--- title: 'Staff Security Engineer at Swile' canonical: 'https://feeny.ai/job/staff-security-engineer-swile-toulouse-ef2ymn8nkm6e' type: 'job' last_seen: '2026-09-09' --- # Staff Security Engineer at Swile - **Company:** Swile - **Location:** Toulouse, France - **Work type:** hybrid - **Posted:** 2026-09-01 - **Last confirmed live:** 2026-09-09 - **Apply:** https://jobs.lever.co/swile/fde8c243-be1a-44b8-a063-15c710c79047 ## Job description Build security platforms, not security processes We are looking for a Staff Security Engineer to strengthen the security of our products, data and engineering platform. This is a highly technical and hands-on role. You will work closely with Engineering teams to continuously harden our systems while helping design the next generation of our security architecture. You will operate across two horizons: Strengthen security today: continuously harden our applications, access controls and data-protection mechanisms against evolving threats. Build the privacy architecture of tomorrow: move beyond traditional perimeter and access-control security by designing systems where sensitive data is cryptographically isolated, minimally exposed, and increasingly usable without being directly revealed. The ultimate objective is not simply to make Swile harder to breach. It is to make a breach increasingly uninteresting, because there is less usable data available to steal. ## What you will do We want Security Engineering to create capabilities that scale across hundreds of engineers. You will: - Identify and reduce high-impact security risks across our applications, APIs and internal tools. - Strengthen authentication, authorization and access controls. - Improve the protection of sensitive and personal data. - Design controls that limit the blast radius of compromised accounts, services or infrastructure. - Improve security monitoring, auditability and detection of suspicious access patterns. - Perform threat modelling and targeted security reviews. - Build reusable security capabilities directly into our engineering platform and development lifecycle. - Contribute to long-term architectures around data isolation, encryption, tokenisation and privacy-preserving systems. - Partner with engineering teams to address systemic security risks rather than individual findings. Where possible, a security requirement should become code rather than documentation. ## What we are looking for You are first and foremost a strong engineer. You have significant experience building or securing production software and distributed systems. You are comfortable reading and writing production code, designing systems and working directly with Engineering teams. You have deep security engineering expertise and strong experience in several of the following areas: - Application and Product Security - API Security - IAM, authentication and authorization - OAuth2 / OIDC, WebAuthn / FIDO2 - RBAC / ABAC and privilege management - Cloud security - Cryptography, KMS / HSM and envelope encryption - Tokenisation and secrets management - Data Security and Privacy Engineering - Threat modelling and secure software architecture - Security monitoring and detection Stronger attacker mindset You naturally ask: - What happens if this employee becomes malicious? - What happens if this backend is compromised? - What happens if someone dumps this database? - Can this endpoint be called directly? - How much data can one account access before we notice? - Where else does this information get replicated? - Why do we have this data at all? You think in terms of attack paths, blast radius and least privilege, not just compliance requirements. Pragmatism You know that security engineering is a prioritisation problem. You can distinguish between: - something that needs to be fixed this week; - something that requires an architectural redesign; - something cryptographically elegant but operationally unnecessary. You are comfortable deploying simple, high-impact controls quickly while designing stronger long-term foundations. What would make you stand out Experience with: - large-scale SaaS or fintech platforms; - highly sensitive or regulated data; - multi-tenant architectures; - insider risk or data-loss prevention; - advanced cryptographic or privacy-enhancing technologies. What success looks like - Sensitive data is exposed to fewer systems and people. - Access to sensitive resources is increasingly scoped, attributable and auditable. - Compromising a single account or service has a limited blast radius. - Security controls are increasingly enforced by the platform rather than by process. - Product teams can build secure systems faster and with less friction. What this role is not This is not primarily a GRC, SOC, compliance, policy-writing or penetration-testing role. Those disciplines are important, but this role exists to change how our products and systems are engineered. We expect this person to design systems, write code, influence architecture and ship security capabilities into production. Localization of this position This position can be based at our offices in Paris, Toulouse, or Montpellier on a flex-remote basis. ## About Swile ## Company Overview - **One-liner**: Swile is a French worktech company that provides an all-in-one employee benefits platform through a smart card and mobile app designed to simplify and digitize salary-linked benefits like meal vouchers, gift cards, mobility, and culture checks. - **Entity Type**: Private (Unicorn, achieved profitability) - **Headquarters**: Montpellier, France - **Founded**: 2018 - **Founders**: Loïc Soubeyrand ## Core Business - **Primary industry/industries**: Worktech (Employee Benefits, Fintech, HR Tech) - **Target customers**: B2B, serving companies of all sizes (from SMBs to large enterprises) in France and Brazil, including clients like Carrefour, Le Monde, JCDecaux, PSG, Airbnb, Spotify, and TikTok. - **Mission or purpose statement**: To reinforce employee engagement and spread smiles at work by offering a unified, personalized, and modern experience that meets everyone's needs. ## Products & Services - **[Swile Card]**: A physical and digital smart card that consolidates all employee salary benefits (meal vouchers, gift cards, mobility allowances, culture checks) into a single payment method. Backed by proprietary "Smartcard" technology. - **[Swile App]**: A mobile application that allows employees to manage their benefits, view transactions, and personalize their experience. High user ratings (4.7/5 on Google Play, 4.7/5 on Trustpilot, NPS of +65). ## Market Standing - **Valuation/Market Cap**: Achieved unicorn status (valuation over €1 billion). Recent valuation not publicly disclosed as a private company. - **Key Metric**: Achieved centaur status (over €100 million in annual recurring revenue) following the acquisition of Bimpli in December 2022. The company is now profitable. - **Notable Investors/Partners**: Raised multiple funding rounds from leading investors (specific names not detailed in the provided sources, but described as "first-rank investors"). - **Growth Signals**: - 1 out of every 3 meal voucher card transactions in France is made with a Swile card. - Successful acquisition and integration of Bimpli, pushing ARR over €100M and enabling profitability. - Expansion into the Brazilian market. ## Competitive Advantages - **Proprietary Smartcard Technology**: An exclusive innovation that powers the unified benefits experience. - **Unified Platform**: Swile aggregates all common employee benefits (meal, gift, mobility, culture) into one card and app, simplifying administration for companies and usage for employees. - **Strong Brand and Trust**: Very high user ratings across app stores and review platforms, indicating high employee satisfaction. - **Market Leadership in France**: Dominant position in the French meal voucher market with significant market share. ## Strategic Focus - **International Expansion**: Operating in both France and Brazil, with ambitions to grow further. - **Product Ecosystem Expansion**: Continuing to enhance the unified platform with new features and benefits categories. - **Profitability and Sustainable Growth**: Having reached profitability, the focus is on maintaining healthy financials while scaling. - **Responsible Business (RSE)**: Pursuing B Corp certification, committed to the Science-Based Target Initiative (SBTi), and holding an Ecovadis Silver Medal. Their strategy "Sustainable Swile 2025" drives environmental and social impact. ## Why Work Here - **Culture**: Described as both "profoundly benevolent and extremely demanding," valuing autonomy and initiative-taking. Core values include "We are team players," "We are doers," "We move fast," "We are ambassadors," and "We stay hungry." - **Remote/Hybrid Policy**: The company has both on-site roles (e.g., São Paulo) and roles with remote potential. Specific policy details would depend on the role and team. - **Notable Perks**: An employee benefits package that starts with their own product—the Swile Card and App. The company strongly emphasizes professional equality (gender equality index score of 90/100), diversity, equity, and inclusion. - **Engineering Culture**: A focus on "moving fast," testing, learning from failure, and high ambition without boundaries. The recruitment process for technical roles includes a practical test and multiple team interviews. ## Sources 1. [Swile Careers Page](https://jobs.lever.co/swile/) 2. [Swile Corporate - About Us](https://www.swile.co/a-propos-de-swile) 3. [Swile Product Page](https://www.swile.co/) 4. [Welcome to the Jungle - Swile Jobs](https://www.welcometothejungle.com/en/companies/swile/jobs) ## Other roles at Swile - [Sales Executive Middle Market](https://feeny.ai/job/sales-executive-middle-market-swile-sao-paulo-1hrh554ppkks) — São Paulo, Brazil - [CX Performance Specialist](https://feeny.ai/job/cx-performance-specialist-swile-montpellier-91p5x9mcznxy) — Montpellier, France - [Sales Executive Middle Market | Belém/PA ou Manaus/AM](https://feeny.ai/job/sales-executive-middle-market-belem-pa-ou-manaus-am-swile-brasil-hr240kj4pyz4) — Brasil - [Staff Security Engineer](https://feeny.ai/job/staff-security-engineer-swile-montpellier-tctnft0pccma) — Montpellier, France - [Sales Executive Middle Market](https://feeny.ai/job/sales-executive-middle-market-swile-rio-de-janeiro-kagyh2dday3t) — Rio de Janeiro, Brasil - [Staff Security Engineer](https://feeny.ai/job/staff-security-engineer-swile-paris-x0ftsvzznpd5) — Paris, France - [Compliance Specialist](https://feeny.ai/job/compliance-specialist-swile-sao-paulo-mj780xra470p) — São Paulo, Brazil - [Customer Care Specialist B2C](https://feeny.ai/job/customer-care-specialist-b2c-swile-montpellier-cj4ff9nebpys) — Montpellier, France - [Engineering Manager - Payments](https://feeny.ai/job/engineering-manager-payments-swile-brasil-vsy9jqcenk5k) — Brasil - [Senior Software Engineer, Backend (Payments)](https://feeny.ai/job/senior-software-engineer-backend-payments-swile-brasil-szp69td1nd84) — Brasil