Security & Compliance Engineer: Être Paranoïde Professionnellement
kpi-vision
À Propos
On cherche un Security & Compliance Engineer pour s'assurer qu'on gère les données proprement.
On a des clients. Les clients ont des données sensibles. Les régulateurs ont des règles.
Tu vas naviguer tout ça.
Responsabilités
- Security audits (assess risks, find vulnerabilities)
- Compliance management (GDPR, CCPA, industry standards)
- Incident response (oh no, we got hacked!)
- Security training (educate employees)
- Policy/procedure development (document everything)
- Vendor security review (are our partners safe?)
Profil Recherché
- 3-4 ans security experience
- GDPR/compliance knowledge (essential)
- Security certifications (CISSP, Security+, etc.)
- Understanding of startup constraints (you can't do enterprise security)
- Communication skills (explain risk to non-technical people)
Ce Qu'On Veut
"We need to be compliant!"
Reality:
- We didn't think about security earlier (it's a startup thing)
- We need to bolt it on now
- We have budget constraints
- You'll balance security vs. velocity
La Comp
Salaire: 53k€ (security premium)
Equity: 0.1%
Benefits: Standard + maybe cyber insurance
Le Jour Typique
- 9h-10h: Review security alerts
- 10h-12h: Audit a new integration (is it secure?)
- 12h-13h: Lunch (while thinking about potential breaches)
- 13h-15h: Update security policies
- 15h-17h: Prepare for a compliance audit
- 17h-18h: Respond to security questions from other teams
The Paranoia
You'll become the person who asks:
- "What if someone hacks this?"
- "How do we know the data is safe?"
- "Do we have backup?"
People will roll their eyes.
But you're right 50% of the time. (Which is too high.)
Common Issues
Issue 1: API Keys In Code
- Developer commits API keys to GitHub
- You find it in a scan
- Database has been accessed by random person
- You had to rotate keys and check logs
- 8 hours of work
Issue 2: Unencrypted Data
- Customer data stored in plain text
- You discover it
- You have to encrypt it
- Takes 2 weeks
- Whole team has to coordinate migration
Issue 3: Vendor Risk
- You recommend using a new service
- CEO: "But it's cheaper!"
- You: "But they don't have SOC 2"
- CEO: "So?"
- You: "So our customers' data might be at risk"
- CEO: "Use them anyway"
- You pray nothing bad happens
The Compliance Grind
GDPR: 100 pages of rules
CCPA: 50 pages of different rules
Industry standards: It depends
Your job: Understand it all and make sure we comply
And document everything (so when we get audited, we have proof).
After 18 Months
Best Case:
- You've implemented solid security practices
- No breaches
- Compliance audits go smoothly
- You're respected
Realistic Case:
- You've improved security a bit
- No major incidents (so far)
- Compliance is "mostly OK"
- You're always worried something will break
Worst Case:
- There's a breach
- It's your "fault" (even if it's not)
- You're blamed
- You leave
Why It's Hard
Security is thankless.
When things go right, nobody notices.
When things go wrong, you get blamed.
And in startups, people want to move fast.
Security slows things down.
So there's constant tension.
The Philosophical Problem
You know: Risk mitigation is important.
Business knows: Velocity is important.
These are often at odds.
You'll always be the "no" person.
The Advice
If you like: Security, risk management, compliance:
Yes.
If you want: To be the popular person on the team:
No.
You'll be the person who slows things down.
That's your job.
And somebody's gotta do it.
(Better you than nobody.)
Details
💼 Department
Security
📊 Level
Mid
💰 Salary
$48K - $58K
📈 Equity
0.1%
📍 Location
Paris, Remote 50%
⏰ Job Type
Full-time
📅 Posted
May 16, 2026
We'll review your application within 2-3 weeks