Security Analyst

FranceFrance·Parismid
Security AnalystCybersecurity
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Threat Detection & SIEM Engineering Maintain, optimize, and enhance our core security monitoring toolkit (SIEM, sensors, etc.). Design, build, and continuously refine meaningful alerts,

Technical Tools
Security AnalystCybersecurity

Proton was founded in 2014 by scientists from CERN on a simple truth: privacy is a fundamental human right. Since then, we’ve built the world’s largest encrypted email service (Proton Mail) and expanded into Proton VPN, Proton Drive, Proton Pass, and Proton Calendar—tools used by millions globally to protect their freedom, fight censorship, and keep their data safe. In some situations, Proton has literally helped save lives!

We are profitable, independent (no VC control), and selectively hire from the top ~1% of applicants. Our 700+ team members across 50+ countries come from leading organizations and elite academic backgrounds. We move fast, keep hierarchy light, and prioritize impact over optics. If you want to do meaningful work with exceptionally high-caliber people, this is it. Join us and do work you can truly be proud of. Check our open-source projects here!

 

The Security Analyst will be at the frontline of protecting Proton’s global infrastructure. This role combines analytical threat investigation with practical security engineering, taking a role in running, tuning, and evolving our detection capabilities.

You will bridge the gap between day-to-day security monitoring and proactive threat defense. Sitting within our security team, you will not only respond to alerts and manage incidents but actively design the rules, playbooks, and systems that catch attackers before they succeed. We value deep logical reasoning, data-driven intuition, and strong cross-functional communication.

 

Responsibilities

~1 min read
  • Maintain, optimize, and enhance our core security monitoring toolkit (SIEM, sensors, etc.).
  • Design, build, and continuously refine meaningful alerts, transforming raw infrastructure events into high-fidelity detections.
  • Proactively identify malicious activities or blind spots within our network and infrastructure that our current toolsets might not cover.
  • Monitor, triage, and deeply investigate security alerts covering all of Proton’s corporate infrastructure.
  • Own the containment and mitigation of potential security incidents, orchestrating quick and effective response actions.
  • Develop, document, and test rigorous incident response plans and actionable playbooks to streamline future workflows.
  • Analyze complex logs, endpoints, and network traffic to isolate anomalies, extract patterns, and identify emerging risks.
  • Collaborate with engineering teams to deploy and maintain secure architectures, applying server and system security best practices (e.g., OS hardening, strict access controls).
  • Contribute to continuous posture improvement by feeding operational findings back into security tooling and roadmaps.
  • Support, advise, and guide the wider company on all security-related matters and emerging risks.
  • Participate in business process documentation, operational metric reporting, and the strategic automation of security tasks.
  • Promote a culture of strong IT security awareness and responsible user behavior across our distributed teams.

 

Requirements

~2 min read
  • Good logical reasoning, structure, and problem-solving skills. The ability to correlate diverse data sources, extract hidden patterns from massive volumes of data, and think like an attacker.
  • Solid understanding of system and network security best practices, including network ACLs, authentication mechanisms, and endpoint defense configurations.
  • Strong working knowledge of Linux-based operating systems, their architectural security components, system calls, and mechanisms like SELinux.
  • Familiarity with modern malware techniques, attacker tactics (TTPs), and how to translate this threat intelligence directly into actionable SIEM rulesets.
  • Sound understanding of networking protocols, web technologies, and detection mechanics (eg. EDR, IDS/IPS).
  • Intermediate-to-advanced proficiency in Python (or similar languages) for scripting, parsing, and automation tasks.
  • Excellent written and spoken English, paired with strong communication and organizational skills to collaborate smoothly across different teams.
  • A deep belief in digital privacy.
  • Proven experience (ideally 3-4 years) in a cybersecurity or operations context.
  • Hands-on experience working with Elastic stack, Vector, or other tools used in large-scale log analysis.
  • Experience utilizing data analysis tools (such as Jupyter, Pandas) to hunt for anomalies.
  • Practical knowledge of securing and analyzing containerized workloads (Docker, Kubernetes) and Cloud infrastructure environments.
  • Experience in leveraging and integrating Threat Intelligence into security workflows.
  • An industry-recognized security certification is considered a strong asset.
  • The SIEM environment is highly tuned, resulting in a demonstrable reduction in false positives and a significant increase in high-value, actionable alerts.
  • Security incidents are quickly contained, thoroughly investigated, and translated into resilient long-term containment strategies and playbooks.
  • Threat detection coverage expands smoothly to secure new infrastructure, products, and cloud microservices.

 

What We Offer

~1 min read
  • At Proton, we believe diversity drives innovation and strengthens our mission to provide privacy as a default for all. We are committed to fostering an inclusive environment where all individuals, regardless of race, ethnicity, gender, age, sexual orientation, physical ability, or socio-economic background, feel valued and empowered. We strive to create equal opportunities, promote open dialogue, and support continuous learning to ensure every voice is heard and respected.

    If you need any extra support or reasonable adjustments during the hiring process, please let your talent partner know.

When you apply for a position, refer a candidate, or are considered for a role at Proton Technologies AG (Proton, we, us, or our), your information is stored in Greenhouse, in accordance with their Service Privacy Policy. This information is used to evaluate your suitability for the posted position. We also retain this information for consideration for future roles that you may apply for or that we believe may align with your background and skills.

If we no longer have a legitimate business need to process your information, we will either delete or anonymize it. Should you have any inquiries about how we use or manage your information, or if you wish to access, correct, or delete your data, please contact our privacy team at careers@proton.ch.

Proton does not accept unsolicited resumes from any sources other than directly from candidates. We will not pay a fee for any placement resulting from an unsolicited offer, even if the candidate is subsequently hired by Proton.

To learn more about our privacy policy, please visit our privacy policy page

Compensation range
Paris:  38.000 - 62.000 gross annually*
Other locations: Compensation will be discussed during the interview process
*Final compensation will be determined based on the candidate's qualifications, skills, and previous experience

#LI-Onsite

 

Location & Eligibility

Where is the job
Paris, France
On-site at the office
Who can apply
FR

Listing Details

Posted
June 29, 2026
First seen
June 29, 2026
Last seen
June 29, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
60%
Scored at
June 29, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
proton tehnologies
Employees
350
Founded
1999
Domain
proton.ro
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

proton tehnologiesSecurity Analyst