Doctolib
Senior Corporate Security Engineer - IT Security (x/f/m)
Part remote, part office, you need to live within commuting distance of a named location.
Hybrid · Paris
Employer listed it 4 months ago · Added 4 days ago
Been open since 4 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
Not stated
Location
Hybrid · Paris
Timezone
Not stated
Contract
Contract
Experience
Senior
Category
Software
This employer didn't state pay. Jobs like this usually pay around $180k–$230k a year, a typical range taken from 596 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Hybrid
This role is only partly remote, the employer expects time in the office around Paris, Hybrid, so you need to live within commuting distance.
What the employer says
- Source listing states candidate location: "Paris, Hybrid"
- Listing mentions "Hybrid"
What Nomaders makes of it
- Not suitable if you plan to move between countries
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Set a new pulse for healthcare!
We are looking for a Senior Corporate Security Engineer to join the Corporate Security team in SecOps .
Your mission will be to secure everything Doctolibers rely on to do their best work identities, endpoints, SaaS applications, and the zero-trust network that connects them in a highly regulated healthcare environment (HDS, ISO 27001, C5) where security directly impacts patient safety and trust. You will own security programs end-to-end, shipping every control as code and driving adoption across teams, contributing directly to the protection of data for over 80 million patients and 400,000 health professionals.
Working in the tech team at Doctolib means building innovative products and features to improve the daily lives of care teams and patients.
What you'll do
Your responsibilities include but are not limited to:
Own corporate security programs from architecture to enforcement: conditional access, phishing-resistant authentication, device compliance, SaaS and third-party app governance (including AI tools), and zero-trust network access.
Ship every change as code: use Terraform and GitHub pull requests to bring controls to production designed, peer-reviewed, rolled out progressively (report-only → enforce), and always reversible.
Drive adoption across teams: write technical proposals, align IT and business stakeholders, plan communications and exception handling, and land security controls without disrupting how people work.
Evaluate and secure the tools Doctolibers adopt: conduct security reviews of SaaS integrations and AI tools, and deliver pragmatic, risk-based responses to shadow IT.
Investigate and improve : lead incident investigations on the corporate perimeter end-to-end, and continuously improve detection rules and response playbooks in our Elastic SIEM.
Mentor more junior engineers and contribute to a team culture of engineering excellence and peer review.
Who you are
Before you read on: if you don't have the exact profile described below, but you feel this job description matches your skill set, we still encourage you to apply.
You'll be a great fit if you:
Have 5+ years of hands-on experience securing corporate/enterprise environments — identity, endpoints, SaaS, and network — including at least 2 years at a senior level. You have built and enforced security controls in production (not only monitored alerts), and owned at least one significant program end-to-end, such as an MFA rollout, a device-compliance initiative, or a SaaS access-governance project.
Have strong daily mastery of GitHub, Terraform, and AI coding assistants (Claude or equivalent). You ship security work as reviewed pull requests and use AI agents as a structural part of your workflow, not an occasional helper.
Have deep identity & access expertise: identity providers, conditional access policies, OAuth/application governance, and modern authentication standards (passkeys, phishing-resistant MFA).
Have a pragmatic mindset, the ability to make decisions under uncertainty and follow through, and strong written communication skills — you can carry a proposal from draft to cross-team adoption.
Are fluent in English (working language in writing); daily team conversations happen mostly in French , so being a French speaker or willing to learn is a strong plus.
It would be fantastic if you:
Have detection engineering or SIEM experience (writing and tuning your own queries).
Are curious about platform security topics (cloud, Kubernetes, supply chain) and willing to contribute beyond your core perimeter.
Have prior experience in a regulated industry (healthcare, fintech, or public sector).
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·Free comprehensive health insurance (basic package) for you and your children
- ·25 days of paid vacation per year, plus up to 14 days of RTT
- ·Free mental health and coaching services through our partner Moka.care
- ·Work from abroad for up to 10 days per year thanks to our flexibility days policy
- ·Lunch vouchers (Swile card) worth €8.50 per working day, with €4.50 covered by Doctolib
How to apply
- 1Check the flexibility label above, hybrid, matches where you plan to live and work.
- 2Tailor your CV to the role at Doctolib, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $180k to $230k per year · You'll be taken to the employer's careers page.