Lead Security Engineer

il y a 1 semaine


Paris, France Nabla Temps plein

2 days ago Be among the first 25 applicants About Nabla We are a team of entrepreneurs, clinicians and engineers committed to bringing back joy to the practice of medicine. Together with a community of clinician innovators, we’ve harnessed the best of machine learning science to develop Nabla: the leading AI assistant that’s restoring the human connection at the heart of healthcare. By streamlining clinical documentation, Nabla is helping clinicians focus on matters most - patient care. Today, over 85,000 clinicians across 130+ healthcare organizations trust Nabla to support how they deliver care every day. We’re at the start of an ambitious journey: Ambient listening, dictation, coding, and command capabilities are all converging into a proactive assistant that intuitively streamlines clinical and financial workflows. Backed by a recent $70M Series C, we’re hiring to build the next generation of clinical AI and improve the lives of clinicians and patients everywhere. Engineering at Nabla Engineering at Nabla is lean, fast-moving, and deeply technical. Our teams span machine learning, native desktop applications, and platform infrastructure to deliver AI into clinical settings reliably and at scale. Lead Security Engineer We are looking for a hands‑on lead security engineer to own the technical side of our security program. You’ll partner with our Head of Information Security and Head of IT to build and operate a best‑in‑class infrastructure and application security function. Our SaaS is fully hosted on Google Cloud and handles highly sensitive healthcare data, so security is core to everything we do. This role is ideal for a senior security engineer or manager who wants to take ownership, and build a security engineering function from the ground up in a fast‑scaling startup environment. Your Team You will report to the CTO and work closely with the Head of Security, Engineering Managers, and Operations. This is a high‑trust, high‑ownership role with broad cross‑functional exposure. What You’ll Do Infrastructure Security Harden our Google Cloud infrastructure (network, firewalls, proxies, IAM policies, service controls) Deploy and manage web application firewalls, DDoS protection, intrusion detection / prevention systems Ensure security architecture aligns with healthcare compliance requirements (HIPAA, SOC 2, ISO 27001, GDPR) Assess and mitigate security risks related to AI workflows and sensitive data processing pipelines Application Security Define and enforce authentication & authorization strategies for customer‑facing applications (OAuth, SAML/SCIM support, least privilege) in collaboration with IT for internal identity and SSO management Integrate security into the SDLC: SAST, DAST, dependency scanning, IaC scanning, container scanning, and CI/CD pipeline hardening Conduct threat modeling and security reviews for new features and system designs Establish and maintain secure coding guidelines Monitor vulnerabilities and track remediation External Partnerships Support relationships with pentesting firms, security assessors, and red‑teaming partners Operate vulnerability disclosure and bug bounty programs Support incident response including forensic analysis Security Operations (SecOps) Select, deploy, and manage security tools (SIEM, SOAR, log aggregation) to efficiently detect, investigate, and respond to threats, in collaboration with IT for endpoint protection (EDR/MDM). Build incident detection and response playbooks and continuously improve response capabilities Monitor and triage security alerts, collaborating with engineering and IT on incident resolution Data Protection Ensure encryption at rest and in transit with secure key management (KMS, HSM) Implement data minimization, tokenization, and pseudonymization strategies where appropriate Maintain detailed audit trails and logging for sensitive data access, and implement data loss prevention (DLP) controls where applicable, in line with HIPAA/GDPR requirements Cross‑functional Collaboration & Culture Partner with the Head of Information Security (compliance & governance) to align technical controls with SOC 2, ISO 27001, HIPAA, and GDPR requirements Work with the Head of IT on endpoint security, vendor security, and access management Foster a culture of secure development, running workshops and sharing best practices with engineering teams Your DNA 6–10+ years in security engineering roles (infrastructure, application, or cloud security) Hands‑on experience with Google Cloud security stack (IAM, VPC, Shielded VMs, Cloud Armor, etc.) Proven track record deploying and managing modern security tools (EDR, SIEM, IDS/IPS, WAF) Strong understanding of modern web application security (authN/authZ, OWASP Top 10, CSP, API security) Experience with secure SDLC practices (CI/CD pipeline scanning, SAST, DAST, IaC security) Excellent communicator able to work cross‑functionally with engineering, compliance, and IT Bonus: experience in regulated industries (healthcare, fintech, govtech) Why Join Us Security is mission‑critical — you’ll have executive sponsorship and direct CTO partnership Opportunity to build and shape the security engineering function from scratch Work on meaningful challenges in healthcare, where protecting data is protecting lives Where you’ll be based Our offices are based in Paris 3e (Arts & Métiers). Remote policy: Hybrid Working Language: English Benefits Stock ownership 100% healthcare coverage Meal vouchers Public transportation costs covered at 50% Exercise class during the workday: Yoga, running, pilates, HIIT Unlimited budget for book purchases, so you can continue to learn about IT, security, and leadership Culture of trust & accountability — your output matters more than your clock‑in time Life at Nabla When you become a part of our company, you join a team of excellence‑driven, curious, and genuinely kind individuals. Together, we're committed to making clinicians' lives easier and improving healthcare experiences for everyone. You’ll enjoy a dynamic culture with regular off‑sites, team exercises, and a positive work environment. Our Values Excellence, humility, growth, and inclusion Commitment to diversity and inclusion Humility, feedback, and learning #J-18808-Ljbffr


  • Senior/Lead Security Engineer

    il y a 2 semaines


    Paris, Île-de-France Mimica Temps plein

    What we are buildingMimica's mission is to empower enterprises, teams, and individuals to reclaim their most precious resource — time and work more efficiently, with greater purpose and impact.Our AI-powered task mining observes employee actions across the desktop and categorizes them into detailed process maps. Mimica's process intelligence highlights...

  • Senior Security Engineer

    il y a 1 semaine


    Paris, France un emploi de Security Expert Temps plein

    Une entreprise d'e-commerce leader recherche un·e Senior Security Engineer pour rejoindre son équipe à Lille ou Paris. Ce rôle implique de travailler sur la cybersécurité pour renforcer la protection des systèmes d'information. Le candidat idéal aura une formation en informatique et une solide expérience en cybersécurité, avec d'excellentes...

  • Security Engineer

    il y a 2 jours


    Paris, France Mambu Temps plein

    Security Engineer **Who we are** Join Numeral - A Mambu Company, Shaping the Future of Financial Technology! At Numeral, a proud part of the Mambu family, we are revolutionizing the banking and financial services landscape with cutting-edge solutions that empower businesses and transform financial services. As a global leader in payment operations and...

  • Lead Security Engineer

    il y a 1 semaine


    Rue Chapon, Paris, France Nabla Temps plein

    About NablaWe are a team of entrepreneurs, clinicians and engineers committed to bringing back joy to the practice of medicine.Together with a community of clinician innovators, we've harnessed the best of machine learning science to develop Nabla: the leading AI assistant that's restoring the human connection at the heart of healthcare. By streamlining...

  • Security Engineer

    il y a 2 jours


    Paris, France Deepki Temps plein

    Join Our Dynamic Team as a Security Engineer at Deepki. Deepki, leading the way in ESG SaaS for real estate owners and accelerating the transition towards net zero and sustainability. As part of our mission to support the construction and industry sectors in their transition to zero carbon, we are excited to announce an opening for a Security...


  • Paris, France Check Point Software Technologies Ltd. Temps plein

    **Your Team**: Are you a graduate that wants to make a career as a Security Engineer? Are you looking for a company to invest in your development? Look no further.. Here at **Check Point** we want to ensure we propel your career by taking you on a journey that puts you at the center of the learning. Be part of the most innovative international team of...


  • Paris, France Theorem, LLC Temps plein

    A cybersecurity company in France is seeking a Lead Python Backend Engineer to implement web services and tools in Python for automating security analysis. Candidates should have over 8 years of software engineering experience along with significant experience in web services and APIs in Python. Familiarity with Google Cloud is a bonus. This role offers an...


  • Paris, France ProtonMail Temps plein

    A privacy-focused tech company in Paris is seeking an Application Security Engineer to enhance the security of its products. The role includes performing penetration tests, supporting security improvements, and collaborating with engineering teams. Ideal candidates should have proven experience in penetration testing and threat modeling, along with strong...

  • Security Engineer

    il y a 2 jours


    Paris, Île-de-France Shift Technology Temps plein

    Shift is the leading AI platform for insurance.  Shift combines generative, agentic, and predictive AI to transform underwriting, claims, and fraud and risk - driving operational efficiency, exceptional customer experiences and measurable business impact.  Trusted by the world's leading insurers, Shift delivers AI when and where it matters most, at scale...


  • Paris, France Qonto Temps plein

    A leading fintech company in Paris is seeking a Security Engineer to safeguard systems and enhance security features. This role involves auditing applications, investigating incidents, and developing security tools to protect users. Ideal candidates will have cloud experience (AWS), programming skills (Python), and a passion for information security. Join a...