Information Security Apprentice
DidomiDidomi helps organizations collect, store, and leverage user choices across multiple channels, increasing precision in marketing and advertising operations and building trust through transparent data practices.
Through a comprehensive software platform and premium support services, Didomi enables large corporations to optimize the collection and activation of user choice data, monitor vendor and tracker activity, and reduce compliance risk under global privacy regulations.
Following the 2025 acquisitions of Addingwell and Sourcepoint, Didomi has strengthened its end-to-end capabilities across consent, preferences, and data activation, bringing together server-side tagging and privacy technology to deliver experiences that improve performance, trust, and loyalty.
Active in 35 countries, Didomi supports over 2,000 clients across various sectors, including some of the world's largest corporations, in building revenue-driving operations based on reliable and robust user choice data.
For more information, please visit www.didomi.io
About the apprenticeship
We are looking for an Information Security Analyst apprentice to join our Security & IT team. This is a work-study position (contrat d'apprentissage) for a student in cybersecurity, information systems, or a related field, who wants to learn how security actually works inside a fast-growing B2B SaaS company.
You will not be on the sidelines. Didomi is a small security team with a large scope: three business units (Didomi, Sourcepoint, and Addingwell) now covered by a single ISO 27001 management system, a HIPAA compliance program being implemented, and security operations across cloud, endpoints, identity, and SaaS. You will take real ownership of recurring activities, with guidance, and grow into broader topics as you progress.
The role covers information security in the broad sense: security operations, cloud and identity security, vulnerability management, awareness, and compliance. Compliance is part of the job, not the whole job.
You will report to the Security & IT Manager, who will also be your tutor (maître d'apprentissage) throughout the contract.
What you will learn and do
Security operations
- Take part in the recurring activities on the security calendar: vulnerability scanning campaigns, quarterly access reviews, business continuity tests, and policy review cycles.
- Triage security and vulnerability findings from AWS (GuardDuty, Inspector, Security Hub), CrowdStrike Falcon, and other sources, learn to prioritize them, and follow remediation through to closure with the engineering teams.
- Help monitor and respond to security alerts and incidents, including endpoint detections in CrowdStrike Falcon, and contribute to incident documentation and post-incident reviews.
- Support endpoint security through our device management platform (JAMF) and our EDR (CrowdStrike Falcon), and help keep device baselines healthy.
Cloud, identity, and access
- Learn how identity and access management works at Didomi (Google Workspace, SSO, MFA) and help keep it tight.
- Run periodic access reviews across critical systems (Google Workspace, AWS, Slack, JAMF, GitLab, GitHub, and internal applications) and surface findings to the team.
- Help harden internal workflows around access, data handling, and SaaS usage.
ISO 27001, HIPAA, and audit readiness
- Help maintain our ISO 27001 management system: keep controls documented and evidenced, and follow up on corrective actions and improvement initiatives.
- Contribute to internal audits, surveillance audits, and recertification cycles, including the unified audit covering all three business units.
- Support the implementation of HIPAA controls and learn how requirements map across frameworks.
Cross-functional security support
- Contribute to security reviews of new tools, vendors, and SaaS applications before adoption.
- Help answer security questionnaires, RFPs, and customer due diligence requests.
- Contribute to security awareness across the company (training content, phishing simulations, internal communication).
- Get exposure to broader initiatives such as AI governance, SaaS governance, and integration of acquired entities into the ISO scope.
What we are looking for
Required
- Enrolled in a degree program (Bac+3 to Bac+5, e.g. Licence pro, Master, or engineering school) in cybersecurity, information systems, computer science, or a related field, and eligible for an apprenticeship contract in France.
- Foundational understanding of information security concepts: networks, operating systems, identity and access, common threats and vulnerabilities.
- Curiosity and a hands-on mindset: you like to understand how things work, and you are comfortable learning new tools quickly.
- Interest in automation and AI tooling to speed up recurring work. You do not need to have built anything yet, but you should want to.
- Rigor and reliability: recurring security work depends on things being done on time and documented properly.
- Professional French and strong written and spoken English. You will work with French and international colleagues, and most documentation is in English.
Nice to have
- First exposure to a cloud provider (AWS in particular), Linux, or scripting (Python, Bash).
- Awareness of ISO 27001, GDPR, or other security and privacy frameworks.
- A personal project, CTF participation, home lab, or certification (e.g. CompTIA Security+, ISC2 CC, AWS Cloud Practitioner) that shows your interest in the field.
Tools you will work with
- Compliance and GRC: Vanta
- Cloud and security monitoring: AWS, AWS GuardDuty, AWS Inspector, AWS Security Hub
- Endpoint detection and response: CrowdStrike Falcon
- Identity and access: Google Workspace, SSO and MFA providers
- Endpoint and device management: JAMF
- Code and engineering: GitLab, GitHub
- Collaboration and documentation: Slack, Notion, Google Workspace
- SaaS governance and vendor review: internal review workflows and questionnaire tooling
Why join
- A rare chance to see the full breadth of a security function, from cloud alerts to certification audits, rather than one narrow slice.
- Direct mentoring from the Security & IT Manager and real responsibility from the first months.
- A team that values pragmatic, working controls and actively uses automation and AI to remove manual work.
- An international, privacy-first company at the heart of the consent and data activation space.