Swile propose une carte et une application pour les avantages salariés, notamment les titres-restaurant, ainsi que des outils destinés à leur gestion par les entreprises.
Security Engineer Intern
Am I a fit — voir ma compatibilitéEn stage de 3 à 6 mois à Paris, vous rejoindrez l’équipe Security de Swile pour traiter les alertes, mener des audits et automatiser les contrôles récurrents. Vous piloterez également des projets de sécurité, contribuerez au durcissement des outils et intégrations, et soutiendrez les investigations liées à la fraude.
Repères sur Swile
- Secteur
- Grande consommation et agroalimentaire
- Siège
- Montpellier
- Domaine officiel
- swile.co
- Création
- 2017 · 9 ans
- Effectif public
- 900 employés
- Offres ouvertes
- 15
Détails de l’offre
La description complète publiée par Swile.
Description de l’offre
Our Security team protects Swile’s products, data and engineering platform. We work with a simple principle: when something is recurring, we automate it, and when a security requirement can become code, we write the code. As a Security Engineer Intern, you will not shadow the team, you will be part of it. You will handle real alerts, run your own audits and own projects end to end, with a dedicated mentor in the team throughout your internship.
What you will do
Detection and response Handle day to day security alerts: triage, investigate, qualify, escalate when needed.
Improve what we detect: reduce noise, close detection gaps, propose new signals. Automate the recurring: when an alert or a manual check keeps coming back, script it away. This is where we expect you to leave a mark. Security audits Run targeted audits, from a few days to a few weeks, on applications, configurations or third party providers. Turn findings into a prioritised remediation plan rather than a list of tickets. Projects you will own Ad hoc security projects across the engineering platform.
Security review and hardening of the tools and integrations we rely on (Dust, third party providers, internal integrations). Fraud
Support fraud investigations: dig, follow the trail, understand how an abuse pattern works and how we could detect it earlier.
This is an internship, so how you think matters more than what you already know. You learn fast and you are genuinely curious about security. You are a doer: you answer quickly, you close loops, you do not let things sit. You are pragmatic: you calibrate your response to the actual level of urgency and risk, and you know that not everything is a P1. You are open minded and comfortable asking questions across engineering teams. You are comfortable working in English, written and spoken.
You have some scripting ability (Python or equivalent) and a basic understanding of web applications, APIs and cloud environments.
Nice to have
that would make you stand out Personal projects, CTFs, homelab, bug bounty or security writeups. First exposure to a SIEM, to detection rules or to log analysis at scale. Curiosity for fraud and abuse patterns in a financial product. What this internship is not Not a pure GRC, compliance or policy writing internship. Not a pentest internship. Not a role where you watch dashboards without changing them.
Prérequis
- curious about security
- scripting ability
- basic understanding of web applications, APIs and cloud environments
- fast learner