As a Cybersecurity Engineer, you make sure the AI we deploy never compromises the security of the environment it operates in. You secure our AI servers and agents at client sites, carry out risk analyses and support the founders on AI governance engagements, including CISO duties. One example: at Caritas, the AI governance and information security policy put in place for 400 employees made it possible to identify, assess and secure more than 20 AI use cases.
Your role
- Secure our AI servers and agents, in our own environment and at client sites: isolation, access management, logging, guardrails
- Run attack tests on our AI applications before they go into production: prompt injection, data leakage, guardrail bypass
- Carry out risk analyses for AI projects, from mapping use cases to the action plan
- Assess gaps against ISO 27001, ISO 42001, the AI Act, DORA and GDPR, and propose corrective measures
- Draft security policies and procedures, and support the founders in AI committees and outsourced CISO roles
- Contribute to our training on AI-related cyber risks: Fresque 402 Cyber x IA™, live cyber attack simulation
About you
- Engineering degree or master’s in cybersecurity, computer science or networking
- Less than two years’ experience in cybersecurity: internship, apprenticeship or first role
- Good grounding in systems and network security: Linux, hardening, access management, logging
- Working knowledge of Python to automate tests and checks
- Knowledge of risk analysis methods and standards: EBIOS RM, ISO 27005, ISO 27001
- Interest in LLM and agent security: prompt injection, data leakage, OWASP Top 10 for LLM Applications
- Clear writing in French and English: risk analyses, policies, test reports
Nice to have
- A certification: ISO 27001 Lead Implementer or Lead Auditor, OSCP or equivalent
- Penetration testing experience: CTFs, bug bounties, red teaming of LLM applications
- Knowledge of ISO 42001, the AI Act or DORA
- French defence security clearance, or eligibility for it
Why this role
- The whole AI chain to secure: servers, models, data and use
- Engineering and consulting combined, from attack testing to AI committees
- Reference clients: AI governance for Caritas, training for Crédit Agricole’s data architects
- A role to shape with both founders: you set our methods for testing AI applications
Recruitment process
- 01Initial conversation with one of the founders
- 02Case study: analyse the risks of an AI agent deployed for an anonymised client
- 03Final interview with both founders
Apply
Send us your CV and, if you wish, a few lines about your background.
Application sent.
Thank you. We will get back to you by email.