Senior Corporate Security Engineer - IT Security (x/f/m) presso Doctolib
Doctolib · Paris, Francia · Remote
Set a new pulse for healthcare!
What you'll do
- Own corporate security programs from architecture to enforcement: conditional access, phishing-resistant authentication, device compliance, SaaS and third-party app governance (including AI tools), and zero-trust network access.
- Ship every change as code: use Terraform and GitHub pull requests to bring controls to production designed, peer-reviewed, rolled out progressively (report-only → enforce), and always reversible.
- Drive adoption across teams: write technical proposals, align IT and business stakeholders, plan communications and exception handling, and land security controls without disrupting how people work.
- Evaluate and secure the tools Doctolibers adopt: conduct security reviews of SaaS integrations and AI tools, and deliver pragmatic, risk-based responses to shadow IT.
- Investigate and improve: lead incident investigations on the corporate perimeter end-to-end, and continuously improve detection rules and response playbooks in our Elastic SIEM.
- Mentor more junior engineers and contribute to a team culture of engineering excellence and peer review.
Who you are
- Have 5+ years of hands-on experience securing corporate/enterprise environments — identity, endpoints, SaaS, and network — including at least 2 years at a senior level. You have built and enforced security controls in production (not only monitored alerts), and owned at least one significant program end-to-end, such as an MFA rollout, a device-compliance initiative, or a SaaS access-governance project.
- Have strong daily mastery of GitHub, Terraform, and AI coding assistants (Claude or equivalent). You ship security work as reviewed pull requests and use AI agents as a structural part of your workflow, not an occasional helper.
- Have deep identity & access expertise: identity providers, conditional access policies, OAuth/application governance, and modern authentication standards (passkeys, phishing-resistant MFA).
- Have a pragmatic mindset, the ability to make decisions under uncertainty and follow through, and strong written communication skills — you can carry a proposal from draft to cross-team adoption.
- Are fluent in English (working language in writing); daily team conversations happen mostly in French, so being a French speaker or willing to learn is a strong plus.
- Have detection engineering or SIEM experience (writing and tuning your own queries).
- Are curious about platform security topics (cloud, Kubernetes, supply chain) and willing to contribute beyond your core perimeter.
- Have prior experience in a regulated industry (healthcare, fintech, or public sector).
Life at Doctolib Tech
- Our solutions are built on a single fully cloud-native platform that supports web and mobile app interfaces, multiple languages, and is adapted to country and healthcare specialty requirements.
- Our stack is composed of Rails, TypeScript, Java, Python, Kotlin, Swift, and React Native.
- We leverage AI ethically across our products to empower patients and health professionals. Discover our AI vision here.
What we offer
- Free comprehensive health insurance (basic package) for you and your children
- 25 days of paid vacation per year, plus up to 14 days of RTT
- Free mental health and coaching services through our partner Moka.care
- Work from abroad for up to 10 days per year thanks to our flexibility days policy
- Lunch vouchers (Swile card) worth €8.50 per working day, with €4.50 covered by Doctolib
- A subsidy from the work council to refund part of the membership to a sport club or a creative class
- 50% reimbursement of your public transport subscription
- Parent Care Program: receive one additional month of leave on top of the legal parental leave
- Enrollment in Doctolib's long-term employee value sharing plan called DoctoGrowth
- For caregivers and workers with disabilities, a package including an adaptation of the remote policy, extra days off for medical reasons, and psychological support
- Relocation support in case of international mobility
- Access to the best AI tools for coding, development and dedicated training
Our interview process
- TA Screening
- Technical Assessment (~90 min, live): security questions followed by a hands-on scenario worked through together — with an AI assistant available directly in the platform, the way we actually work
- Behavioral Interview
- At least one reference check
Job details
- Permanent position
- Tech stack: Terraform, GitHub, Entra ID, Intune, CrowdStrike, Cloudflare, Elastic, Google Workspace
- Full-time
- Paris, France
- Hybrid work setup (up to 2 remote days per week)
- Start date: as soon as possible