Senior Backend & AI Engineer (Go/Python)

StoïkParis, Île-de-FranceOn-siteFull-timeSenior, 5–8 yearsListed 1 day ago

Apply now

About this role

About Stoïk

Founded in 2021, Stoïk aims at becoming the most relevant cyber company in Europe through:

- An insurance product to reimburse clients in case of a cyber attack;
- An internalized incident response team (CERT) to minimize the financial consequences of a cyber attack;
- Top-notch prevention tools to reduce the likelihood of such an attack.

We sell only through intermediaries (brokers or MSP) and now have an extensive partners network we keep solidifying. A few numbers so it gets more concrete:

- We are 170+ people with a 40+ tech team.
- We insure 14k+ companies across 7 markets in Europe with a turnover from €0 to €1B.
- Our CERT is 30 people and handles 150+ incidents every month (from small compromise to full scale ransomware attacks).
- Our insurance product reimburses €15m+ annually.

Why build here

AI impacts us in two ways (1) cyber risk is changing very fast on the attack side; and (2) the complexity of cyber problems we can solve is decreasing. This makes it very interesting to build here:

- We are one of the only players in the world with a clear view on how cyber risk is changing. We literally reimburse clients for the financial consequences of attacks so we know very well what types of attack cost money, what are the trends, how are hackers updating their operations. Basically we are able to cut through the noise and assess what products are worth building to reduce cyber risk efficiently . The noise is increasing as the innovation pace is through the roof, so it is becoming one of our most precious assets.
- We have skin in the game and a perfect alignement of interests with our clients . If our prevention tools don't work, we will pay more because we insure our clients. That forces us to have very high standards about what we build and the team building. And to keep up with frontier cyber capabilities.
- Many problems have become simpler (but not simple!) because of AI. Think for instance edge cases in detection that were very time consuming but can now be handled decently well with well-setup agents. We don't have attachment to one given product because we aim at solving cyber risk as a whole. If tomorrow, one of our product becomes irrelevant becomes cyber risk has changed, we will drop it. On the contrary, that means that we are currently super ambitious about what we can build because we can help our clients in a coherent way.

As of now, we have built:

- Tools to monitor vulnerabilities and wrong configurations in the IT system (EASM tool, Phishing campaigns, AD Scan, Cloud Scans).
- Managed Services both on Endpoints (the endpoint agent being a 3rd party solution like Crowdstrike or SentinelOne) and on Emails (fraud detection, mailbox compromise).
- An "Incident Management Tool( IMS)" to automate a significant part of the CERT workload (forensic, communications, action plans).

This is quite balanced, especially: some of those require handling scale (Email Security process 10m+ emails / day), some crafting smart workflows (IMS is about agent orchestration, testing them and making sure they are reliable on a critical task).

Your profile

- Strong engineering profile. Very smart, lots of agency.
- Keeping up with innovation and ruthlessly updating your way of working.
- Looking for a fast-paced environnement where you can grow and take ownership.
- Experience running a production environnement and handling speed vs reliability trade-offs.
- Decent knowledge or very curious about cyber.
- Stack:

Go / Python (strong in at least one)
- PostgreSQL
- AWS / Terraform / K8s