Security Engineer Intern

À propos

Pourquoi rejoindre l'aventure Swile ?

Depuis son lancement en 2018, Swile a révolutionné le marché des avantages salariés, et des frais et déplacements professionnels.
En digitalisant la gestion et l’utilisation des avantages, grâce à notre super app, nous avons amélioré l’expérience, afin de la rendre plus simple, plus moderne et plus intuitive.

Swile, c’est aussi une ambition forte : devenir le leader de la worktech, en cherchant à adresser, à terme, via nos produits, toute la sphère de la gestion de la vie au travail.

Nous misons sur l’innovation technologique, un design soigné et une approche RSE structurante, pour contribuer à améliorer le quotidien des travailleurs et des décideurs, tout en dynamisant l'engagement.

Avec plus de 1000 collaborateurs, en France et au Brésil, Swile a déjà convaincu des millions d’utilisateurs et des milliers d’entreprises.

Et l’aventure ne fait que commencer. Rejoignez-nous pour bâtir ensemble un monde du travail plus épanouissant.

Descriptif du poste

Our Security team protects Swile's products, data and engineering platform. We work with a simple principle: when something is recurring, we automate it, and when a security requirement can become code, we write the code.

As a Security Engineer Intern, you will not shadow the team, you will be part of it. You will handle real alerts, run your own audits and own projects end to end, with a dedicated mentor in the team throughout your internship.

What you will do

Detection and response

  • Handle day to day security alerts: triage, investigate, qualify, escalate when needed.

  • Improve what we detect: reduce noise, close detection gaps, propose new signals.

  • Automate the recurring: when an alert or a manual check keeps coming back, script it away. This is where we expect you to leave a mark.

Security audits

  • Run targeted audits, from a few days to a few weeks, on applications, configurations or third party providers.

  • Turn findings into a prioritised remediation plan rather than a list of tickets.

Projects you will own

  • Ad hoc security projects across the engineering platform.

  • Security review and hardening of the tools and integrations we rely on (Dust, third party providers, internal integrations).

Fraud

  • Support fraud investigations: dig, follow the trail, understand how an abuse pattern works and how we could detect it earlier.

Profil recherché

This is an internship, so how you think matters more than what you already know.

  • You learn fast and you are genuinely curious about security.

  • You are a doer: you answer quickly, you close loops, you do not let things sit.

  • You are pragmatic: you calibrate your response to the actual level of urgency and risk, and you know that not everything is a P1.

  • You are open minded and comfortable asking questions across engineering teams.

  • You are comfortable working in English, written and spoken.

  • You have some scripting ability (Python or equivalent) and a basic understanding of web applications, APIs and cloud environments.

    Nice to have that would make you stand out

    • Personal projects, CTFs, homelab, bug bounty or security writeups.
    • First exposure to a SIEM, to detection rules or to log analysis at scale.
    • Curiosity for fraud and abuse patterns in a financial product.

    What this internship is not

    • Not a pure GRC, compliance or policy writing internship.
    • Not a pentest internship.
    • Not a role where you watch dashboards without changing them.

Informations complémentaires

  • Type de contrat : Stage (3 à 6 mois)
  • Lieu : Paris
  • Niveau d'études : Bac +5 / Master
  • Télétravail ponctuel autorisé