--- title: 'GRC Security Engineer at DataDome' canonical: 'https://feeny.ai/job/grc-security-engineer-datadome-france-4qsknsdswbw7' type: 'job' last_seen: '2026-09-09' --- # GRC Security Engineer at DataDome - **Company:** DataDome - **Location:** France - **Work type:** remote - **Posted:** 2026-06-29 - **Last confirmed live:** 2026-09-09 - **Apply:** https://job-boards.greenhouse.io/ddome/jobs/8602893002 ## Job description ⭐ About the role : At DataDome, security is a core part of the product and of how we operate as a company. We protect large enterprises against bots, fraud, and account abuse, which means strong security and compliance foundations are critical to the trust our customers place in us. As the company grows, so does the level of rigor expected around certifications, risk management, internal controls, third-party security, and audit readiness. We’re looking for a Senior GRC Security Engineer to help us scale that work in a way that is practical, effective, and grounded in how teams actually operate. This is a hands-on individual contributor role reporting to the Head of Security. The impact of the role comes from follow-through, sound judgment, and the ability to turn compliance requirements into security practices that hold up in the real world. You also will build and own a robust tooling and workflow engine to power and automate GRC activities at scale. 👉 You will be more specifically in charge of things like... Compliance programs - Play a leading role in DataDome’s ISO 27001 program, driving day-to-day execution across control maturity, evidence collection, internal audits, and audit preparation. - Help maintain DataDome’s SOC 2 Type II program over time, ensuring controls, evidence, and follow-up actions stay on track. - Keep compliance work practical, reliable, and scalable as the company grows. Risk management - Run the risk management process in practice, including risk assessments, workshops, the risk register, treatment plans, and follow-up. - Work with both technical and business stakeholders to identify and assess risks in a structured and useful way. - Help teams turn risk findings into clear, prioritized remediation actions. Third-party risk and internal controls - Handle third-party security reviews for internal tools and vendors, including onboarding assessments, reassessments, and follow-up actions. - Check that key controls are actually in place across tools and processes, spot gaps or weak configurations, and make sure remediation is tracked and moving with the right teams. Awareness and business partnership - Lead the security awareness program, including training, phishing simulations, and effectiveness tracking. - Act as a key security partner for Legal, HR, Finance, and Business Operations on topics such as people controls, data handling, and process design. - Help Sales on security topics when needed, including writing clear, accurate, and high-quality answers to security questionnaires and supporting follow-up discussions during the sales cycle. - Be comfortable representing security during audits, including explaining how controls work, answering auditor questions, and following up on findings. 👤 It would be great if... - You have at least 7+ years Experience in a cybersecurity product company or internet-scale SaaS environment. - You have demonstrated hands-on experience with ISO 27001 and understand what it takes to drive and maintain a certification program in the long run. - You are comfortable going directly to teams, understanding how things work in practice, spotting gaps, and pushing for improvements that actually fit the way people work. - You care about whether controls are real and effective, not just documented. - You are comfortable running structured risk assessments and facilitating discussions with both technical and non-technical stakeholders. - You communicate clearly and confidently, both in writing and in person, and you are comfortable working in French and English. - You have the technical fluency to assess tools, systems, and processes with a critical eye, and to engage credibly with engineering teams on remediation efforts - You look for practical ways to simplify and automate repetitive GRC work, including with AI when it adds real value. Bonus Points - Experience with SOC 2 Type II and third-party risk management in a SaaS environment. - Experience with Vanta or similar GRC automation platforms. - Familiarity with AI governance topics or security implications of AI tooling. What’s in it for you? - Flex Life: While we offer remote, hybrid, & in-office options each position specifies the level of flexibility. Our Parisian office is located next to the Opera Garnier. You will also receive a 500€ stipend to help you set up your ideal workspace if you work hybrid or remotely. - If you are full remote, the SNCF dicount card is paid for you to come to our office to visit us & your team! - Generous Health Benefits: We have partnered with Kenko for your healthcare needs. - A 100€ annual allowance is provided for a leisure activity of your choice in Sports or Culture. - Annual allowance of €200 if you come to the office by bike to cover maintenance costs. - Professional Development: #Weaimhigh is part of our DNA, therefore we have invested in an internal Learning and Development platform and offer the opportunity to request additional training and support via your manager. - Events & Team building: #We care and we have fun! We organise ****Annual Company-Offsite, Events, Drinks, Winter Party, Lunch & Learns and much more are part of our Culture - Parent Care: Gift & care packages for parents. - PTO: Based on the country you are based from (e.g. 25 days in France). What are the next steps? - You x Talent Acquisition Manager : first interview and cultural fit - You x Engineering Manager Damien : technical and cultural fit + Take-home technical challenge - You x Team: Presentation and review of your "technical proposal" with the team - You x Member of the leadership team - Discussion about DataDome vision and "raison d'être"! - Now you really met everyone! Welcome to DataDome :) DataDome stops cyberfraud and bots in real time, outpacing AI-driven fraud from simple to sophisticated across your sites, apps, and APIs. Named a Leader in the Forrester Wave for Bot Management, the DataDome platform is built on a multi-layered AI engine that focuses on intent, not just identity. Because it’s not about knowing who’s real, it’s about what they intend to do. With thousands of AI models that adapt to every fraudulent click, signup, and login, DataDome blocks fraud in less than 2 milliseconds, without compromising performance. DataDome is fully automated and integrates seamlessly into any tech stack. Backed by a 24/7 SOC team of advanced threat researchers, DataDome stops over 350 billion attacks annually. Experience protection that outperforms with DataDome. DataDome is an equal opportunity employer, and proud to be committed to diversity and inclusion. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age. ## About DataDome ## Company Overview - **One-liner**: DataDome provides real-time AI-powered protection against bot-driven fraud, malicious AI agents, and cyberattacks for websites, mobile apps, and APIs. - **Entity Type**: Private (Series C; total disclosed funding of $77M) - **Headquarters**: New York, NY (USA); Paris (France); Singapore (global hubs) - **Founded**: 2015 - **Founders**: Benjamin Fabre, Fabien Grenier, Benjamin Barrier, Olivier Trabucato ## Core Business - **Industry**: Cybersecurity – bot management & agent trust, account protection, L7 DDoS mitigation, ad fraud prevention. - **Target Customers**: B2B – primarily enterprise and mid-market online businesses across e‑commerce, media, travel, fintech, and SaaS. - **Mission**: “Free the web from fraudulent traffic” by blocking every malicious click, signup, and login in under 2 milliseconds. ## Products & Services - **Bot Protect**: Stops AI bots, web scrapers, scalpers, and carding attacks using intent-based detection across websites, mobile apps, and APIs. - **Account Protect**: Prevents account takeover (ATO), credential stuffing, fake account creation, and AI-operated account farming. - **DDoS Protect**: Blocks Layer 7 DDoS attacks (including flash crowds) that bypass standard CDN defenses — in under 2 ms. - **Ad Protect**: Preserves ad spend by eliminating click fraud and ensuring analytics reflect real human traffic. - **Priority Protect**: Manages traffic surges during high-demand events, keeping real customers first while blocking bots and unauthorized AI agents. All products are delivered as a cloud-native SaaS with 80+ integrations and 35+ global Points of Presence (PoPs). ## Market Standing - **Valuation / Market Cap**: Not publicly available (private company). - **Key Metric**: Total disclosed funding of **$77M** (Series B: $35M in 2021; Series C: $42M in 2023 led by InfraVia Growth). Over **300 enterprise customers**, including brands like Tripadvisor, Zocdoc, and SoundCloud. - **Notable Investors / Partners**: InfraVia Growth (lead, Series C). Partners include YesWeHack (ethical hacking platform) and major CDN/cloud providers through integrations. - **Growth Signals**: - Headcount grew from 100+ (2023) to **200 employees** (2025/2026). - Named a **Leader in The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026** – highest scores in 12 criteria. - Recognized as one of **America’s Best Startup Employers by Forbes** (2024, 2025). - Earned **Great Place to Work Certification™** (2024). - Included on the **Inc. 5000** list for three consecutive years. ## Competitive Advantages - **Intent‑focused AI**: Unlike simple identity checks, DataDome’s multi‑layered AI analyzes 5 trillion signals daily to determine the *intent* of every request – achieving 99.99% detection accuracy. - **Speed & scale**: Blocks attacks in under 2 milliseconds; autonomously stops over 400 billion attacks per year. - **24/7 SOC & threat research**: Dedicated security operations center and threat research team that adapts models in real time. - **Platform breadth**: Covers bots, ATO, L7 DDoS, ad fraud, and agent trust – all from a single agent with 80+ integrations. - **Proven customer outcomes**: Customers see a **99% reduction in account takeover fraud** and a **99% reduction in credential stuffing**. ## Strategic Focus - **Agent trust management**: Building guardrails and trust frameworks for AI agents (e.g., agentic commerce), positioning as a leader in the emerging “bot & agent trust” category. - **Global expansion**: Continued scaling of sales and engineering teams in North America, Europe, and Asia (recent New York office opening). - **Threat research leadership**: Publishing threat intelligence and maintaining a public bug bounty program (75+ ethical hackers, zero successful breaches) to stay ahead of evolving AI‑driven attacks. - **Platform integration**: Deepening integrations with major CDNs, cloud providers, and tech stacks to reduce time-to-value for new customers. ## Why Work Here - **Remote‑first culture**: offers both remote and hybrid roles depending on the job; global team with offices in New York, Paris, and Singapore. - **Compensation & benefits**: Competitive salary, comprehensive health plans (medical/dental/vision through Anthem, Guardian, VSP), 401(k) with 4% match (US), paid parental leave (4 weeks after 6 months), and learning & development budget. - **Perks & community**: Monthly team events, bi‑annual all‑company offsites (one in Europe, one holiday party), referral bonuses ($1,500/€1,500), and access to a benefits platform (Leeto in France, CSE for French employees). - **Engineering culture**: 80,000+ attempted breaches of their product each month – engineers work on high‑stakes, real‑time threat detection at massive scale (processing 5 trillion signals/day). - **Recognition**: Certified Great Place to Work (2024) and multiple “Best Employer” awards; fast‑growing company with a clear mission and strong leadership. ## Sources 1. [datadome.co – Company page](https://datadome.co/company/) 2. [datadome.co – Product overview](https://datadome.co/) 3. [Greenhouse – Jobs at DataDome](https://job-boards.greenhouse.io/ddome) 4. [careers.datadome.co – Life at DataDome](https://careers.datadome.co/en/life-at-datadome) 5. [careers.datadome.co – Join the team](https://careers.datadome.co/) ## Other roles at DataDome - [Senior Solutions Engineer- US](https://feeny.ai/job/senior-solutions-engineer-us-datadome-united-states-tqjy3apgvnwg) — United States - [Solutions Engineer EMEA](https://feeny.ai/job/solutions-engineer-emea-datadome-paris-ev0eax2yy8m7) — Paris, France - [AI Engineer](https://feeny.ai/job/ai-engineer-datadome-france-qxjt668zhv80) — France - [Enterprise Account Executive - EMEA](https://feeny.ai/job/enterprise-account-executive-emea-datadome-paris-nebr99p7dd9v) — Paris, France - [Enterprise Account Executive- Bay Area & Northern California](https://feeny.ai/job/enterprise-account-executive-bay-area-northern-california-datadome-united-states-krxjjwv2wx4x) — United States - [Software Engineer (Integrations)](https://feeny.ai/job/software-engineer-integrations-datadome-france-6m76ptgv65cn) — France - [Senior Security Engineer](https://feeny.ai/job/senior-security-engineer-datadome-france-sh84z8s7m3mb) — France - [Threat Research Engineer (Client Side)](https://feeny.ai/job/threat-research-engineer-client-side-datadome-france-w6aq94barpdg) — France - [Cyber Security Analyst](https://feeny.ai/job/cyber-security-analyst-datadome-united-states-fdhqyddkd781) — United States - [Cyber Security Analyst (Wed-Sun)](https://feeny.ai/job/cyber-security-analyst-wed-sun-datadome-costa-rica-gkwz1qscwex4) — Costa Rica