Founded in 2023 by Antoine and Paul-Adrien, Spiko gives businesses, non-profits, financial advisers, and fintechs access to institutional-grade cash management, via app or API. We are building the full infrastructure: issuing, operating, and distributing the products ourselves.
Two years after launch, we serve thousands of organizations across Europe and process hundreds of millions of euros in flows every month.
Our ambition: become the world's leading treasury management infrastructure in a market worth trillions.
We are backed by Index Ventures, the CEO of Revolut, the founder of Kyriba, and the CTO of Wise.
Spiko runs on excellence, transparency, and straight talk.
The role: (Job Title)Your core mission is simple: make our customers' data and money safe
As head of security, you own security at Spiko end to end: application, infrastructure and cloud security, identity and access, vulnerability management, pentests and AI-driven security testing, detection and incident response, and the security culture of the whole company.
You define the roadmap and set the priorities. In return, you get full ownership. This role sits within Spiko’s tech team.
Your second-order missions are:
Own our compliance framework. Bring ISO 27001 certification over the line and keep it, lead our DORA implementation, and put in place the policies, controls and evidence collection that regulators, auditors and partners expect from a company that manages client money. You work hand in hand with our legal & compliance team on this.
Support the business on security due diligence. Large partners and Spiko Embedded clients run security due diligence on us before they integrate. You work to answer their questionnaires or enable the sales team to do it, to present our security posture to their teams, and makes our security a selling point.
Cloud: AWS, GCP, Cloudflare
Infrastructure as Code: Terraform
Orchestration & Deployment: Kubernetes, Docker, Qovery
Databases: PostgreSQL
Observability: Datadog (logs, traces, metrics, RUM)
Identity & Access: Ory (Kratos, Hydra, Oathkeeper)
CI/CD: GitHub Actions
Application stack: TypeScript, NX, Effect, React
5+ years of experience in security engineering roles
Solid understanding of application security, network security, and cloud security best practices
Experience with security audit processes, vulnerability management, and compliance frameworks (ISO 27001, SOC 2, or similar)
Familiarity with CI/CD security tooling (SAST, DAST, dependency scanning, container scanning)
Experience with automated pentesting tools or AI-driven security testing
Comfortable working autonomously and defining your own roadmap
Comfortable working in an English-speaking environment
Curious, pragmatic, and eager to learn
Experience in fintech, capital markets, or other highly regulated environments
Knowledge of blockchain infrastructure or Web3 security
💰Compensation: Competitive package depending on experience + Stock Options
📍 Offices: in central Paris & London
🏡 Remote work: up to 2 days per week and one full remote week per month
💻 The best tech for your job: latest-generation laptops and industry-leading software
🏥 Health insurance: 100% covered by Spiko
💳 Monthly Budget to cover different perks of choice
🚇 Transport: 50% of public transport pass covered or the Forfait Mobilités Durables (FMD)
👥 Referral Bonus
🎊 Social life: regular afterworks and biannual offsites
Screening Interview - 30 min screening call with Talent Acquisition
Hiring Manager Interview - 30 min with Nicolas, Tech Lead
45 min technical interview focused on infrastructure & security with one engineer (remote)
2h hands-on technical session with two engineers (infrastructure design, security scenario) (in the office)
Final Interviews with the Founders
Reference Check: we'll reach out to your references to gather further insights
Offer 🎉
If something here doesn't match your résumé perfectly but you believe you'd thrive in this role, apply anyway. Tell us why.
Skills Required
- 5+ years of experience in security engineering roles
- Solid understanding of application, network, and cloud security best practices
- Experience with security audits, vulnerability management, and compliance frameworks such as ISO 27001 or SOC 2
- Familiarity with CI/CD security tooling, including SAST, DAST, dependency scanning, and container scanning
- Experience with automated penetration testing tools or AI-driven security testing
- Ability to work autonomously and define a security roadmap
- Comfort working in an English-speaking environment
- Curiosity, pragmatism, and eagerness to learn
- Experience in fintech, capital markets, or another highly regulated environment
- Knowledge of blockchain infrastructure or Web3 security
What We Do
Spiko is a Paris-based fintech startup launched in 2023 that democratizes access to money markets and treasury yields. The company develops tokenized infrastructure to provide seamless access to next-generation, internet-native financial instruments, specifically Money Market Funds. This allows businesses and individuals to earn daily interest on their cash holdings with institutional-grade security, enhancing capital efficiency and liquidity.







