Senior security engineer
- Hiring from
- France
- Work type
- Hybrid
- Posted
Is this job info correct?
Show job descriptionHide job description
๐ You don't have to match 100% of the requirements. If you believe you're a strong fit, we'd love to hear from you.
๐We just raised $35M in Series A, if you join Tsuga you will experience a strong growth.
About the role & the team
At Tsuga, security has always been everyoneโs responsibility. We want to keep it that way โ but weโve reached the point where we need someone whose full-time focus is raising the bar, setting the direction, and making it easy for every engineer to build securely.
As our first dedicated Security Engineer, youโll shape how security works at Tsuga from the ground up. Youโll have the opportunity to influence our product, infrastructure, engineering practices, and customer-facing security, with direct support from the CTO.
Where we're at today
Youโre not starting from scratch. We already have:
- mTLS between our control plane and customer clusters, tunneled connections, and strong admin authentication
- Aikido for code and dependency scanning, and Drata for compliance automation
- ISO 27001 and SOC 2 certification
What you'll do
- Own our security posture across the product โ including the control plane, customer data planes, and internal tooling. Define security practices, review designs, and help engineers ship securely.
- Partner with our Forward Deployed Engineers to ensure customers receive clear, consistent, and timely communication around security incidents and vulnerabilities.
- Drive compliance and certifications alongside the CTO. Improve and automate the evidence collection and processes behind ISO 27001 and SOC 2.
- Threat-model critical systems that interact with customer environments, including credentials, tunnels, deployment paths, and IAM.
- Own the customer security process, from questionnaires and pentests to security reviews, and turn it into a scalable, repeatable workflow.
- Build security into the development lifecycle through CI checks, dependency management, secrets management, and infrastructure-as-code reviews.
About you & what we are looking for
- Hands-on experience securing cloud infrastructure and Kubernetes, ideally across multiple cloud providers.
- Youโre comfortable reading and writing code. Our stack includes TypeScript, Rust, Python, and Pulumi โ you donโt need to know all of them, but you should be comfortable reviewing and contributing to code.
- Experience with at least one SOC 2 or ISO 27001 certification cycle, and a good sense of what effective security and compliance tooling looks like.
- A pragmatic approach to risk. You enable engineers rather than gatekeep them.
- Strong communication skills โ you can work effectively with engineers, customers, auditors, and leadership.
Working at Tsuga
- ๐ฅ We move fast. As an early-stage startup, we are pragmatic, we value ownership, and quick feedback over unnecessary process and hierarchy.
- ๐ We solve problems, not blame people. When something goes wrong, we fix it, learn from it, and improve the system.
- ๐ ๏ธ We are builders. We start everything from a blank page and we lean on your colleagues' knowledge to move faster.
- ๐ We are customer-obsessed. We dogfood Tsuga every day, so you care how the product is actually used and want to contribute ideas.
- ๐ฅ We lean hard on AI, but not blindly. Our problems are hard and canโt be AI-slopped away.
- ๐ We're international from day one. Every quarter, the whole team meets at our French office to align on company goals, celebrate wins, and connect with teammates from the US, UK, the Middle East, and across Europe.