Senior Backend & AI Engineer (Cyber-Engineering)
Build AI-powered cyber defense tools in Go or Python, turning real-world attack insights into reliable products that protect thousands of European businesses.
About Stoïk
Founded in 2021, Stoïk aims at becoming the most relevant cyber company in Europe through:
An insurance product to reimburse clients in case of a cyber attack;
An internalized incident response team (CERT) to minimize the financial consequences of a cyber attack;
Top-notch prevention tools to reduce the likelihood of such an attack.
We sell only through intermediaries (brokers or MSPs) and now have an extensive partner network we keep solidifying. A few numbers so it gets more concrete:
We are 170+ people with a 40+ tech team.
We insure 14k+ companies across 7 markets in Europe, with turnovers ranging from €0 to €1B.
Our CERT is 30 people and handles 150+ incidents every month (from small compromise to full-scale ransomware attacks).
Our insurance product reimburses €15m+ annually.
In the next five years, we intend to take a leading role in protecting European companies against an increasing cyber risk. As a consequence, we aim at taking a significant share of the European cybersecurity software market.
Why build here
AI impacts us in two ways: (1) cyber risk is changing very fast on the attack side; and (2) many cyber problems that used to be super hard are now within reach. This makes it very interesting to build here:
We are one of the only players in the world with a clear view on how cyber risk is changing. We literally reimburse clients for the financial consequences of attacks, so we know very well what types of attack cost money, what the trends are, and how hackers are updating their operations. We are able to cut through the noise and assess which products are worth building to reduce cyber risk efficiently. The noise is increasing as the innovation pace goes through the roof, so this is becoming one of our most precious assets.
We have skin in the game and a perfect alignment of interests with our clients. If our prevention tools don't work, we pay more, because we insure our clients. That forces us to hold very high standards about what we build and the team building it. And to keep up with frontier cyber capabilities.
Many problems have become simpler (but not simple!) because of AI. Think for instance of edge cases in detection that were very time-consuming but can now be handled decently well with well-set-up agents. We have no attachment to any single product, because we aim at solving cyber risk as a whole. If tomorrow one of our products becomes irrelevant because cyber risk has changed, we will drop it. On the contrary, that means we are currently super ambitious about what we can build, because we can help our clients in a coherent way.
As of now, we have built:
Tools to monitor vulnerabilities and misconfigurations in the IT system (EASM tool, phishing campaigns, AD scan, cloud scans).
Managed Services both on endpoints (the endpoint agent being a 3rd-party solution like CrowdStrike or SentinelOne) and on emails (fraud detection, mailbox compromise).
An Incident Management System (IMS) to automate a significant part of the CERT workload (forensics, communications, action plans).
This is quite balanced. Some of those require handling scale (Email Security processes 10m+ emails/day), others crafting smart workflows (IMS is about agent orchestration, testing them and making sure they are reliable on a critical task).
The role
We’re hiring for two distinct positions: an engineer to extend our AI-powered workflows in Python, and an experienced endpoint engineer to build our Go agent.
1) IMS - Extending the tool to every run team (Python). Our Incident Management System already automates a large part of the CERT workload. We're now extending its scope to:
more complex incidents like full-scale ransomware, and
all our run teams (underwriting, CSM, sales call prep).
The key quality here is the ability to ramp up fast and to deploy agentic capabilities solving the issue: understand a new team's workflow, ship something useful, and iterate. For ransomware response for instance, that means working directly with incident responders to understand their workflows and forensic tasks. You’ll build the tools, agent orchestration, and evaluation framework, and own the system’s reliability and adoption across our ransomware cases.
2) Endpoint Agent - Software inventory and risk detection (Go). You'll build an endpoint agent, in Go, that collects the software deployed on a machine and flags potential risks. This is a hard and critical problem: footprint, reliability, cross-platform behavior, and running quietly on someone else's production machines. Because of that, we're looking for someone with a strong previous experience in endpoint agent deployment and architecture.
We are iterating quite fast and have new projects frequently. So if your profile matches what's below, but that you're interested in another tool we've built, please reach out anyway.
Your profile
Strong engineering profile. Very smart, lots of agency, sense of urgency. Based in Paris.
You keep up with innovation and ruthlessly update your way of working. You're looking for a fast-paced and ambitious environment where you can grow and take ownership.
Previous senior+ backend experience. Notably you have 4+ years of experience running a production environment and handling speed-vs-reliability trade-offs.
Decent knowledge of cyber, or very curious about it.
Stack:
Go / Python (strong in at least one)
PostgreSQL
AWS / Terraform / K8s
Compensation
Competitive salary set to reflect the impact you'll have. We discuss salary and equity during the first screening call, before any technical assessment.
Process
Screening call - 30mn
Technical test - take home + 2h on-site debrief and live test
Fit round - 2h on-site with founders and future colleagues
- Department
- Engineering
- Role
- Dev Go/Python
- Locations
- Paris, Stoïk Headquarters
- Remote status
- Hybrid
- Employment type
- Full-time