Location: Lyon, France (Hybrid – EMEA scope)
We are recruiting a Security & Compliance Engineer to join a growing SaaS organisation operating across EMEA. This role plays a key part in securing cloud-based environments, ensuring GDPR compliance, and embedding security best practices across the business.
You will work closely with technical and non-technical teams including Engineering, DevOps, Sales, IT, HR, and Customer teams, while reporting directly to a US-based CTO. This is a highly collaborative role where communication, influence, and cultural alignment are just as important as technical security skills.
Design, implement, and maintain cloud security controls across SaaS environments
Conduct security assessments, audits, and risk reviews on systems and applications
Maintain and improve security policies and procedures, with a strong focus on GDPR and data protection
Support security incident management, including investigation of potential data breaches
Contribute to customer and sales security questionnaires (RFPs, RFIs, RFQs)
Partner with engineering and DevOps teams to embed security into development pipelines
Promote security awareness and training, helping teams adopt security-first behaviours
Act as a trusted security partner across the organisation, enabling rather than blocking delivery
3-5 years’ experience in information security (internships or alternance included)
Strong, practical understanding of GDPR and data protection regulations
Hands-on exposure to cloud security (AWS, Azure, and/or GCP)
Experience performing security or risk assessments
Familiarity with security frameworks such as ISO 27001, SOC 2, or NIST
Fluent in French and English (written and spoken)
Strong communication skills with the ability to explain security concepts to non-technical audiences
A collaborative, people-oriented security professional
Someone comfortable influencing stakeholders at all levels
A pragmatic approach to security, balancing risk with business needs
High autonomy, accountability, and a strong sense of ownership
A mindset focused on alignment, trust-building, and long-term improvement
37.5-hour working week (standard hours: 9:00-18:00)
25 days annual leave + 15 public holidays (RTT/BH)
Hybrid working with regular on-site collaboration encouraged
Performance-based bonus
Flexible working culture
Supportive, international environment with strong EMEA-US collaboration
This role offers the opportunity to:
Have real visibility and influence across the business
Shape and mature security practices in a growing SaaS environment
Work closely with both technical and business teams
Build meaningful local relationships while operating in an international context
