SlipstreamJobsFresh Startup & VC-Backed Jobs

Platform Security Engineer (x/f/m)

Doctolib - Levallois-Perret, Île-de-France, France - Hybrid - posted 2026-09-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Doctolib is seeking a Platform Security Engineer to join its Security team. Your mission is to protect sensitive healthcare data while enabling rapid, secure innovation across Doctolib's cloud infrastructure and application ecosystem. You will combine multi-cloud security expertise with hands-on platform engineering, contributing directly to the safety of millions of patients and care teams who rely on the platform. Key Responsibilities: - Own platform security workstreams end-to-end, from architecture to enforcement: scope initiatives with your tech lead, design controls, roll out progressively (report-only mode, then enforcement), handle exceptions, and drive to full coverage. Examples include hardening IAM across AWS accounts, tightening cluster admission policies, or closing misconfiguration classes. - Ship all changes as infrastructure-as-code using Terraform and GitHub pull requests, peer-reviewed and always reversible. No console clicking or undocumented state. - Harden and maintain cloud and infrastructure baselines: manage IAM permissions and access reviews, secrets management, network and cluster guardrails, CI/CD and supply chain controls. Drive remediation with platform and engineering teams, converting recurring findings into automation rather than manual tickets. - Lead incident investigations on the platform perimeter end-to-end and continuously improve detection rules and response playbooks in Elastic SIEM. - Work transparently: write clear technical notes, drive adoption of changes with affected engineering teams, and grow through code review and pairing with the security team. Tech Stack: Terraform, AWS, Kubernetes, Elastic SIEM, GitHub. Doctolib's Tech Environment: Solutions are built on a fully cloud-native platform supporting web and mobile interfaces, multiple languages, and country/specialty-specific healthcare requirements. The stack includes Rails, TypeScript, Java, Python, Kotlin, Swift, and React Native. The company leverages AI ethically across products to empower patients and health professionals. Requirements: - 1 to 3 years of hands-on experience in security engineering, security operations, SRE, infrastructure, or platform engineering, including exposure to a cloud environment (AWS, GCP, or Azure) in production. Internships or apprenticeships in these roles count. - Daily work with infrastructure-as-code and GitHub: you have written and shipped Terraform through reviewed pull requests and are comfortable operating and debugging workloads on Kubernetes. - Use AI coding assistants (Claude or equivalent) as a normal part of your workflow. - Have carried at least one project through to production—security or not—and stayed with it past initial deployment until it was actually adopted. - Solid fundamentals in Linux, networking, cloud, Kubernetes, and development/scripting. Pragmatic mindset, ability to make decisions under uncertainty and follow through, and strong written communication skills. Ability to carry proposals from draft to cross-team adoption. - Fluent in English (working language in writing). French fluency or willingness to learn is a strong plus, as daily team conversations happen mostly in French. Nice-to-Have: - Experience with SIEM tools (Elastic, Splunk, or equivalent), writing and tuning queries. - Background in detection engineering, incident response, threat hunting, or CTFs. - Public write-ups, open-source contributions, or home lab projects. - Prior experience in regulated industries (healthcare, fintech, or public sector).

Similar roles