⚠️ Site parodique — chaque profil, entreprise, post et réaction sur 11nk3d1n est 100 % imaginaire et exagéré. Tout comme le vrai, mais avec un VRAI disclaimer. En savoir plus
1n
← Back to jobs

Security & Compliance Engineer: Être Paranoïde Professionnellement

kpi-vision

Mid

À Propos

On cherche un Security & Compliance Engineer pour s'assurer qu'on gère les données proprement.

On a des clients. Les clients ont des données sensibles. Les régulateurs ont des règles.

Tu vas naviguer tout ça.

Responsabilités

  • Security audits (assess risks, find vulnerabilities)
  • Compliance management (GDPR, CCPA, industry standards)
  • Incident response (oh no, we got hacked!)
  • Security training (educate employees)
  • Policy/procedure development (document everything)
  • Vendor security review (are our partners safe?)

Profil Recherché

  • 3-4 ans security experience
  • GDPR/compliance knowledge (essential)
  • Security certifications (CISSP, Security+, etc.)
  • Understanding of startup constraints (you can't do enterprise security)
  • Communication skills (explain risk to non-technical people)

Ce Qu'On Veut

"We need to be compliant!"

Reality:
- We didn't think about security earlier (it's a startup thing)
- We need to bolt it on now
- We have budget constraints
- You'll balance security vs. velocity

La Comp

Salaire: 53k€ (security premium)
Equity: 0.1%
Benefits: Standard + maybe cyber insurance

Le Jour Typique

  • 9h-10h: Review security alerts
  • 10h-12h: Audit a new integration (is it secure?)
  • 12h-13h: Lunch (while thinking about potential breaches)
  • 13h-15h: Update security policies
  • 15h-17h: Prepare for a compliance audit
  • 17h-18h: Respond to security questions from other teams

The Paranoia

You'll become the person who asks:
- "What if someone hacks this?"
- "How do we know the data is safe?"
- "Do we have backup?"

People will roll their eyes.

But you're right 50% of the time. (Which is too high.)

Common Issues

Issue 1: API Keys In Code
- Developer commits API keys to GitHub
- You find it in a scan
- Database has been accessed by random person
- You had to rotate keys and check logs
- 8 hours of work

Issue 2: Unencrypted Data
- Customer data stored in plain text
- You discover it
- You have to encrypt it
- Takes 2 weeks
- Whole team has to coordinate migration

Issue 3: Vendor Risk
- You recommend using a new service
- CEO: "But it's cheaper!"
- You: "But they don't have SOC 2"
- CEO: "So?"
- You: "So our customers' data might be at risk"
- CEO: "Use them anyway"
- You pray nothing bad happens

The Compliance Grind

GDPR: 100 pages of rules

CCPA: 50 pages of different rules

Industry standards: It depends

Your job: Understand it all and make sure we comply

And document everything (so when we get audited, we have proof).

After 18 Months

Best Case:
- You've implemented solid security practices
- No breaches
- Compliance audits go smoothly
- You're respected

Realistic Case:
- You've improved security a bit
- No major incidents (so far)
- Compliance is "mostly OK"
- You're always worried something will break

Worst Case:
- There's a breach
- It's your "fault" (even if it's not)
- You're blamed
- You leave

Why It's Hard

Security is thankless.

When things go right, nobody notices.

When things go wrong, you get blamed.

And in startups, people want to move fast.

Security slows things down.

So there's constant tension.

The Philosophical Problem

You know: Risk mitigation is important.

Business knows: Velocity is important.

These are often at odds.

You'll always be the "no" person.

The Advice

If you like: Security, risk management, compliance:
Yes.

If you want: To be the popular person on the team:
No.

You'll be the person who slows things down.

That's your job.

And somebody's gotta do it.

(Better you than nobody.)

Details

💼 Department

Security

📊 Level

Mid

💰 Salary

$48K - $58K

📈 Equity

0.1%

📍 Location

Paris, Remote 50%

⏰ Job Type

Full-time

📅 Posted

May 16, 2026

We'll review your application within 2-3 weeks