Senior Application Security Engineer

il y a 1 semaine


Paris, France ProtonMail Temps plein

OverviewA better internet, where privacy is the default, is possible. Building this better internet might seem daunting or even unthinkable, but at Proton, this is what we do every day.Proton was founded in 2014 by a group of scientists who met at the European Organization for Nuclear Research (CERN). Our first product, Proton Mail, is now the world’s largest encrypted email service. Subsequent Proton products, such as Proton VPN, Proton Calendar, Proton Drive and Proton Pass give our users full control over how and with whom their data is shared.Today, Proton makes privacy universally accessible. Journalists from outlets like The Guardian and The New York Times, some of the world’s largest organizations, and people in more than 180 countries have signed up for over 100 million accounts. Our diverse and dynamic team is made up of more than 400 members representing over 40 different nationalities. While we are based in Geneva, Switzerland, we have offices in Zurich, Prague, London, Vilnius, Skopje, Taipei, Paris, Barcelona and many more employees working remotely around the world.Join one of Europe’s fastest-growing companies to help us solve challenging problems and build new products that will reach hundreds of millions of people. We want to create more than just one of the world’s most impactful tech companies; we want to create a new internet that serves the interests of all people. We need you, your voice, your ideas, and your ambition to make it happen.The TeamThe Security team is tasked with protecting Proton’s and its users against various cyber-security threats. We ensure the confidentiality, availability and integrity of thousands of assets, necessary to the fulfillment of Proton’s privacy mission. Since 2018, the team has been providing services to other business units, including security monitoring, risk management, internal advisory, product security, vulnerability management and identity & access management. Our mandate includes the protection of people, devices, applications, infrastructure, data, software and our products. We work mainly with on-prem infrastructure and open source tools.The security team is small yet mighty. We are a close-knit group of people who work hard to help Proton achieve its mission. We strongly believe that we cannot protect our users\' privacy if we do not protect the company\'s security.Tech Stack and ToolsProton currently offers the following products: Mail, Calendar, VPN, Pass, Drive, each of which is available on multiple platforms, including Windows, MacOS, iOS and Linux.Our infrastructure is entirely composed of Linux machines.Wherever we can, we make use of open-source technologies.About the roleYou will be leading our efforts to ensure that Proton's applications are secure.What you will be doingPerform penetration tests on Proton products, both those released to the public and notSupport bug bounty triage by reproducing submissions and assessing their potential impactWork with engineering teams to remediate identified bugsIdentify and implement improvements in product security and secure codingWork with the wider Security and developer units to create security guidelinesDemonstrate the value of an “assume breach” mentalityPerform threat modeling and security reviews: review the design of services from a security perspective to identify vulnerabilities and weaknesses in the architecture and designWhat we are looking forProven experience in organizing and executing penetration tests / red team operationsA proactive and creative application security engineerA proactive and creative mindset to come up with efficient and effective ways to continuously improve the security of our productsExpertise in threat modelingExperience with at least two of the following iOS Android Windows MacOS LinuxStrong skills in coding and code review for at least two of the following Go Rust PythonNice to haveExperience or knowledge about open source tools for application security testingExperience in automationA toolbox for application security testingExperience or knowledge of infrastructure penetration testsEven if you don’t meet all the requirements listed above, but feel you could still be a great fit, please still apply.Why should you join Proton?Be part of a movement - Proton is not just a product or service but a community-driven movement united by a shared vision of online freedom. Our services are open source, audited, and supported by community contributions. We give back to our community by maintaining core encryption libraries and by supporting other organizations furthering the same goals as us. Proton is free, open source, neutral, independent, and community first, while remaining financially sustainable.Work with smart and dedicated people - Our team is diverse, collaborative, and tight-knit with people coming from all walks of life, including many of the world’s top academic institutions and organizations, such as MIT, Harvard, Stanford, Caltech, Cambridge, and ETH.Join a strong brand - Our encrypted email service - ProtonMail - has grown to be a staple of online security and privacy. Proton has been featured in multiple popular television and film productions, such as Mr. Robot, Knives Out, Sounds of Metal, and more.Grow with us - We’re one of Europe’s fastest-growing startups, doubling in size every year. Our growth gives you limitless career and educational opportunities as well as the opportunity to work side-by-side with many world-leading experts in their fields.Have your voice heard - We value your opinion and encourage you to speak up and share your ideas and thoughts. At Proton, no problem is someone else’s problem. We collectively strive to do the right thing and be the undisputed best in the world at everything we do.Benefits – these vary by location and type of contract but expect support on your vacation, parental leave, refreshment if working from the office, learning and development opportunities, equity for shared success, flexible working hours and remote work, company events and team building activities.Proton does not accept unsolicited resumes from any sources other than directly from a candidate. Proton will not pay a fee for any placement resulting from the receipt of an unsolicited offer, even in a situation when the relevant candidate is employed by Proton. #J-18808-Ljbffr



  • Paris, France Amazon Temps plein

    Key Job ResponsibilitiesAs a Senior Security Engineer, you’ll help to build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon’s infrastructure. You’ll work with data scientists, software development engineers, and other security engineers across multiple teams to develop innovative security solutions....

  • Senior Security Engineer

    il y a 2 semaines


    Paris, France Swile Temps plein

    At Swile, we believe that good products can help reduce friction in daily professional life and boost employee satisfaction. Today, we provide innovative solutions in various areas such as Fintech, Travel, HR, and Employee Benefits to more than 5.5 million users in 85,000 companies in France and Brazil. Your role as a DevSecOps Engineer centers around...


  • Paris, France Capital Fund Management (CFM) Temps plein

    Are you passionate about application security and ready to serve as a subject matter expert in both application security and securing the software development lifecycle? In this role, you’ll be instrumental in protecting our low‑latency processing systems and trading platforms across diverse environments. Reporting directly to the Director of Application...

  • Senior Security Engineer

    il y a 5 jours


    Paris, Île-de-France Doctolib Temps plein

    We are looking for an Application Security Engineer to join the Security team in Paris.   As an Application Security Engineer, your mission will be to safeguard the security and privacy of millions of practitioners and patients while helping deliver an exceptional user experience across Europe's leading healthcare products. You will build and scale...


  • Paris, France Capital Fund Management (CFM) Temps plein

    Founded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients.We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate...

  • Senior Security Engineer

    il y a 4 jours


    Paris, Île-de-France Doctolib Temps plein

    We are looking for an Application Security Engineer to join the Security team in Paris.As an Application Security Engineer, your mission will be to safeguard the security and privacy of millions of practitioners and patients while helping deliver an exceptional user experience across Europe's leading healthcare products. You will build and scale...


  • Paris, France MarkJames Search Temps plein

    Job description Our client, a fast growing Cyber Security Consultancy, based in Paris, are currently hiring for a Senior Software Security Engineer to to join the team to maintain, troubleshoot, upgrade and enhance automatic telecom vulnerabilities security scanner.ResponsibilitiesMaintain, troubleshoot, upgrade and enhance our automatic telecom...

  • Senior Security Engineer

    il y a 2 semaines


    Paris, Île-de-France C12 Quantum Electronics Temps plein

    C12 develops quantum computers, to solve highly complex computing tasks, currently out of reach of even the most powerful supercomputers. Building a quantum computer still needs innovators ready to tackle exciting challenges. C12's founders are convinced that only a new material for the qubit will bring a technological breakthrough. C12 uniquely uses carbon...

  • Senior Security Engineer

    il y a 2 semaines


    Paris, Île-de-France Teads Temps plein

    About TeadsTeads is the omnichannel outcomes platform for the open internet, driving full-funnel results for marketers across premium media. With a focus on meaningful business outcomes for branding and performance objectives, the combined company ensures value is driven with every media dollar by leveraging predictive AI technology to connect quality media,...


  • Paris, France Amazon Temps plein

    A leading technology company in Nouvelle-Aquitaine, Paris, is seeking a Senior Security Engineer. The role involves building and managing services that detect and mitigate cybersecurity threats while working with various teams. Candidates should have extensive security experience, in-depth knowledge of cyber threats, and a degree in a STEM field. This...