Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Lead Security Engineer image - Rise Careers
Job details

Lead Security Engineer

We're a product-first team on a mission to help grow the cybersecurity culture 🔐


We want to instill cybersecurity good practices to employees in a way that's actually effective, and entertaining enough so that employees don't feel like they're working. Think Duolingo but for cybersecurity.


We created a platform to easily rollout a cybersecurity awareness program: the platform sends chat-based 4-minutes long courses to teams. Following the courses, the other side of the platform simulates phishing attacks, to prepare employees to face hackers — but in a safe environment.


Created in 2020, Riot has raised $30m with leading investors (Y Combinator, Left Lane, Base10, Funders Club and Frst Capital) and is now protecting more than 1 million employees in over 1,500 companies (including Intercom, Deel, and Deezer) all over the world.


Cybersecurity is everywhere. It's impacting everyone, everyday, and it's becoming the number one risk to any organization, whether it's a small business or a big firm. Yet, the cybersecurity culture in most companies is a disaster. Hackers are leveraging this by targeting the weakest link: the employees. We're on a mission to fix that.


As the first Security Engineer in our organization, you will lead and define our security strategy across IT management, security programs, compliance, and application security (AppSec). You will play a crucial role in ensuring our infrastructure, software, and processes are secure, scalable, and compliant with industry standards. This is an opportunity to establish and drive security initiatives from the ground up in a dynamic cybersecurity environment.


What you will do 🤝


- Lead security initiatives like bug bounty, penetration testing, app monitoring, dependency management, and secure IaC with DevOps.

- Maintain SOC2 compliance, implement ISO27001, and manage audits and third-party security reviews.

- Embed security into development workflows, fix vulnerabilities, and deploy AppSec tools and processes.

- Manage IT operations including MDM, employee access, and infrastructure security controls.


Who you are 🪪
  • Experience: 3-7 years experience in security engineering or software engineering.
  • Familiarity with SOC2, ISO27001, and compliance frameworks.
  • You have hands-on experience with bug bounty programs, penetration testing programs, and vulnerability management.
  • You have strong communication and ability to work collaboratively with engineering and cross-functional teams.
  • You have a full professional proficiency in English and native in French
  • You're based in Paris or you're willing to relocate


It will be a cultural fit if 🫂
  • You're a doer: not afraid to get your hands dirty and get things done
  • You have high standards: expect performance to be nothing short of the best
  • You are an enthusiastic at heart: exhibit passion and excitement over work


Why join us at Riot 💜
  • Join a healthy-financial company: we already are break-even, fundraising helps us to accelerate our scale!
  • Contribute to a fast-moving environment where growth is real—our revenue grew by an impressive 2.5x in 2024!
  • Experience the energy of a collaborative team in our modern and cosy office located in heart of Paris: Le Marais


Recruitment process 🎙️
  • First call with the software engineer currently leading the security effort (30min)
  • Onsite case study with the CTO (2hr)


€65,000 - €80,000 a year

At RIOT, we believe that diversity drives innovation and inclusion fosters belonging. We are committed to building a team that reflects a wide range of perspectives, backgrounds, and experiences. We welcome candidates from all walks of life and are dedicated to creating an environment where everyone feels valued, respected, and empowered to thrive.


Please note that this is an on-site position with up to 2 days per week of remote work.

Average salary estimate

$72500 / YEARLY (est.)
min
max
$65000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Lead Security Engineer, Riot Security

Join Riot as a Lead Security Engineer in the beautiful city of Paris! We’re a product-first company dedicated to changing the narrative around cybersecurity. Our mission is to create a culture of cybersecurity that’s not only effective but also engaging and fun for employees. Think of us as the Duolingo of cybersecurity, making learning an enjoyable experience. Our innovative platform delivers short, interactive courses via chat to help users enhance their cybersecurity knowledge, followed by real-world simulations of phishing attacks to prepare them for the threat landscape. With over $30 million raised and a growing user base exceeding 1 million employees across 1,500 companies—such as Intercom and Deezer—we're making a significant impact in the industry. In this role, you will be pivotal in shaping our security strategy, covering IT management to application security. You'll drive vital initiatives like bug bounty programs and penetration testing while ensuring compliance with SOC2 and ISO27001 standards. If you have 3-7 years of experience in security engineering, thrive in collaborative environments, and share our passion for cybersecurity, you might be the perfect fit. Embrace the opportunity to innovate within a dynamic team and contribute to securing organizations against ever-evolving threats. Let's join forces to enhance cybersecurity culture together!

Frequently Asked Questions (FAQs) for Lead Security Engineer Role at Riot Security
What responsibilities does the Lead Security Engineer at Riot have?

As the Lead Security Engineer at Riot, you'll take on an array of responsibilities that are crucial to our cybersecurity mission. You'll lead initiatives such as bug bounty programs and penetration testing, ensuring our systems and software are secure and resilient against threats. Additionally, you'll manage compliance tasks related to SOC2 and ISO27001, helping to implement robust security measures alongside collaborative engineering and cross-functional teams.

Join Rise to see the full answer
What qualifications are required for the Lead Security Engineer position at Riot?

To qualify for the Lead Security Engineer position at Riot, candidates should possess 3-7 years of experience in security engineering or related disciplines. Familiarity with compliance frameworks such as SOC2 and ISO27001 is essential, alongside hands-on experience with bug bounty and penetration testing programs. Strong communication skills and the ability to collaborate effectively within teams are also important. Proficiency in English and fluency in French is required, along with a willingness to work in Paris.

Join Rise to see the full answer
What is the work culture like for the Lead Security Engineer at Riot?

The work culture for the Lead Security Engineer role at Riot is dynamic and collaborative. You will be expected to take initiative and exhibit a high level of enthusiasm for your work. We seek individuals who are not just doers but also hold high standards for performance. Our modern office in Le Marais, Paris, promotes a productive environment where diverse perspectives are valued, ensuring everyone feels empowered to thrive.

Join Rise to see the full answer
How does Riot support professional development for the Lead Security Engineer?

At Riot, we recognize the importance of professional development for our Lead Security Engineer. You'll have opportunities to drive security initiatives from the ground up while working alongside experienced professionals. We foster a culture of learning, which includes participating in security workshops, conferences, and gaining insights into the latest security technologies and practices. We believe that as we grow, so will you.

Join Rise to see the full answer
What is the recruitment process for the Lead Security Engineer role at Riot?

The recruitment process for the Lead Security Engineer position at Riot begins with an introductory call with the current security lead. Following that, candidates will partake in an onsite case study with our CTO. This two-step process is designed not just to assess skills but also to ensure alignment with our organizational culture and values, giving insight into how you'll fit into our energetic team.

Join Rise to see the full answer
Common Interview Questions for Lead Security Engineer
Can you describe your experience with bug bounty programs as a Lead Security Engineer?

In your response, detail your previous involvement with bug bounty programs, including how you managed them and any tools you used. Highlight any particular successes or lessons learned from handling vulnerabilities, emphasizing your ability to collaborate with engineering teams to remediate issues.

Join Rise to see the full answer
How do you approach penetration testing in a software development lifecycle?

Explain your strategy for incorporating penetration testing within the software development lifecycle. You might discuss your approach to planning, executing tests, and working with development teams to address vulnerabilities. Share any frameworks or tools you have utilized in past roles to convey your methodology.

Join Rise to see the full answer
What steps do you take to ensure compliance with SOC2 and ISO27001?

Detail the process you follow for maintaining compliance with SOC2 and ISO27001. This can include regular audits, risk assessments, and establishing policies and procedures to meet compliance requirements. Be sure to mention any specific experiences that illustrate your success in achieving and maintaining these standards.

Join Rise to see the full answer
How do you manage vulnerabilities found during security assessments?

Focus on how you prioritize vulnerabilities based on risk and impact. Discuss your process for documenting findings, communicating with development teams, and tracking remediation progress while ensuring that security measures align with business objectives.

Join Rise to see the full answer
How do you keep up with the latest trends in cybersecurity?

Share the resources you rely on to stay informed about trends in cybersecurity, such as blogs, webinars, conferences, and professional networks. Explain how you apply new knowledge to enhance your strategies and practices in your role as a Lead Security Engineer.

Join Rise to see the full answer
What tools and technologies do you find essential for security engineering?

Describe the tools and technologies you consider vital for enhancing security. This could include programs for vulnerability management, compliance tracking, or Incident Response. Discuss your rationale for using these tools and how they have improved your security practices in previous roles.

Join Rise to see the full answer
How do you promote a culture of security awareness among employees?

Discuss strategies you’ve implemented to ensure that cybersecurity awareness is integrated into the workplace culture. This might involve training sessions, reminders, or gamified learning experiences, particularly how you would utilize our chat-based platform to engage employees effectively.

Join Rise to see the full answer
Describe a challenging security issue you've handled in the past.

Narrate a specific security challenge you've faced, detailing your approach to resolving it. This should include analysis, team collaboration, and the outcome. Your answer should demonstrate critical thinking, problem-solving skills, and your capability in leading a team through complex scenarios.

Join Rise to see the full answer
How do you balance security measures with the need for usability in software products?

Share your philosophy on balancing security and usability, focusing on your experience in integrating security features without compromising user experience. Discuss specific instances where you’ve successfully implemented security while maintaining a user-friendly approach.

Join Rise to see the full answer
What is your experience with secure Infrastructure as Code (IaC)?

Talk about your practical experience with secure Infrastructure as Code (IaC), including frameworks you've used, how you ensure security practices are embedded in the IaC workflow, and any successful implementations you've overseen that led to improved security posture.

Join Rise to see the full answer
Similar Jobs

Embark on an exciting journey with Riot as an Account Executive, playing a crucial role in expanding our cybersecurity education platform in Spain.

Photo of the Rise User
Posted 12 days ago

Exciting opportunity for a Systems Administrator Advisor to join Abile Group, working within the Intelligence Community on impactful IT services.

Photo of the Rise User
General Dynamics Information Technology Hybrid US, Sarpy County, NE; Nebraska, Offutt Air Force Base, NE
Posted 11 days ago

As a Network Engineer at GDIT, you will play a crucial role in providing mission-critical IT services and support for the USSTRATCOM enterprise.

Photo of the Rise User

Seeking a skilled PC Maintenance Tech II to support IT operations at the University of Maryland Medical System.

Photo of the Rise User
Customer-Centric
Mission Driven
Inclusive & Diverse
Rise from Within
Diversity of Opinions
Work/Life Harmony
Growth & Learning
Transparent & Candid
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Child Care stipend
Paternity Leave
WFH Reimbursements
Flex-Friendly
Dental Insurance
Vision Insurance
Life insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Military leave

Join NVIDIA as a Senior Solutions Architect to lead innovations in Cloud Infrastructure and DevOps in a fully remote role.

Photo of the Rise User

Join a dynamic healthcare organization as a Web Developer and SEO Specialist focusing on website development and search engine optimization.

Photo of the Rise User

Join the University of Maryland Medical System as a PC Maintenance Tech II to deliver high-quality technical support for computer systems and devices.

Photo of the Rise User

We are looking for a skilled Application Support Engineer to provide critical support for our trade processing applications at OSTTRA in New York City.

Photo of the Rise User

As a Technical Integrations Specialist at MCG, you'll drive partnerships and ensure critical integration of healthcare systems for improved patient care.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 12, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, North Canton just viewed NodeJs developer at BlackStone eIT
Photo of the Rise User
Someone from OH, North Canton just viewed Software Development Engineer - Recent Grads Welcome at Sonos
Photo of the Rise User
16 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry and Word Processing at MoxieIT
Photo of the Rise User
Someone from OH, Dayton just viewed Content Developer - Intern at Big Ideas Learning
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Lead at Bounteous
Photo of the Rise User
Someone from OH, Pickerington just viewed Industry Lead - High Tech (Salesforce) at Thunder
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Success Manager, US SLED at Dataminr
Photo of the Rise User
Someone from OH, Greenville just viewed Systems Engineer (Linux & Shell or Python scripting) at Visa
Photo of the Rise User
Someone from OH, Greenville just viewed Help Desk Technician - Youngstown at R.I.T.A.
Photo of the Rise User
Someone from OH, Mount Orab just viewed Backend Developer at G2i Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Product Marketing Manager at Cast & Crew
Photo of the Rise User
Someone from OH, Cincinnati just viewed Marketing Manager at Cast & Crew
o
Someone from OH, Cincinnati just viewed Administrative Assistant at osu
A
Someone from OH, Cincinnati just viewed Data Entry Clerk at Alphabe Insight Inc