Senior Corporate Security Engineer - IT Security (x/f/m)
at Doctolib
- Seniority
- Senior
- Location
- Paris, Paris, France
- Posted
- 16d ago
at Doctolib
<h2> </h2> <h2 class="pb-2 pt-4 heading-xl text-foreground">Set a new pulse for healthcare!</h2> <div class="whitespace-pre-wrap break-words font-normal first:pt-0 last:pb-0 py-1 @md:pt-2 @md:pb-[10px] @md:leading-relaxed text-base leading-relaxed text-foreground">We are looking for a <strong class="font-semibold text-foreground">Senior Corporate Security Engineer</strong> to join the <strong class="font-semibold text-foreground">Corporate Security</strong> team in <strong class="font-semibold text-foreground">SecOps</strong>.</div> <div class="whitespace-pre-wrap break-words font-normal first:pt-0 last:pb-0 py-1 @md:pt-2 @md:pb-[10px] @md:leading-relaxed text-base leading-relaxed text-foreground">Your mission will be to secure everything Doctolibers rely on to do their best work identities, endpoints, SaaS applications, and the zero-trust network that connects them in a highly regulated healthcare environment (HDS, ISO 27001, C5) where security directly impacts patient safety and trust. You will own security programs end-to-end, shipping every control as code and driving adoption across teams, contributing directly to the protection of data for over 80 million patients and 400,000 health professionals.</div> <div class="whitespace-pre-wrap break-words font-normal first:pt-0 last:pb-0 py-1 @md:pt-2 @md:pb-[10px] @md:leading-relaxed text-base leading-relaxed text-foreground">Working in the tech team at Doctolib means building innovative products and features to improve the daily lives of care teams and patients.</div> <h2 class="pb-2 pt-4 heading-xl text-foreground">What you'll do</h2> <div class="whitespace-pre-wrap break-words font-normal first:pt-0 last:pb-0 py-1 @md:pt-2 @md:pb-[10px] @md:leading-relaxed text-base leading-relaxed text-foreground">Your responsibilities include but are not limited to:</div> <ul class="list-disc pb-2 pl-6 flex flex-col gap-1 text-foreground text-base leading-relaxed"> <li class="break-words text-foreground text-base leading-relaxed"><strong class="font-semibold text-foreground">Own</strong> corporate security programs from architecture to enforcement: conditional access, phishing-resistant authentication, device compliance, SaaS and third-party app governance (including AI tools), and zero-trust network access.</li> <li class="break-words text-foreground text-base leading-relaxed"><strong class="font-semibold text-foreground">Ship</strong> every change as code: use Terraform and GitHub pull requests to bring controls to production designed, peer-reviewed, rolled out progressively (report-only → enforce), and always reversible.</li> <li class="break-words text-foreground text-base leading-relaxed"><strong class="font-semibold text-foreground">Drive</strong> adoption across teams: write technical proposals, align IT and business stakeholders, plan communications and exception handling, and land security controls without disrupting how people work.</li> <li class="break-words text-foreground text-base leading-relaxed"><strong class="font-semibold text-foreground">Evaluate and secure</strong> the tools Doctolibers adopt: conduct security reviews of SaaS integrations and AI tools, and deliver pragmatic, risk-based responses to shadow IT.</li> <li class="break-words text-foreground text-base leading-relaxed"><strong class="font-semibold text-foreground">Investigate and improve</strong>: lead incident investigations on the corporate perimeter end-to-end, and continuously improve detection rules and response playbooks in our Elastic SIEM.</li> <li class="break-words text-foreground text-base leading-relaxed"><strong class="font-semibold text-foreground">Mentor</strong> more junior engineers and contribute to a team culture of engineering excellence and peer review.</li> </ul> <h2 class="pb-2 pt-4 heading-xl text-foreground">Who you are</h2> <div class="whitespace-pre-wrap break-words font-normal first:pt-0 last:pb-0 py-1 @md:pt-2 @md:pb-[10px] @md:leading-relaxed text-base leading-relaxed text-foreground">Before you read on: if you don't have the exact profile described below, but you feel this job description matches your skill set, we still encourage you to apply.</div> <div class="whitespace-pre-wrap break-words font-normal first:pt-0 last:pb-0 py-1 @md:pt-2 @md:pb-[10px] @md:leading-relaxed text-base leading-relaxed text-foreground"><strong class="font-semibold text-foreground">You'll be a great fit if you:</strong></div> <ul class="list-disc pb-2 pl-6 flex flex-col gap-1 text-foreground text-base leading-relaxed"> <li class="break-words text-foreground text-base leading-relaxed">Have 5+ years of hands-on experience securing corporate/enterprise environments — identity, endpoints, SaaS, and network — including at least 2 years at a senior level. You have built and enforced security controls in production (not only monitored alerts), and owned at least one significant program end-to-end, such as an MFA rollout, a device-compliance initiative, or a SaaS access-governance project.</li> <li class="break-words text-foreground text-base leading-relaxed">Have strong daily mastery of <strong class="font-semibold text-foreground">GitHub, Terraform, and AI coding assistants</strong> (Claude or equivalent). You ship security work as reviewed pull requests and use AI agents as a structural part of your workflow, not an occasional helper.</li> <li class="break-words text-foreground text-base leading-relaxed">Have deep <strong class="font-semibold text-foreground">identity & access</strong> expertise: identity providers, conditional access policies, OAuth/application governance, and modern authentication standards (passkeys, phishing-resistant MFA).</li> <li class="break-words text-foreground text-base leading-relaxed">Have a pragmatic mindset, the ability to make decisions under uncertainty and follow through, and <strong class="font-semibold text-foreground">strong written communication skills</strong>&nb