Voltar às vagas
ScovaiScovaiJobs
Wooclap

Wooclap

Security Engineer (SOC/AppSec)

Paris, FRPresencialPermanenteTempo integral

Publicado 3 de set. de 2026

Esta vaga foi publicada em FR

As a Security Engineer (SOC/AppSec), you will own Wooclap's operational and application security, reporting to the Director of Engineering. You will be the go-to person for security incident detection and response (SOC) as well as for securing the application lifecycle (AppSec), working closely with the Engineering, DevOps and Product teams, as well as with the Legal & Compliance officer.

This hybrid role combines continuous security monitoring with dedicated expertise in reducing our products' attack surface from the design stage onwards. It is a role with a high level of autonomy and responsibility: you set your own priorities and evolve your tooling and processes, with the direct support of the Director of Engineering and a dedicated budget. Rigour and confidentiality are non-negotiable: you will handle sensitive information relating to the security of the company and its customers. You will communicate mainly in English.

Key responsibilities

Detection & response (SOC)

  • Own and evolve the detection tooling (SIEM / EDR): selection, tuning, industrialisation.

  • Qualify incidents and lead first- and second-level investigations: triage, log analysis, event correlation.

  • Drive incident response and write post-incident reports (root cause, remediation, lessons learned).

  • Evolve detection rules (use cases, correlation, false-positive reduction) and keep watch on emerging threats (threat intelligence).

Application security (AppSec)

  • Carry out code security reviews (SAST) and application penetration tests (DAST, manual testing).

  • Analyse dependencies and third-party components (SCA) to identify known vulnerabilities (CVEs) and drive their remediation with the development teams.

  • Maintain and improve security controls in the CI/CD pipelines (DevSecOps) to catch issues as early as possible.

  • Take part in threat modelling for new features and architectures.

  • Raise awareness and train the development teams in security best practices (secure coding).

Compliance & assurance

  • Own the ISO 27001 certification: maintaining the framework, preparing and following up on audits, driving action plans.

  • Lead the annual security audit and the pentest campaign: scoping, relationship with providers, remediation follow-up.

  • Work closely with the Legal & Compliance officer: responses to customer security questionnaires, security-related contractual clauses (DPA, SLA), and management of incidents with a contractual or regulatory dimension.

  • Maintain and improve operational security processes, tools and metrics, and report regularly to the Director of Engineering on the security posture and identified risks.

  • Benefit from a dedicated budget for security tooling (SIEM/EDR, SAST/DAST/SCA scanners, etc.).

Tech stack

  • Frontend : React, TypeScript

  • Backend : Node.js, Go

  • Infra : AWS, Kubernetes, Terraform

  • AI : Claude subscription covered by the company

  • More than 5 years of experience in operational security (SOC) and/or application security (AppSec), ideally in a SaaS or fast-growing tech environment.

  • Strong command of SOC detection mechanisms (SIEM, EDR, event correlation, threat hunting).

  • Good knowledge of AppSec methodologies: OWASP Top 10, OWASP ASVS, SAST/DAST/SCA.

  • Working knowledge of scripting/programming (Python, JavaScript/TypeScript, or equivalent) for automation and code analysis.

  • Hands-on DevSecOps practice and integration into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, etc.).

Bonus points if you...

  • Hold a security certification (OSCP, eWPT, GWAPT, CEH, Security+, etc.).

  • Have experience in pentesting or bug bounty.

  • Are familiar with compliance frameworks (GDPR, ISO 27001, NIS2).

Why join Wooclap

Meaningful impact - Make a real contribution to helping millions of students and trainers around the world engage better with their learning.

A collaborative, international team - Join a team of 80+ Wooclapers who value trust, curiosity and mutual support across borders.

Flexibility - A 100% remote role, with flexible hours and no on-call duty.

Tangible benefits

  • 🏥 Health insurance fully covered for you and your children (Alan)

  • 📚 Learning budget: €150/year on top of training (Woocredits)

  • 📱 Phone subscription reimbursement

  • 🍽️ Meal vouchers

  • 🏠 Monthly remote-work allowance

  • 🤖 Claude (Anthropic) subscription covered by the company

  • 🇧🇪 Belgium: extra days off, eco-vouchers, mobility budget

  • ☎️ 30' Screening interview with the Talent Acquisition Manager

  • 🧭 45' Managerial interview with the Director of Engineering

  • 🧩 45' Technical case study (SOC/AppSec) with the Engineering team

  • 🤝 60' Culture fit interview with 2 or 3 Wooclapers

  • 🔊 30' Interview with the CEO

Resumo da função

Tipo de vaga

Tempo integral

Email

lucie.ledoyen@wooclap.com

Competências necessárias

SIEM (Security Information and Event Management) administration and tuningEDR (Endpoint Detection and Response) administration and tuningIncident response and digital forensics (SOC triage, investigations, post-incident reporting)Threat hunting and threat intelligence (detection rule evolution, emerging threats)Static Application Security Testing (SAST) / code security reviewsDynamic Application Security Testing (DAST) and manual application penetration testingSoftware Composition Analysis (SCA) and dependency vulnerability (CVE) managementDevSecOps and CI/CD pipeline security integration (GitHub Actions, GitLab CI, Jenkins, etc.)Threat modeling for features and architecturesKnowledge of OWASP methodologies (OWASP Top 10, OWASP ASVS)ISO 27001 management, audit preparation and certification ownershipScripting and automation for security (Python, JavaScript/TypeScript)Security tooling evaluation, selection and procurement (SIEM/EDR, SAST/DAST/SCA scanners)Security compliance and contractual management (customer security questionnaires, DPA, SLA)

Vagas similares

ACADEMICA DUAL DIPLOMA

Alternance Chargé.e des Admissions et de la Relation Familles (F/H)

ACADEMICA DUAL DIPLOMA

Paris, FRPresencialPermanenteTempo integral
há 17 horas
ACADEMICA DUAL DIPLOMA

Chargé Relations Partenaires – CDI (F/H)

ACADEMICA DUAL DIPLOMA

Paris, FRPresencialPermanenteTempo integral
há 8 dias
Refugee Food

Responsable du Comptoir Refugee Food (H/F)

Refugee Food

Paris, FRPresencialPermanenteTempo integral
há 9 dias
Cartoonbase

Directeur·ice de comptes

Cartoonbase

Paris, FRPresencialPermanenteTempo integral
mês passado
Wooclap

Stagiaire Operations et Customer Success

Wooclap

Paris, FRPresencialContratoTempo integral
há 16 horas
M Education

Bras Droit des Fondateurs [Stage @ Paris]

M Education

Paris, FRPresencialContratoTempo integral
há 3 dias