
Alan · Anywhere in France
HEALTH CAN’T WAIT. Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today....
Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare
works today. You wait, until you can’t.
Alan exists to end the wait.
Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop
treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of
willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way.
So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and
care into a single, acclaimed user experience.
We are on an incredible journey to build a global leading company, with a unique culture. We already partner with 40K+ companies
of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR.
Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across
France, Spain, Belgium, and Canada. And beyond.
Alan operates at the intersection of health insurance, prevention, and regulated data. The person in this role owns the security
governance and risk posture of a company that handles sensitive health data for 1M+ members, operates under DORA and HDS
certification requirements, and is regulated by the ACPR. They work in close partnership with Legal, Internal Audit, and the
broader Risk function. It's a highly collaborative role.
Own and operate the ISO 27001 ISMS. You are the accountable owner of the Information Security Management System: scope definition,
Statement of Applicability, internal audit programme, and management review. You've led at least one full certification or
recertification cycle and know what breaks down in the months between audits.
Be the security expert on regulatory and privacy matters. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships.
Your role is to bring the technical and operational security substance: translating regulatory requirements into controls,
flagging implementation gaps, and making sure the security programme is solid when the regulatory team negotiates with the ACPR or
Run risk as an ongoing programme, in partnership with the broader risk function. You lead security risk cartography using EBIOS RM
and ensure it feeds into, and is informed by, the company-wide risk framework. You facilitate risk workshops, produce treatment
plans, and bring the security lens to forums where non-security risks are also on the table. You know when a security risk is
really a business risk.
Own the controls framework, but distribute ownership of controls themselves. You define the framework, set the standards, and
track coverage, but the controls live with the teams who build and run the things they protect. You work closely with
Infrastructure, Platform, and Engineering to ensure foundational building blocks (identity, network, secrets management, logging)
are designed with security requirements built in from the start. You work alongside those teams as a partner.
Run audit cycles with rigour, in close partnership with Internal Audit. You manage the security audit programme and coordinate
with certification bodies. You work with Internal Audit to align scopes, avoid duplication, and present a coherent picture of
control effectiveness to the board. You've sat in joint audit planning sessions and know how to make that relationship work well.
Manage third-party risk. You run vendor security assessments and define contractual security requirements (security annexes,
DPAs). You partner with our Risk team, which oversees third-party risk, and own the security dimension.
Bring the health sector context. You understand the ANS framework, CERT Santé requirements, and what it means to handle sensitive
health data in day-to-day operations. You're a useful partner to Legal when the question is "what does this regulation actually
require us to do technically?"
Own incident governance and support DORA reporting. You classify and escalate ICT incidents internally, own BCP and DRP
governance, and provide the security substance for DORA incident reports.
Compliance Framework: ISO 27001, DORA, HDS, NIS2. Multiple regulators, multiple countries, one coherent governance backbone. Build
the system that lets Alan scale from 1M to many millions of members without rebuilding compliance every time.
Automated Audit & Evidence Engine: Replace manual evidence collection with scripted pipelines plugged directly into engineering
systems. Turn audit cycles into a continuous capability instead of a quarterly rush.
Risk Cartography: Risk treated as an operational signal that feeds directly into business and engineering decisions, with EBIOS RM
at the core.
You'll work closely with Legal, DPO, Internal Audit, and the broader Risk function, and partner day-to-day with Infrastructure,
Platform, Engineering, Product, and Operations. You're the bridge between regulatory complexity and operational simplicity.
Direct Impact: You own the trust foundation that lets Alan handle health data for 1M+ members and operate in highly regulated
markets. Your work is the precondition for everything else Alan does.
Complex Problems: 4 regulators across 4 countries, sensitive health data, and a regulatory landscape that keeps shifting (DORA,
NIS2, AI Act), all to be modeled into a single, coherent control system.
Ownership & Growth: Board and executive exposure, real influence on company-wide risk decisions, and the autonomy to shape Alan's
security culture across 800+ people.
Automate compliance work wherever possible. You script evidence collection, automate control testing, and connect GRC tooling to
engineering pipelines. You've used Python or similar to reduce the manual work of an audit cycle, and you actively look for the
next process to streamline.
Configure and own GRC tooling. You can administer platforms like CISO Assistant, ServiceNow GRC, or Archer, designing workflows,
building dashboards, and making them genuinely useful for the teams that feed them data.
Speak cloud governance fluently. You understand shared responsibility in HDS-qualified environments, know what CSPM tools surface
and what they miss, and can reason about policy-as-code (OPA, SCP) without needing an engineer to translate.
Read architecture well enough to challenge it. You can review a proposed architecture, identify control gaps in identity, network
segmentation, encryption, or logging, and push back credibly with engineers even though you're not one.
Interpret vulnerability data and drive prioritisation. You read scan outputs, work with engineering teams to prioritise
remediation by business impact over CVSS score alone, and track resolution KPIs over time.
You translate risk into business language. You can brief a board or an audit committee and leave them genuinely informed. You know
the difference between a finding that requires an emergency board call and one that belongs in a quarterly report.
You influence without authority. You align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without
creating blockers or adversarial dynamics. People come to you early because you make their work easier.
You manage programmes with audit-grade rigor. You run structured, traceable roadmaps. You know where every commitment is, who owns
it, and when it's due. You escalate proactively and don't let dependencies surprise you.
You build a genuine security culture. Your awareness programmes land because they're relevant to the people who take them. You
foster proportionate risk ownership across the company, so teams make better day-to-day decisions.
You think in principles when frameworks shift. DORA is live. NIS2 transposition pace varies. The AI Act is arriving. When the
regulatory landscape moves, you reason from first principles and adapt without waiting to be told what to do.
Location: You must be legally eligible to work from France.
Remote work: We offer remote work flexibility, but we value in-person collaboration
If you're excited about this opportunity but don't check every box, we'd love to hear from you. Everyone, no matter how
underrepresented, should feel free to apply, as it can only bring learnings or success.
If you identify yourself as a woman: Did you know that research shows women often apply only when meeting 100% of requirements?
Remember, this is just a guide, not a checklist. We'll be thrilled to receive your application!
🔖 Check out our About Alan and Career pages, as well as our Medium, blog and Glassdoor page for more info.
🙌 Perks & Benefits: Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend
only high-quality time with co-workers.
🤘A strong culture: People joining Alan are often surprised and delighted by our innovative working method. We have a set of
cultural values that guide our approach to work
HEALTH CAN’T WAIT. Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t. Alan exists to end the wait. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way. So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. We are on an incredible journey to build a global leading company, with a unique culture. We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR. Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond. ⭐ THE ENGINEERING TEAM ⭐ In our engineering team, we build the infrastructure, interfaces, and applications to provide first-class service to our members, health professionals, and even ourselves! Being an engineer at Alan means joining a team of talented, committed and passionate engineers, with a lot of product interaction. We move fast, with a lot of ownership, and are proud to tackle big problems! We do security as we do everything else — that is, not quite the traditional way, but always in line with our leadership principles. Want to know more? Read this article on our Engineering career path. 🛠️ THE STACK Python/Flask, Typescript, React, React Native, on the coding side. AWS, GCP, Kubernetes, Keycloak, PostgreSQL, Redis, Terraform/Terramate, Datadog, Cloudflare, GitHub Actions on the platform side, all in a monorepo. We deploy daily and believe in distributed ownership - you build it, you own it. 🤖 THE APPLICATION SECURITY CREW - WITHIN TECH FOUNDATIONS AREA 🎯 MISSION * Tech Foundations - enables product crews and creates the environment to thrive—combining world-class infrastructure, intuitive developer experience, exquisite operational excellence, and built-in security to make shipping exceptional products effortless. * Application Security - is one of its crews. Its mission: build, evolve and operate the foundational security building blocks and secure-by-default patterns that make Alan’s products safe by design, highly available, and easy to ship, while partnering with product teams and Security Operations to reduce real risk without turning security into a bottleneck. 🔭 SCOPE 1. Security core components in the product 1. Authentication - design, build and operate the authentication stack on top of our self-hosted identity provider. Our goal is to go passwordless with great UX and unblock strategic initiatives relying on this stack. 2. Encryption - build, evolve and operate our end-to-end encryption component used by our Alan Clinic while keeping it delightful and frictionless for our members. 2. Security platforms 1. Secure file exchange - evolve and operate our secure file exchange platform to unblock product/ops teams while bringing support when relevant. 2. Secure enclave for medical secrecy - contribute to the foundations to isolate and protect highly sensitive medical data without sacrificing usability or delivery speed. 3. Contribute to engineering-wide security practices by building tools and patterns that help every engineer ship safely (secure CI/CD, vulnerability remediation tooling, AI/LLM safety, etc.). 👀 FOCUS FOR 2026: In 2026, we will grow the team significantly to further increase our impact. We want to complete the modernization of our authentication flows and make it operable at high availability, unlock strategic initiatives by shipping new authentication/encryption flows. We are also evolving our AI-augmented development, by putting AI code assistants as a first-class citizen for everyone, including non-engineers. Ultimately we have massive ambitions around our Security stack and posture with enhanced tools and processes to protect our developers and users. EXPERIENCE WE VALUE * 3+ years in full-stack software engineering roles * Experience designing systems, APIs, libraries, or frameworks used by other engineers * You've shipped, owned, and operated production systems (rollouts, on-call, incidents) * You've shipped secure features, fixed vulnerabilities, designed auth/crypto flows, or championed secure-by-default patterns in past teams * You love turning complex problems into elegant secure solutions * You care about creating secure-by-design products while keeping delightful experiences MINDSET WE VALUE * You treat security engineering as product work: engineers & members are your customers, and security should feel effortless. * You’re hands-on: writing code is the bulk of the job (Python, TypeScript, Terraform). You ship what you write to production yourself, then operate it: rollouts, alerting, on-call, incident response. * You design and communicate: you're as comfortable writing a framing, drawing a sequence diagram, and aligning 3 product crews on an auth migration as you are writing the code. You make complex security tradeoffs legible to non-security engineers. * You're an enabler: you measure your impact by how fast product crews ship secure features without ever consulting you. The harder you've worked, the less they have to engage you. * You build reusable patterns: guardrails, libraries, and secure-by-default abstractions that prevent vulnerabilities at scale. * You’re fluent in English (French is not required). For this opportunity, we are aiming to hire within the above C1 level range. But above all, we are looking for high potential and curiosity: make sure to show us this when you apply! Everything else is a bonus. 🌍 HOW WE WORK * Location: You must be legally eligible to work in France, Belgium, or Spain. * Remote work: We offer remote work flexibility, but we value in-person collaboration 🎯 IMPORTANT NOTE: WE HIRE PEOPLE, NOT ROLES. If you're excited about this opportunity but don't check every box, we'd love to hear from you. Everyone, no matter how underrepresented, should feel free to apply, as it can only bring learnings or success. If you identify yourself as a woman: Did you know that research shows women often apply only when meeting 100% of requirements? Remember, this is just a guide, not a checklist. We'll be thrilled to receive your application! 🔖 Check out our About Alan and Career pages, as well as our Medium, blog and Glassdoor page for more info. YOU WANT TO KNOW MORE ABOUT ALAN? * 🙌 Perks & Benefits: Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend only high-quality time with co-workers. * 🤘 A strong culture: People joining Alan are often surprised and delighted by our innovative working method. We have a set of cultural values that guide our approach to work 🔄 A quick note about the process Note: While you're applying for a specific area, you may join a different engineering team based on where we think you'll have the most impact. Check out descriptions of other areas here.
HEALTH CAN’T WAIT. Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t. Alan exists to end the wait. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way. So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. We are on an incredible journey to build a global leading company, with a unique culture. We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR. Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond. ⭐ THE ENGINEERING TEAM ⭐ In our engineering team, we build the infrastructure, interfaces, and applications to provide first-class service to our members, health professionals, and even ourselves! Being an engineer at Alan means joining a team of talented, committed and passionate engineers, with a lot of interactions. We move fast, with a lot of ownership, and are proud to tackle big problems! Our process is very simple: those who make product decisions are the same ones who build them. Want to know more? Read this article on our Engineering career path. 🛠️ THE STACK Python/Flask, Typescript, React, React Native on the coding side. AWS, GCP, Kubernetes, PostgreSQL, Redis, Terraform/Terramate, Datadog, Cloudflare, GitHub Actions on the platform side, all in a monorepo. We deploy daily and believe in distributed ownership - you build it, you own it. 🤖 THE INFRA CREW - WITHIN THE TECH FOUNDATIONS AREA 🎯 Mission: * Tech Foundations - enables product crews and creates the environment to thrive, combining world-class infrastructure, intuitive developer experience, exquisite operational excellence, and built-in security to make shipping exceptional products effortless. * Infra - is one of its crews. Its mission: operate and evolve the foundations Alan runs on (multi-cloud infrastructure, data platforms, observability, and the operational practices around them) so that product crews ship safely and quickly, members never feel the platform underneath, and the business can expand to new countries without re-inventing how we run. 🔭 Scope: 1. Cloud foundations & multi-cloud architecture: own and evolve Alan’s cloud footprint, Infrastructure-as-Code stack (Terraform, Terramate), and the architectural decisions enabling international expansion. 2. Data & application platforms: operate and evolve the foundations product crews build on: PostgreSQL/Aurora, our events pipeline, async workloads, and database migration tooling, without leaking complexity into product code. 3. Reliability, observability & on-call: own Alan's platform uptime and latency SLOs end-to-end. Evolve our observability stack (Datadog), the incident response process (Incident.io), and the shared on-call rotation across the area to keep it sustainable as we scale. 4. Governance & compliance enablement and FinOps: own the cross-cutting concerns no single domain holds, infrastructure cost (FinOps), IAM posture, backup and disaster recovery, exit strategy, with automation and reporting that scales beyond the crew. 5. AI-augmented infrastructure operations: make AI assistants a first-class citizen for incident investigation, runbook execution, and toil reduction, so engineers spend their time on high-leverage work. 👀 Focus for 2026: In 2026, we're growing the team significantly to step up impact across four bets: * Multi-cloud expansion: revisit our cloud strategy as we go international, and launch new geographies. * Decoupling for scale: evolve service architecture to carry Alan 2.0 from 1M members today to 10M. * Operational excellence: raise the quality bar end-to-end by overhauling observability, on-call, and cost management practices. * AI-augmented infra ops: make AI assistants a first-class part of investigation, troubleshooting, and toil reduction, so engineers spend time where leverage is highest. ⭐ IS IT YOU WE’RE LOOKING FOR? EXPERIENCE WE VALUE * 3+ years in Platform engineering, DevOps, Site reliability engineering or equivalent roles. * You have strong experience with cloud platforms (especially AWS or GCP). * You're comfortable writing code for automation and tooling (e.g. API, internal command line, developer portal) and willing to work in Python/Typescript (but you don’t need to have experience with those 2 languages!). * You have touched observability, monitoring, alerting or incident management tools and practices. * You are able to design and implement robust infrastructure systems with a focus on reliability and observability. * You can maintain our uptime targets while optimizing infrastructure costs. * You’ve built and maintained internal or external tooling (e.g. API, web interface, internal command line, configuration as code, etc) for other engineers. MINDSET WE VALUE * You treat infrastructure and platform engineering as product work: engineers & members are your customers, and infrastructure should feel effortless. * You’re hands-on: writing code is the bulk of the job (Python, TypeScript, Terraform). You ship what you write to production yourself, then operate it: rollouts, alerting, on-call, incident response. * You're an enabler: you measure your impact by how fast product crews ship features without ever consulting you. The harder you've worked, the less they have to engage you. * You build reusable patterns: guardrails, libraries, and reliable-by-default abstractions that prevent outages and runaway cost at scale. * You’re fluent in English (French is not required). For this opportunity, we are aiming to hire above C1 level range. But above all, we are looking for high potential and curiosity: make sure to show us this when you apply! Everything else is a bonus. 🌍 HOW WE WORK * Location: You must be legally eligible to work in France, Belgium, or Spain. * Remote work: We offer remote work flexibility, but we value in-person collaboration 🎯 IMPORTANT NOTE: WE HIRE PEOPLE, NOT ROLES. If you're excited about this opportunity but don't check every box, we'd love to hear from you. Everyone, no matter how underrepresented, should feel free to apply, as it can only bring learnings or success. If you identify yourself as a woman: Did you know that research shows women often apply only when meeting 100% of requirements? Remember, this is just a guide, not a checklist. We'll be thrilled to receive your application! 🔖 Check out our About Alan and Career pages, as well as our Medium, blog and Glassdoor page for more info. YOU WANT TO KNOW MORE ABOUT ALAN? * 🙌 Perks & Benefits: Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend only high-quality time with co-workers. * 🤘 A strong culture: People joining Alan are often surprised and delighted by our innovative working method. We have a set of cultural values that guide our approach to work
HEALTH CAN’T WAIT. Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t. Alan exists to end the wait. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way. So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. We are on an incredible journey to build a global leading company, with a unique culture. We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR. Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond. ⭐ THE ENGINEERING TEAM ⭐ In our engineering team, we build the infrastructure, interfaces, and applications to provide first-class service to our members, health professionals, and even ourselves! Being an engineer at Alan means joining a team of talented, committed and passionate engineers, with a lot of product interaction. We move fast, with a lot of ownership, and are proud to tackle big problems! Our process is very simple: those who make product decisions are the same ones who build them. Want to know more? Read this article if you want to discover how life as an Engineer at Alan and this article on our Engineering career path. 🛠️ THE STACK Python/Flask, React, React Native, PostgreSQL in a monorepo. We deploy daily and believe in distributed ownership - you build it, you own it. 🤖 THE EVERYONE CAN BUILD CREW — WITHIN TECH FOUNDATIONS AREA 🎯 Mission: * Tech Foundations enables product crews and creates the environment to thrive—combining world-class infrastructure, intuitive developer experience, exquisite operational excellence, and built-in security to make shipping exceptional products effortless. * Everyone Can Build is one of its crews. Its mission: propel Alan into the AI-native engineering era, by building the tools, agents, and infrastructure that let both engineers and non-engineers contribute confidently and sustainably at scale. 🔭 Scope: 1. Hopper — Alan's own background coding agent: agent orchestration, parallel agent pools, web dashboard for builders 2. AI-native engineering enablement — Harness integration, agentic workflows, ... 3. Autonomous testing infrastructure — agents that validate their own work before shipping 4. Sandboxed development environments — removing brittle local setups so everyone can contribute safely 5. CI/CD and quality guardrails — auto-fix, complexity scoring, automated checks and new PR review experiences that enable confident reviewing 6. Non-engineer contribution tooling — flows and interfaces that make Designers, PMs and Ops autonomous contributors 👀 Focus for 2026: In 2026, we're moving from "AI tools you monitor" to "AI agents you trust." That means scaling Hopper — Alan's own background coding agent — alongside the infrastructure that makes it reliable: managed agent pools, sandboxed environments, autonomous testing, and CI auto-fix. Engineers will routinely offload tasks to agents. Non-engineers will open pull requests after having easily tested their changes. Agents will validate their own work before it ships. ⭐ IS IT YOU WE’RE LOOKING FOR? EXPERIENCE WE VALUE * 3+ years in full-stack software engineering roles * Experience building internal platforms, frameworks, CLIs, or libraries that improve developer workflows * Experience with LLM APIs, agent orchestration frameworks, or AI-assisted coding tools is a strong plus * You care about creating delightful experiences, whether building UIs or APIs MINDSET WE VALUE * You think in terms of platform experience: engineers are your primary customers, and you care about making AI-native workflows reliable for everyone * You are collaborative, humble, and motivated by enabling others * You simplify complexity with elegant abstractions and maintainable code * You're excited about AI changing who gets to build — and want to be the one building that infrastructure * You are fluent in English (no French required) * But above all, we are looking for high potential and curiosity: make sure to show us this when you apply! Everything else is a bonus. 🌍 HOW WE WORK * Location: You must be legally eligible to work in France, Belgium, or Spain. * Remote work: We offer remote work flexibility, but we value in-person collaboration 🎯 IMPORTANT NOTE: WE HIRE PEOPLE, NOT ROLES. If you're excited about this opportunity but don't check every box, we'd love to hear from you. Everyone, no matter how underrepresented, should feel free to apply, as it can only bring learnings or success. If you identify yourself as a woman: Did you know that research shows women often apply only when meeting 100% of requirements? Remember, this is just a guide, not a checklist. We'll be thrilled to receive your application! 🔖 Check out our About Alan and Career pages, as well as our Medium, blog and Glassdoor page for more info. YOU WANT TO KNOW MORE ABOUT ALAN? * 🙌 Perks & Benefits: Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend only high-quality time with co-workers. * 🤘 A strong culture: People joining Alan are often surprised and delighted by our innovative working method. We have a set of cultural values that guide our approach to work 🔄 A quick note about the process Note: While you're applying for a specific area, you may join a different engineering team based on where we think you'll have the most impact. Check out descriptions of other areas here.