SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Dashlane is a credential security platform trusted by millions of consumers and over 25,000 brands worldwide, including Michelin, Air France, and Forrester. The company is headquartered in Paris with offices in New York and Lisbon, and employs over 300 people globally.
As a Senior Security Engineer (titled "Staff Application Security Engineer" in the posting), you will play a crucial role in safeguarding Dashlane's systems and ensuring the company maintains a cutting-edge secure development lifecycle. You will collaborate across all departments to advocate for and implement best-in-class security practices, helping millions of Dashlane users enjoy a safer digital life.
Key responsibilities include:
- Drive continuous improvement of Dashlane's security program across product and company infrastructure
- Conduct architecture design reviews, threat modeling, and technical security assessments of Dashlane's product (application and infrastructure) to identify security risks and provide mitigation guidance
- Ensure security best practices are integrated throughout the software development lifecycle (SDLC)
- Build upon and scale Vulnerability Management to track, analyze, and manage vulnerabilities and their remediation
- Perform risk assessments of Dashlane's internal systems, environments, assets, and data, and implement security best practices accordingly
- Evaluate and implement security tooling, or build customized tooling in-house where necessary
- Participate in Compliance and Incident Response activities
- Innovate and propose new forward-looking security features that protect Dashlane and its users
You will be based in Paris with English as your working language. Dashlane operates a hybrid model: you will come together in the office on Mondays, Tuesdays, and Thursdays, while Wednesdays and Fridays offer flexibility for focused work.
Critical competencies include strong communication and collaboration skills (engaging empathetically with both technical and non-technical audiences), mentoring ability, motivated learning, and adaptability across technical and non-technical business domains.
REQUIREMENTS:
- Strong understanding of application security best practices, including experience with threat modeling and risk assessments
- Demonstrated experience building or improving an SDLC program
- Familiarity with CI/CD pipelines and their security implications
- Familiarity with cloud infrastructure (e.g., AWS, Azure, Kubernetes) and Infrastructure-as-Code (e.g., Terraform)
- Interest in enabling secure use of AI tools to drive efficiency, creativity, and impact internally
BONUS QUALIFICATIONS:
- Interest in cryptography and its application in modern systems
- Experience in Identity and Access Management (IAM) frameworks and protocols (Passkeys, SAML, OAuth, SCIM, etc.)