
Stripe · SF
WHO WE ARE ABOUT STRIPE Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ...
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the
most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission
is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented
opportunity to put the global economy within everyone's reach while doing the most important work of your career.
We're creating an entirely new payments platform, built with stablecoins, to simplify global money movement. Bridge enables
faster, cheaper payments and borderless access to dollars via stablecoins. Through our APIs, businesses can send and receive funds
across borders faster and cheaper vs. SWIFT and other fiat-only rails. Our virtual accounts enable international consumers and
businesses to easily access, store, and spend US dollars. Our payouts infrastructure enables platforms to disburse USD to anyone
globally. We believe many trillions of dollars will move and settle through stablecoin payment rails. Bridge is pulling this
future forward.
We have a small team of people who have previously built financial infrastructure at some of the world's leading companies
(Coinbase, Stripe, Square, Brex, Upstart, DoorDash, Airbnb), and each and every one of them chose Bridge because they
fundamentally believe that stablecoins will be a critical piece of financial infrastructure that allows for the improvement of
global money movement.
We're hiring a Security Engineer to build and scale the Bridge security foundation. This is a rare opportunity to design a
security program from the ground up, while also leveraging the infrastructure, best practices, and tooling of one of the most
mature security organizations in the industry.
hardening.
compromising safety.
About Agoda At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world. Today, we are part of Booking Holdings [NASDAQ: BKNG], with a diverse team of over 7,000 people from 90 countries, working together in offices around the globe. Every day, we connect people to destinations and experiences, with our great deals across our millions of hotels and holiday properties, flights, and experiences worldwide. No two days are the same at Agoda. Data and technology are at the heart of our culture, fueling our curiosity and innovation. If you’re ready to begin your best journey and help build travel for the world, join us. We are looking for a hands on Senior Security Engineer to secure our cloud and platform environments. This role works closely with engineering teams and focuses on building, reviewing, and operating security controls using Infrastructure as Code, Kubernetes, and custom security services written in Go and TypeScript. Key Responsibilities: Secure Cloud Deployment: * Design, implement, and manage secure cloud deployments across AWS and GCP environments using Terraform. * Kubernetes & GitOps Security: Deploy and manage both internal and third‑party security products within the Kubernetes ecosystem. * Work with GitOps workflows using tools like Argo CD and Flux, and Helm charts. * Security Automation & Tooling: Design and build security tooling and services using Go and TypeScript. * Misconfiguration Management: Proactively identify, analyze, and remediate cloud misconfigurations. * Cloud Architecture Guidance: Provide guidance to Engineering teams on secure architecture. * Threat Detection & Response: Build and optimize cloud-native detection rules and alerting pipelines to monitor for suspicious activities within the cloud and container workloads. Required Skills & Experience: * 8+ years of experience in security engineering, cloud security, or platform engineering roles. * Hands-on experience securing production workloads in AWS and GCP. * Strong experience designing and securing Infrastructure as Code using Terraform. * Deep understanding of Kubernetes security, including troubleshooting Helm deployments and GitOps-based workflows. * Strong programming skills in Go and TypeScript, with Python used for automation where appropriate. * Experience embedding security controls into CI/CD pipelines. * Certifications (Required) Certified Kubernetes Administrator (CKA) Certified Kubernetes Security Specialist (CKS) Certifications (Preferred) AWS Certified Security * Specialty Google Professional Cloud Security Engineer HashiCorp Certified: Terraform Associate * Nice-to-Have Experience with Policy-as-Code frameworks such as Open Policy Agent (OPA). * Experience securing service mesh environments (Istio). Background in software engineering or platform engineering before moving into security. #sanfrancisco #sanjose #losangeles #sandiego #oakland #denver #miami #orlando #atlanta #chicago #boston #detroit #newyork #portland #philadelphia #dallas #houston #austin #seattle #sydney #melbourne #perth #toronto #vancouver #montreal #shanghai #beijing #shenzhen #prague #Brno #Ostrava #cairo #alexandria #giza #estonia #paris #berlin #munich #hamburg #stuttgart #cologne #frankfurt #hongkong #budapest #jakarta #bali #dublin #telaviv #milan #rome #venice #florence #naples #turin #palermo #bologna #tokyo #osaka #kualalumpur #malta #amsterdam #oslo #manila #warsaw #krakow #doha #alrayyan #riyadh #jeddah #mecca #medina #singapore #seoul #barcelona #madrid #stockholm #zurich #taipei #tainan #taichung #kaohsiung #bangkok #Phuket #istanbul #london #manchester #liverpool #edinburgh #hcmc #hanoi #lodz #wroclaw #poznan #katowice #rio #salvador #newdelhi #bangalore #bandung #yokohama #nagoya #okinawa #fukuoka #jerusalem #IT #4 #LI-RS1 PLEASE REVIEW OUR HIRING PROCESS GUIDELINES BEFORE YOUR INTERVIEW — CLICK HERE TO LEARN HOW INTERVIEWING AT AGODA WORKS. DISCOVER MORE ABOUT WORKING AT AGODA * Agoda Careers https://careersatagoda.com * Facebook https://www.facebook.com/agodacareers/ * LinkedIn https://www.linkedin.com/company/agoda * YouTube https://www.youtube.com/agodalife Equal Opportunity Employer At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and innovation. Employment at Agoda is based solely on a person’s merit and qualifications. We are committed to providing equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics. We will keep your application on file so that we can consider you for future vacancies and you can always ask to have your details removed from the file. For more details please read our privacy policy. Disclaimer We do not accept any terms or conditions, nor do we recognize any agency’s representation of a candidate, from unsolicited third-party or agency submissions. If we receive unsolicited or speculative CVs, we reserve the right to contact and hire the candidate directly without any obligation to pay a recruitment fee.
About Agoda At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world. Today, we are part of Booking Holdings [NASDAQ: BKNG], with a diverse team of over 7,000 people from 90 countries, working together in offices around the globe. Every day, we connect people to destinations and experiences, with our great deals across our millions of hotels and holiday properties, flights, and experiences worldwide. No two days are the same at Agoda. Data and technology are at the heart of our culture, fueling our curiosity and innovation. If you’re ready to begin your best journey and help build travel for the world, join us. We are looking for a hands on Senior Security Engineer to secure our cloud and platform environments. This role works closely with engineering teams and focuses on building, reviewing, and operating security controls using Infrastructure as Code, Kubernetes, and custom security services written in Go and TypeScript. Key Responsibilities: Secure Cloud Deployment: * Design, implement, and manage secure cloud deployments across AWS and GCP environments using Terraform. * Kubernetes & GitOps Security: Deploy and manage both internal and third‑party security products within the Kubernetes ecosystem. * Work with GitOps workflows using tools like Argo CD and Flux, and Helm charts. * Security Automation & Tooling: Design and build security tooling and services using Go and TypeScript. * Misconfiguration Management: Proactively identify, analyze, and remediate cloud misconfigurations. * Cloud Architecture Guidance: Provide guidance to Engineering teams on secure architecture. * Threat Detection & Response: Build and optimize cloud-native detection rules and alerting pipelines to monitor for suspicious activities within the cloud and container workloads. Required Skills & Experience: * 8+ years of experience in security engineering, cloud security, or platform engineering roles. * Hands-on experience securing production workloads in AWS and GCP. * Strong experience designing and securing Infrastructure as Code using Terraform. * Deep understanding of Kubernetes security, including troubleshooting Helm deployments and GitOps-based workflows. * Strong programming skills in Go and TypeScript, with Python used for automation where appropriate. * Experience embedding security controls into CI/CD pipelines. * Certifications (Required) Certified Kubernetes Administrator (CKA) Certified Kubernetes Security Specialist (CKS) Certifications (Preferred) AWS Certified Security * Specialty Google Professional Cloud Security Engineer HashiCorp Certified: Terraform Associate * Nice-to-Have Experience with Policy-as-Code frameworks such as Open Policy Agent (OPA). * Experience securing service mesh environments (Istio). Background in software engineering or platform engineering before moving into security. PLEASE REVIEW OUR HIRING PROCESS GUIDELINES BEFORE YOUR INTERVIEW — CLICK HERE TO LEARN HOW INTERVIEWING AT AGODA WORKS. DISCOVER MORE ABOUT WORKING AT AGODA * Agoda Careers https://careersatagoda.com * Facebook https://www.facebook.com/agodacareers/ * LinkedIn https://www.linkedin.com/company/agoda * YouTube https://www.youtube.com/agodalife Equal Opportunity Employer At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and innovation. Employment at Agoda is based solely on a person’s merit and qualifications. We are committed to providing equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics. We will keep your application on file so that we can consider you for future vacancies and you can always ask to have your details removed from the file. For more details please read our privacy policy. Disclaimer We do not accept any terms or conditions, nor do we recognize any agency’s representation of a candidate, from unsolicited third-party or agency submissions. If we receive unsolicited or speculative CVs, we reserve the right to contact and hire the candidate directly without any obligation to pay a recruitment fee.
HEALTH CAN’T WAIT. Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t. Alan exists to end the wait. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way. So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. We are on an incredible journey to build a global leading company, with a unique culture. We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR. Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond. Alan operates at the intersection of health insurance, prevention, and regulated data. The person in this role owns the security governance and risk posture of a company that handles sensitive health data for 1M+ members, operates under DORA and HDS certification requirements, and is regulated by the ACPR. They work in close partnership with Legal, Internal Audit, and the broader Risk function. It's a highly collaborative role. 🛡️ YOUR MISSION: GOVERNANCE, RISK & COMPLIANCE Own and operate the ISO 27001 ISMS. You are the accountable owner of the Information Security Management System: scope definition, Statement of Applicability, internal audit programme, and management review. You've led at least one full certification or recertification cycle and know what breaks down in the months between audits. Be the security expert on regulatory and privacy matters. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships. Your role is to bring the technical and operational security substance: translating regulatory requirements into controls, flagging implementation gaps, and making sure the security programme is solid when the regulatory team negotiates with the ACPR or ANS. Run risk as an ongoing programme, in partnership with the broader risk function. You lead security risk cartography using EBIOS RM and ensure it feeds into, and is informed by, the company-wide risk framework. You facilitate risk workshops, produce treatment plans, and bring the security lens to forums where non-security risks are also on the table. You know when a security risk is really a business risk. Own the controls framework, but distribute ownership of controls themselves. You define the framework, set the standards, and track coverage, but the controls live with the teams who build and run the things they protect. You work closely with Infrastructure, Platform, and Engineering to ensure foundational building blocks (identity, network, secrets management, logging) are designed with security requirements built in from the start. You work alongside those teams as a partner. Run audit cycles with rigour, in close partnership with Internal Audit. You manage the security audit programme and coordinate with certification bodies. You work with Internal Audit to align scopes, avoid duplication, and present a coherent picture of control effectiveness to the board. You've sat in joint audit planning sessions and know how to make that relationship work well. Manage third-party risk. You run vendor security assessments and define contractual security requirements (security annexes, DPAs). You partner with our Risk team, which oversees third-party risk, and own the security dimension. Bring the health sector context. You understand the ANS framework, CERT Santé requirements, and what it means to handle sensitive health data in day-to-day operations. You're a useful partner to Legal when the question is "what does this regulation actually require us to do technically?" Own incident governance and support DORA reporting. You classify and escalate ICT incidents internally, own BCP and DRP governance, and provide the security substance for DORA incident reports. 🚀 WHAT YOU'LL BUILD AND WHO YOU'LL WORK WITH Compliance Framework: ISO 27001, DORA, HDS, NIS2. Multiple regulators, multiple countries, one coherent governance backbone. Build the system that lets Alan scale from 1M to many millions of members without rebuilding compliance every time. Automated Audit & Evidence Engine: Replace manual evidence collection with scripted pipelines plugged directly into engineering systems. Turn audit cycles into a continuous capability instead of a quarterly rush. Risk Cartography: Risk treated as an operational signal that feeds directly into business and engineering decisions, with EBIOS RM at the core. You'll work closely with Legal, DPO, Internal Audit, and the broader Risk function, and partner day-to-day with Infrastructure, Platform, Engineering, Product, and Operations. You're the bridge between regulatory complexity and operational simplicity. ⚡ WHY THIS ROLE IS SPECIAL Direct Impact: You own the trust foundation that lets Alan handle health data for 1M+ members and operate in highly regulated markets. Your work is the precondition for everything else Alan does. Complex Problems: 4 regulators across 4 countries, sensitive health data, and a regulatory landscape that keeps shifting (DORA, NIS2, AI Act), all to be modeled into a single, coherent control system. Ownership & Growth: Board and executive exposure, real influence on company-wide risk decisions, and the autonomy to shape Alan's security culture across 800+ people. 🤝 WHAT YOU WILL ALSO DO: TECHNICAL ENABLEMENT Automate compliance work wherever possible. You script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines. You've used Python or similar to reduce the manual work of an audit cycle, and you actively look for the next process to streamline. Configure and own GRC tooling. You can administer platforms like CISO Assistant, ServiceNow GRC, or Archer, designing workflows, building dashboards, and making them genuinely useful for the teams that feed them data. Speak cloud governance fluently. You understand shared responsibility in HDS-qualified environments, know what CSPM tools surface and what they miss, and can reason about policy-as-code (OPA, SCP) without needing an engineer to translate. Read architecture well enough to challenge it. You can review a proposed architecture, identify control gaps in identity, network segmentation, encryption, or logging, and push back credibly with engineers even though you're not one. Interpret vulnerability data and drive prioritisation. You read scan outputs, work with engineering teams to prioritise remediation by business impact over CVSS score alone, and track resolution KPIs over time. ⭐️ QUALIFICATIONS, MINDSET AND SOFT SKILLS You translate risk into business language. You can brief a board or an audit committee and leave them genuinely informed. You know the difference between a finding that requires an emergency board call and one that belongs in a quarterly report. You influence without authority. You align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers or adversarial dynamics. People come to you early because you make their work easier. You manage programmes with audit-grade rigor. You run structured, traceable roadmaps. You know where every commitment is, who owns it, and when it's due. You escalate proactively and don't let dependencies surprise you. You build a genuine security culture. Your awareness programmes land because they're relevant to the people who take them. You foster proportionate risk ownership across the company, so teams make better day-to-day decisions. You think in principles when frameworks shift. DORA is live. NIS2 transposition pace varies. The AI Act is arriving. When the regulatory landscape moves, you reason from first principles and adapt without waiting to be told what to do. 🌍 HOW WE WORK Location: You must be legally eligible to work from France. Remote work: We offer remote work flexibility, but we value in-person collaboration 🎯 IMPORTANT NOTE: WE HIRE PEOPLE, NOT ROLES. If you're excited about this opportunity but don't check every box, we'd love to hear from you. Everyone, no matter how underrepresented, should feel free to apply, as it can only bring learnings or success. If you identify yourself as a woman: Did you know that research shows women often apply only when meeting 100% of requirements? Remember, this is just a guide, not a checklist. We'll be thrilled to receive your application! 🔖 Check out our About Alan and Career pages, as well as our Medium, blog and Glassdoor page for more info. YOU WANT TO KNOW MORE ABOUT ALAN? 🙌 Perks & Benefits: Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend only high-quality time with co-workers. 🤘A strong culture: People joining Alan are often surprised and delighted by our innovative working method. We have a set of cultural values that guide our approach to work