Doctolib
Platform Security Engineer (x/f/m)
Part remote, part office, you need to live within commuting distance of a named location.
Hybrid · Paris
Employer listed it 2 weeks ago · Added 4 days ago
Been open since 2 weeks ago, still being checked, but it has been live a while.
Salary
Not stated
Location
Hybrid · Paris
Timezone
Not stated
Contract
Contract
Experience
Mid
Category
Software
This employer didn't state pay. Jobs like this usually pay around $165k–$260k a year, a typical range taken from 595 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Hybrid
This role is only partly remote, the employer expects time in the office around Paris, Hybrid, so you need to live within commuting distance.
What the employer says
- Source listing states candidate location: "Paris, Hybrid"
- Listing mentions "Hybrid"
What Nomaders makes of it
- Not suitable if you plan to move between countries
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Set a new pulse for healthcare!
We are looking for a Platform Security Engineer to join the Security team at Doctolib.
Your mission will be to protect sensitive healthcare data while enabling rapid, secure innovation. You will be responsible for securing Doctolib's cloud infrastructure and application ecosystem, combining multi-cloud security expertise with hands-on platform engineering — contributing directly to the safety of millions of patients and care teams who rely on our platform every day.
Working in the tech team at Doctolib means building innovative products and features to improve the daily lives of care teams and patients.
What you'll do
Your responsibilities include but are not limited to:
Own a platform security workstream end to end, from architecture to enforcement: scope it with your tech lead, design the control, roll it out progressively (report-only, then enforce), handle exceptions, and see it through to full coverage. Typical examples: hardening IAM across our AWS accounts, tightening cluster admission policies, or closing a class of misconfiguration for good.
Ship every change as code: Terraform and GitHub pull requests, peer-reviewed and always reversible. No console clicking, no undocumented state.
Harden our cloud and infrastructure baseline and keep it hardened: IAM permissions and access reviews, secrets management, network and cluster guardrails, CI/CD and supply chain controls — building the guardrails and driving remediation of what they surface with platform and engineering teams, turning recurring findings into automation rather than tickets.
Investigate and improve: lead incident investigations on the platform perimeter end to end, and continuously improve detection rules and response playbooks in our Elastic SIEM.
Work in the open: write clear technical notes, drive adoption of your changes with the engineering teams they affect, and grow through code review and pairing with the rest of the team.
Who you are
Before you read on: if you don't have the exact profile described below, but you feel this job description matches your skill set, we still encourage you to apply.
You'll be a great fit if you:
Have 1 to 3 years of hands-on experience in security engineering, security operations, SRE, infrastructure or platform engineering, including some exposure to a cloud environment (AWS, GCP or Azure) in production — an internship or apprenticeship in one of those roles counts.
Work daily with infrastructure as code and GitHub: you have written and shipped your own Terraform through reviewed pull requests, and you are comfortable operating and debugging workloads on Kubernetes.
Use AI coding assistants (Claude or equivalent) as a normal part of how you work.
Have carried at least one project through to production — security or not — and stayed with it past the first deployment until it was actually adopted.
Have solid fundamentals: Linux, networking, cloud, Kubernetes and development/scripting, a pragmatic mindset, the ability to make decisions under uncertainty and follow through, and strong written communication skills — you can carry a proposal from draft to cross-team adoption.
Are fluent in English (working language in writing); daily team conversations happen mostly in French, so being a French speaker or willing to learn is a strong plus.
It would be fantastic if you:
Have worked with a SIEM (Elastic, Splunk, or equivalent), writing and tuning your own queries.
Have done detection engineering, incident response, threat hunting, or CTFs.
Can point to public write-ups, open-source contributions, or a home lab.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·Free comprehensive health insurance (basic package) for you and your children
- ·25 days of paid vacation per year, plus up to 14 days of RTT
- ·Free mental health and coaching services through our partner Moka.care
- ·Work from abroad for up to 10 days per year thanks to our flexibility days policy
- ·Lunch vouchers (Swile card) worth €8.50 per working day, with €4.50 covered by Doctolib
How to apply
- 1Check the flexibility label above, hybrid, matches where you plan to live and work.
- 2Tailor your CV to the role at Doctolib, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $165k to $260k per year · You'll be taken to the employer's careers page.