Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Security Analyst

Proton
CompanyProton
CategorySecurity
LocationParis
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted29 Jun 2026
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
About Proton Join Proton and build a better internet where privacy is the default Proton was founded in 2014 by scientists from CERN on a simple truth: privacy is a fundamental human right . Since then, we’ve built the world’s largest encrypted email service (Proton Mail) and expanded into Proton VPN, Proton Drive, Proton Pass, and Proton Calendar—tools used by millions globally to protect their freedom, fight censorship, and keep their data safe. In some situations, Proton has literally helped save lives! We are profitable, independent (no VC control), and selectively hire from the top ~1% of applicants. Our 700+ team members across 50+ countries come from leading organizations and elite academic backgrounds. We move fast, keep hierarchy light, and prioritize impact over optics. If you want to do meaningful work with exceptionally high-caliber people, this is it. Join us and do work you can truly be proud of. Check our open-source projects here !   Role Overview The Security Analyst will be at the frontline of protecting Proton’s global infrastructure. This role combines analytical threat investigation with practical security engineering, taking a role in running, tuning, and evolving our detection capabilities. You will bridge the gap between day-to-day security monitoring and proactive threat defense. Sitting within our security team, you will not only respond to alerts and manage incidents but actively design the rules, playbooks, and systems that catch attackers before they succeed. We value deep logical reasoning, data-driven intuition, and strong cross-functional communication.   What you will do: Threat Detection & SIEM Engineering Maintain, optimize, and enhance our core security monitoring toolkit (SIEM, sensors, etc.). Design, build, and continuously refine meaningful alerts, transforming raw infrastructure events into high-fidelity detections. Proactively identify malicious activities or blind spots within our network and infrastructure that our current toolsets might not cover. Incident Response & Monitoring Monitor, triage, and deeply investigate security alerts covering all of Proton’s corporate infrastructure. Own the containment and mitigation of potential security incidents, orchestrating quick and effective response actions. Develop, document, and test rigorous incident response plans and actionable playbooks to streamline future workflows. Risk Mitigation & System Security Analyze complex logs, endpoints, and network traffic to isolate anomalies, extract patterns, and identify emerging risks. Collaborate with engineering teams to deploy and maintain secure architectures, applying server and system security best practices (e.g., OS hardening, strict access controls). Contribute to continuous posture improvement by feeding operational findings back into security tooling and roadmaps. Governance Support, advise, and guide the wider company on all security-related matters and emerging risks. Participate in business process documentation, operational metric reporting, and the strategic automation of security tasks. Promote a culture of strong IT security awareness and responsible user behavior across our distributed teams.   Job requirements Good logical reasoning, structure, and problem-solving skills. The ability to correlate diverse data sources, extract hidden patterns from massive volumes of data, and think like an attacker. Solid understanding of system and network security best practices, including network ACLs, authentication mechanisms, and endpoint defense configurations. Strong working knowledge of Linux-based operating systems, their architectural security components, system calls, and mechanisms like SELinux. Familiarity with modern malware techniques, attacker tactics (TTPs), and how to translate this threat intelligence directly into actionable SIEM
HOUSE ADYou found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →