized- You are a quick learner, and you like to work on different projects (application security, cloud infrastructure, training, ISO 27001…)  What does the recruitment process look like ?- You will first have a general chat with Alexandre, Talent Acquisition (30min)- Then you’ll meet Louis, (AppSec Team Lead) and 1 team member for a technical interview (1h)- You carry out independently the technical challenge for the next 48h- Then, you’ll discuss about your solutions with Louis and another team member - (1h)- Finally, a last culture fit meeting with Guillaume, Head of Security (1h)We make sure we move fast; you can expect the recruitment process with us to last between 15 and 25 days in total.What do we do to make your work life easier  Wherever you are based, you will get 25 vacations days paid by Pennylane You’ll have a competitive compensation package You'll get company shares to enjoy a piece of the success story you're building with us You’ll have a budget to turn your home into a more comfortable workspace, as well as a monthly allowance to work from a coworking space whenever you feel like it⛹️ Through our partner Gymlib, you’ll have access to 8000 fitness spaces in Europe and more than 300 activities related to wellness You’ll have access to Busuu to perfect your English or your French You’ll get the latest Apple equipment Depending on the teams and the requirements of the position - you'll be able to work remotely from your country of residence, as long as it is in Europe and within a maximum time difference of two hours from the CET time zone We are committed to regularly coming together for company events such as Tech Days (which bring remote Pennylaners together every 3 months) or our annual company seminar, fostering significant moments of cohesion for everyone.If you are based in France, you will have a French contract following French regulation on top of the additional perks : 6 to 12 RTT, 5 weeks PTOs, lunch credits (Swile), Alan Blue healthcare cover and regular events in cities where Pennylaners are mostly presents (Lyon, Bordeaux, Nantes…)We're working on providing those last advantages to our people based outside of France as well, but it can be quite more complex depending on different countries.Who are we looking for ?To thrive at Pennylane, you need :-To speak English (level is assessed and appreciated according to the department you’re applying to)-To be energized by an ever-shifting work environment-To be highly collaborative (within your team or other stakeholders)-Sufficiently experienced to prioritize business-led actions on your day to day activityWe know that some people are less likely to apply than others, if they don’t feel like they meet the full list of criteria.If you’re hesitating, we encourage you to apply : who knows, it might be the start of a meaningful and long-lasting collaboration.We also want to emphasize that we fully embrace diversity, equity and inclusion and that we’re doing our best to create a safe and inclusive environment. We are committed to providing an equal employment opportunity regardless of gender, sexual orientation, origin, disabilities, or any other traits that make you who you are. If anything, diversity makes us a more fun place to work at.Pennylane est une des FinTech à la plus forte croissance en France, et souhaite bientôt adresser le marché européen.En 5 ans d'existence, nous sommes parvenus à : Nous positionner sur le marché comme un éditeur de solution de comptabilité et de gestion financière innovant Lever un total de 225 millions d'euros, auprès d'investisseurs de renom, dont Sequoïa, le fonds phare de la Silicon Valley, connu pour avoir soutenu Google, Facebook, Airbnb, Stripe, Paypal et bien d'autres à leur début. Passer de 7 cofondateurs à une équipe de 800 collaborateurs, avec une note moyenne de 4,6/5 sur Glassdoor et 94% des évaluateurs Glassdoor qui recommanderaient PL à leurs proches Construire une équipe internationale composée de collaborateurs issus de 25 pays différents, avec une culture du télétravail très flexible Gagner la confiance de milliers d'utilisateurs et obtenir d'excellents retours  Déjà plus de 500,000 TPE/PME et plus de 5000 cabinets d’expertise-comptable utilisent Pennylane en France Notre équipe Tech se compose d'environ 230 personnes (Ingénieurs Backend, Fullstack et Frontend, Engineering Managers et Senior Engineering Managers)Chaque ingénieur fait partie d’une squad dédiée à un périmètre spécifique du produit, sous la responsabilité d’un Engineering Manager et en étroite collaboration avec un Product Manager et un Product Designer.Chaque squad réunit toutes les compétences nécessaires pour concevoir, développer et livrer des fonctionnalités de bout en bout, en totale autonomie.


  • Senior Security Engineer

    il y a 1 semaine


    Paris, France un emploi de Security Expert Temps plein

    Une entreprise d'e-commerce leader recherche un·e Senior Security Engineer pour rejoindre son équipe à Lille ou Paris. Ce rôle implique de travailler sur la cybersécurité pour renforcer la protection des systèmes d'information. Le candidat idéal aura une formation en informatique et une solide expérience en cybersécurité, avec d'excellentes...


  • Paris, Île-de-France PENNYLANE Temps plein

    Are you looking to have an impact on the daily life of millions of entrepreneurs in France (and tomorrow in Europe)?Are you looking for a work environment that values trust, proactivity, and autonomy?Are our Engineering principles aligned with your vision?Then Pennylane is the right place for you Our visionWe aim to become the most beloved financial...


  • Paris, Île-de-France Pennylane Temps plein

    Are you looking to have an impact on the daily life of millions of entrepreneurs in France (and tomorrow in Europe)?Are you looking for a work environment that values trust, proactivity, and autonomy?Are our Engineering principles aligned with your vision?Then Pennylane is the right place for you Our visionWe aim to become the most beloved financial...


  • Paris, France CryptoNext Security Temps plein

    A leading deeptech startup in Paris is hiring a Senior Probe Appliance Engineer. In this role, you will have full technical ownership of the COMPASS probe appliance, focusing on system installation, performance optimization, and security hardening. You will collaborate with R&D and data engineering teams to ensure integration and quality. This position...

  • Senior Security Engineer

    il y a 1 semaine


    Paris, France Qonto Temps plein

    Our mission Creating the freedom for SMEs to succeed in business and beyond, by delivering Europe’s leading finance workspace. We combine business-class tools (seamless invoicing, spend management, and pre-accounting) with unwaveringly attentive 24/7 support, designed to help businesses breeze through all things finance. Our journey Founded by Alexandre...


  • Paris, France Qonto Temps plein

    A financial technology company in Paris is looking for a Security Engineer to safeguard systems and applications, ensuring a seamless tech stack with AWS and Kubernetes. You will audit applications, investigate incidents and shape the security roadmap. Ideal candidates have hands-on cloud experience and programming skills in Python or Golang. Join a dynamic...

  • Senior Security Engineer

    il y a 2 semaines


    Paris, Île-de-France Qonto Temps plein

    Our mission? Creating the freedom for SMEs to succeed in business and beyond, by delivering Europe's leading finance workspace. We combine business-class tools (seamless invoicing, spend management, and pre-accounting) with unwaveringly attentive 24/7 support, designed to help businesses breeze through all things finance. Our journey: Founded by...

  • Senior Security Engineer

    il y a 1 semaine


    Paris, France Qonto Temps plein

    Our mission Creating the freedom for SMEs to succeed in business and beyond, by delivering Europe’s leading finance workspace. We combine business-class tools (seamless invoicing, spend management, and pre-accounting) with unwaveringly attentive 24/7 support, designed to help businesses breeze through all things finance. Our journey Founded by Alexandre...

  • Senior Security Engineer

    il y a 2 semaines


    Paris, Île-de-France Qonto Temps plein

    Our mission? Creating the freedom for SMEs to succeed in business and beyond, by delivering Europe's leading finance workspace. We combine business-class tools (seamless invoicing, spend management, and pre-accounting) with unwaveringly attentive 24/7 support, designed to help businesses breeze through all things finance.Our journey:Founded by Alexandre and...


  • All France (remote) / Paris / Madrid / Rome / Portugal / Allemagne / Bucharest / Croatia / Greece / Poland / Ireland / London Pennylane Temps plein

    Are you looking to have an impact on the daily life of millions of entrepreneurs in France (and tomorrow in Europe)? Are you looking for a work environment that values trust, proactivity, and autonomy? Are our Engineering principles aligned with your vision? Then Pennylane is the right place for you Our vision We aim to become the most beloved financial...