Why This Role Stands Out
As Head of Security at Spiko, you'll have the opportunity to build and own the security strategy for a rapidly growing fintech company, directly impacting their mission to safeguard customer data and funds. This role is ideal for a seasoned security leader who thrives on end-to-end ownership and is passionate about establishing robust compliance and security frameworks in a dynamic environment. Apply to make a significant impact at Spiko and contribute to their journey as a leading treasury management infrastructure provider.
Quick Overview
Job Description
Our Mission
Money sitting idle is money lost. We're fixing that.
Founded in 2023 by Antoine and Paul-Adrien, Spiko gives businesses, non-profits, financial advisers, and fintechs access to institutional-grade cash management, via app or API. We are building the full infrastructure: issuing, operating, and distributing the products ourselves.
Two years after launch, we serve thousands of organizations across Europe and process hundreds of millions of euros in flows every month.
Our ambition: become the world's leading treasury management infrastructure in a market worth trillions.
We are backed by Index Ventures, the CEO of Revolut, the founder of Kyriba, and the CTO of Wise.
Spiko runs on excellence, transparency, and straight talk.
The role: (Job Title)
Your core mission is simple: make our customers' data and money safe
As head of security, you own security at Spiko end to end: application, infrastructure and cloud security, identity and access, vulnerability management, pentests and AI-driven security testing, detection and incident response, and the security culture of the whole company.
You define the roadmap and set the priorities. In return, you get full ownership. This role sits within Spiko’s tech team.
Your second-order missions are:
Own our compliance framework. Bring ISO 27001 certification over the line and keep it, lead our DORA implementation, and put in place the policies, controls and evidence collection that regulators, auditors and partners expect from a company that manages client money. You work hand in hand with our legal & compliance team on this.
Support the business on security due diligence. Large partners and Spiko Embedded clients run security due diligence on us before they integrate. You work to answer their questionnaires or enable the sales team to do it, to present our security posture to their teams, and makes our security a selling point.
Our stack
Cloud: AWS, GCP, Cloudflare
Infrastructure as Code: Terraform
Orchestration & Deployment: Kubernetes, Docker, Qovery
Databases: PostgreSQL
Observability: Datadog (logs, traces, metrics, RUM)
Identity & Access: Ory (Kratos, Hydra, Oathkeeper)
CI/CD: GitHub Actions
Application stack: TypeScript, NX, Effect, React
Who we’re looking for
Requirements (must-haves):
5+ years of experience in security engineering roles
Solid understanding of application security, network security, and cloud security best practices
Experience with security audit processes, vulnerability management, and compliance frameworks (ISO 27001, SOC 2, or similar)
Familiarity with CI/CD security tooling (SAST, DAST, dependency scanning, container scanning)
Experience with automated pentesting tools or AI-driven security testing
Comfortable working autonomously and defining your own roadmap
Comfortable working in an English-speaking environment
Curious, pragmatic, and eager to learn
Nice to have:
Experience in fintech, capital markets, or other highly regulated environments
Knowledge of blockchain infrastructure or Web3 security
What we offer
💰Compensation: Competitive package depending on experience + Stock Options
📍 Offices: in central Paris & London
🏡 Remote work: up to 2 days per week and one full remote week per month
💻 The best tech for your job: latest-generation laptops and industry-leading software
🏥 Health insurance: 100% covered by Spiko
💳 Monthly Budget to cover different perks of choice
🚇 Transport: 50% of public transport pass covered or the Forfait Mobilités Durables (FMD)
👥 Referral Bonus
🎊 Social life: regular afterworks and biannual offsites
Our hiring process
Screening Interview - 30 min screening call with Talent Acquisition
Hiring Manager Interview - 30 min with Nicolas, Tech Lead
45 min technical interview focused on infrastructure & security with one engineer (remote)
2h hands-on technical session with two engineers (infrastructure design, security scenario) (in the office)
Final Interviews with the Founders
Reference Check: we'll reach out to your references to gather further insights
Offer 🎉
If something here doesn't match your résumé perfectly but you believe you'd thrive in this role, apply anyway. Tell us why.
Similar jobs
- ER
Cyber Security Architect
NewECS Resource Group Ltd
Newbury, Berkshire🇬🇧Remote49 minutes ago5GAWSEncryption+3Technology - SE
Senior Cybersecurity Engineer
NewSchneider Electric
Coventry, Warwickshire🇬🇧Hybrid49 minutes ago5GMFATCP/IP+5Technology - SE
Senior Cybersecurity Engineer
NewSchneider Electric
Woolston, Warrington🇬🇧Hybrid49 minutes ago5GMFATCP/IP+5Technology - MU
Security Operations Analyst
NewMoog UK
Tewkesbury, Gloucestershire🇬🇧Hybrid49 minutes agoOperations & Project Management - EC
Cyber Security Architect
NewECS
Newbury, Berkshire🇬🇧Remote49 minutes agoTechnology - CH
Security Architect - DV Cleared
NewCBSbutler Holdings Limited trading as CBSbutler
Corsham, Wiltshire🇬🇧Hybrid49 minutes agoPenetration TestingTechnology