Security & Compliance Engineer
Secure the BuyCo platform powering global shipping: lead hands-on cloud security, strengthen ISO 27001 and SOC 2, and build a security-minded culture across the team.
Security & Compliance Engineer
🌊 BuyCo digitalizes and simplifies container shipping operations with a motto: “Shipping made easy!”
Most of the things around you (your phone, your clothes, your coffee) crossed an ocean in a shipping container.
Behind each of those containers, a company has to book space on a ship, coordinate carriers, freight forwarders and customs agents, and keep track of dozens of documents, often still by email, phone and spreadsheet.
That's where we come in.
Our collaborative SaaS platform gives importers and exporters a single place to:
book, organize and track their shipments from start to finish,
work smoothly with their own teams and all their partners,
get clear visibility on where their goods and documents are,
use their data to make their supply chain more efficient and more sustainable.
Our mission: bring an industry that still relies heavily on manual work into the digital age, with a platform people actually enjoy using.
🐣 BuyCo was founded in 2015 by a team combining deep maritime expertise and a strong tech background. Today, we're around 50 people.
Solidly funded, we have ambitious plans: new features on the platform (like our CO2NTROL project, which helps clients measure and reduce the CO2 emissions of their shipments) and faster growth, with new clients, especially abroad.
⚡️ Want to work with energetic, experienced people who care about results?
Join us and help change the way goods move around the world!
Job description
We are recruiting a Security & Compliance Engineer.
As BuyCo grows, especially abroad, security and compliance have become key expectations from our customers. BuyCo is ISO 27001 certified, SOC 2 certification is around the corner, and new regulations such as the EU AI Act are coming.
To support this ambition, we are looking for someone who combines strong hands-on security expertise, a solid tech culture and a taste for governance and compliance.
The role is a 50/50 split between security and compliance, with a stronger focus on security expertise. On the compliance side, you will be supported by our compliance automation platform, Drata.
You will play a key role in making BuyCo's platform more secure every day and in keeping our certifications and policies alive, while spreading a strong security culture across the company.
You will report directly to Joffrey, Head of Platform, and join a team with:
Saad, Platform Engineer,
Ludwig, Senior Cloud Engineer,
César, Security & Compliance Administrator apprentice.
and work closely with:
our Software Engineers,
the Data team,
but also:
all BuyCo teams, as security and compliance are everyone's business,
our external partners: pentesters, security vendors and service providers, and customers' security teams.
What you will do on a daily basis:
Core tasks:
Platform security
Secure the BuyCo platform by applying and promoting best practices across our infrastructure: AWS, Azure, data tools and Kubernetes.
Act as BuyCo's pentest referent: work with pentesters, understand their findings and recommendations, and drive remediation with the engineering teams.
Prioritize security topics based on risks, so the main risks are always covered.
Spread a strong security culture: explain security choices in simple words and bring teams on board.
Security operations (run & build)
Monitor, maintain and improve BuyCo's security stack: check alerts every day, triage and categorize them, and create tickets for the right teams.
Improve our security tooling over time, and contribute to the choice of new tools and service providers.
Manage access across the company: onboarding, offboarding and access levels.
Compliance & governance
Maintain and improve our ISO 27001 certification and our SOC 2 certification (to obtain or maintain, depending on your start date), with the support of Drata.
Write, update and improve our security policies, rules and processes.
Prepare internal audits (at least once a year, ideally twice).
Handle GDPR topics and their international equivalents (e.g. LATAM, Australia), and prepare BuyCo for the EU AI Act.
Answer our customers' security questionnaires.
Your path at BuyCo:
We imagine (ideally) a journey like this one:
4 months after your arrival: you have a good grasp of the whole BuyCo platform: our infrastructure, Disaster Recovery Plan, SLAs and ISO 27001 framework. You can answer a customer's security questionnaire on your own.
8 months after your arrival: you have run a gap analysis between where we are and where we want to be, and built BuyCo's security roadmap. The hot topics (platform, development, tools, processes) are identified to get and stay compliant.
1 year after your arrival: your impact on security and compliance is concrete and visible. Our certifications are ready for renewal, internal audits show no non-conformities, and BuyCo has clear governance on data, AI and GDPR risks.
Preferred experience
If you recognize yourself in this, you have a great chance of succeeding in the position:
You have solid experience in cybersecurity and can work autonomously from day one on security topics.
You speak English and French, and are comfortable working with vendors and customers in English.
You have a strong tech background: you understand infrastructure and software engineering fundamentals, and you can talk with developers in their own language.
You have hands-on experience with public Cloud (AWS preferred) and Kubernetes.
You have already taken part in a certification process (ISO 27001, SOC 2 or any other). You don't need to be a compliance expert: you are eager to grow on this side.
You know how to prioritize based on risk: you know nothing is infallible, and you focus on what matters most.
You anticipate problems instead of waiting for them.
You are a good teacher and tenacious: you can explain tricky security topics in simple words and bring people on board.
You are curious and keep up with new topics, such as AI and its security challenges.
Your profile will be 😍 if:
You have worked with Wiz or another Cloud security platform, and with Drata or another compliance automation tool.
You have experience with Identity and Access Management, ideally Keycloak.
You know GDPR well and have followed the EU AI Act closely.
You have worked in a B2B SaaS company.
Compensation, remote policy & others
Compensation: between 52k€ and 64k€ gross per year
No on-call duty (pas d'astreintes)
Ideal start date: January 2027
Participation in purchasing remote items
Remote policy: full remote possible. As a reminder, we have offices in Paris & Marseille (HQ).
+
Swile meal vouchers 🍝
SideCare health insurance 🩺
50% reimbursement of public transportation costs Ⓜ️
Sustainable mobility bonus 🚲
Profit-sharing bonus 🍰
Holiday bonus 🏝
Choice of your equipment: Lenovo or Mac 💻
6 additional RTT days per year ✈️
2 paid sick child leave days 🤒
(Only with a French contract)
Recruitment process
Step 1: interview with Cyril, Talent Acquisition Manager (45min)
Step 2: interview with Joffrey, Head of Platform, and Mickaël, CTPO, with a deep dive into your security and compliance expertise (1h30)
Step 3: Culture fit interview with Annie, VP People, and possibly Christophe, Head of Engineering (1h)
- Department
- Tech
- Role
- Security & Compliance Engineer
- Remote status
- Fully Remote
- Salary
- €52,000 - €64,000/year
- Employment type
- Full-time
About BuyCo
BuyCo simplifies container shipping with SaaS.
Founded in Marseille in 2015, now 50+ people and scaling fast.
Join us to disrupt the maritime supply chain!