Skip to content

Open nowPosted 106 days ago

Security Engineer

yousign14 open roles

Where
Paris, France
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineeryousign · Paris, France
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on yousign's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 106 days ago

The posting

About Youtrust

Youtrust is a European Digital Trust provider, fully compliant with eIDAS and the highest European standards. Our three modules – electronic signatures, identity and document verification, and e-seals – can be used independently or combined within sector-specific workflows, ensuring simple, secure and legally compliant processes for SMEs and mid-sized companies. Hosted and processed entirely in Europe, we guarantee sovereignty, transparency and reliability. As a certified B-Corp, we combine innovation with responsibility – building trust at the heart of every digital exchange. We are entering a key moment as we expand from eSignature to the full Digital Trust chain.

Your Role

As a Security Engineer at Youtrust, you are the embedded security partner for the entire company, with Product as your primary internal client. You lead Youtrust's security review cycle end-to-end on prioritized initiatives: from understanding the context of a new feature or project, to issuing your requirements and guidance, supporting implementation, and unblocking through risk management when needed.

You own and operate the pentest and BugBounty programs and ensure consistent, pragmatic security coverage across all team initiatives, from Engineering and Product to cross-functional projects company-wide.

You also step into the topics that make Youtrust a Digital Trust provider: the security of our Trusted Zone, our fraud detection and prevention efforts, and our regulatory compliance (eIDAS, NIS2, ISO 27001). You won't own every one of these, but you contribute wherever the team needs you — your specialization defines where you spend most of your time, not a silo you stay inside.

Your Responsibilities

  • Lead the end-to-end security review cycle for all product features: context intake, Decision Records, implementation support, and risk-based unblocking.
  • Own and operate Youtrust's BugBounty program: triage reports, drive remediation, and manage reward decisions.
  • Identify, prioritise, and track remediation of vulnerabilities across Youtrust's product and infrastructure perimeter.
  • Contribute to the security of the Trusted Zone, and to fraud detection and prevention, alongside the Security & Compliance team.
  • Support regulatory compliance (eIDAS, NIS2, ISO 27001): help translate requirements into technical controls, and contribute to audits and remediation when needed.
  • Extend security expertise beyond Product to all company initiatives: assess risks, issue guidance, and maintain a consistent security posture company-wide.
  • Take part in the team's weekly on-call ("doctor") rotation, and build automation (n8n, AI tooling, alerting) to reduce manual toil.
  • Raise the security bar across Engineering and beyond: share knowledge, coach teams on secure-by-design practices, and build security awareness.

Your Profile

  • You have deep, hands-on expertise in web application and API security, you know attack and defense mechanisms inside out and can spot a vulnerability in a PR or architecture diagram.
  • You are able to independently run threat modeling sessions, produce clear Decision Records, and translate security risks into actionable requirements for engineering teams.
  • You have experience managing vulnerabilities across a product perimeter: triaging, prioritising, tracking remediation, and knowing when to accept risk versus escalate.
  • You have participated in or run BugBounty programs. You understand triage workflows, reward logic, and how to communicate decisions clearly to researchers.
  • You use AI actively to automate parts of your security work, CVE monitoring, BugBounty triage, report generation, and you think critically about how to integrate AI into existing workflows rather than simply adding tools.
  • You are comfortable working across domains. Your core is product security, but you are happy to contribute to compliance topics (eIDAS, NIS2, ISO 27001), to fraud detection and prevention, and to the security of a Trusted Zone. Prior exposure to a regulated or Digital Trust environment is a strong plus.
  • You are genuinely self-sufficient: you pick up a brief, define the scope, and deliver without hand-holding. You are comfortable in ambiguous, fast-moving environments.
  • You are pragmatic by nature. You do not block for the sake of blocking. You find the right balance between security rigour and business velocity, and you know when to escalate versus when to accept risk.
  • You communicate clearly and simply. You can explain a complex vulnerability to a non-security engineer in two minutes, and you coach without being preachy.
  • You are genuinely curious: you follow threat intel, participate in CTFs, and keep your technical edge sharp because you care about the craft.
  • French at a native or near-native level (C2) is required. English at a professional working level (B2) is required for security research, technical documentation, and communication with international BugBounty researchers.

Recruitment Process

  1. R1 — TAM Interview with Guillhem Cambiganu (30 min)
  2. R2 — Hiring Manager Interview with Tony Belot (45–60 min)
  3. R3 — Technical Interview: slide deck presentation + peer discussion with Tony Belot and a member of the Security & Compliance team (1H)
  4. R4 — Director Interview with Kevin Dubourg (30 min)

Benefits

  • Salary: 53 000 – 79 000 EUR
  • Stock options - BSPCE
  • Meal vouchers (Swile): 10.50 EUR/day, 50% covered by Youtrust
  • Youtrust
  • Life & disability insurance: 100% employer-covered
  • Wellbeing: Axomove (4 physio sessions) and Moka.care (6 therapy/coaching sessions)
  • Transportation: 50% reimbursement for public transport for hybrid workers
  • Leeto: Access to numerous employee discounts
  • Time off: 10 RTT days/year, plus menstrual leave, parenthood benefits, seniority days
  • 1 volunteering day/year, learning & development budget, and more

Why join Youtrust now?

  • A mission that matters in a world challenged by AI-driven fraud
  • A vision built on integrity
  • A European & sovereign platform
  • A certified B Corp
  • The golden age of Youtrust
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against yousign's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on yousign's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    yousign's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.