Three Openings, One Direction
Stoïk has opened three roles that reveal where its European cyber-insurance operation is thickening. The hiring push marks a significant expansion of the company's European cybersecurity operations; its multi-stage screening process filters for both technical depth and cultural alignment. Together the openings signal where the product is heading: one seat writes code that powers the detection engine, two sit on the customer side translating that engine's output into something a broker in Madrid or a managing director in Munich can act on.
The Senior Backend & AI Engineer role anchors the Cyber-Engineering squad in Paris. The posting is explicit: this hire will work on the proprietary AI layer that drives continuous risk prevention and detection, the same layer that feeds Stoïk's in-house incident response teams. The company's 360° model (insurance, prevention, detection, response) depends on that layer turning raw telemetry into underwriting signal fast enough to matter. Candidates need production-grade backend experience and a track record of moving ML models from notebook to pipeline; the "AI" in the title isn't decorative.
In Madrid, the Junior Customer Success Manager role carries different weight. Stoïk's Iberia expansion is less than two years old, and the Spanish broker network (part of 2,000-plus partners company-wide) needs hands-on onboarding. The job description assigns 60 percent of the role to cyber tools implementation: guiding new policyholders through sensor deployment, configuration, and the first 90 days of alerts. The other 40 percent is feedback loops: structured input from brokers and clients that shapes the Product and Operations roadmaps. SaaS or tech-facing experience is required; cybersecurity fluency is the differentiator.
Munich hosts the third opening: a "Cyber" Customer Success Manager for the DACH region, fully remote. The title's qualifier is deliberate. This isn't a generic CSM slot. The role sits inside Stoïk GmbH and serves the German-speaking broker base, where regulatory scrutiny on cyber resilience is tightening and the conversation starts at technical controls, not premium savings. The remote designation reflects a market where senior talent rarely relocates. The expectation mirrors Madrid: own the post-bind journey, coordinate with Cyber Sales and the Paris tech teams, feed the product loop. But the DACH context adds GDPR-adjacent compliance fluency and a buyer persona that evaluates vendors on evidence, not decks.
All three roles exist because Stoïk's footprint — more than 12,000 protected companies across seven countries — has outpaced its 170-person specialist team. The engineering hire scales the brain; the two success hires scale the nervous system.
How the Funnel Works
Stoïk's hiring pipeline moves fast by design. The company publishes its process on GitHub: apply by emailing [email protected] with your LinkedIn profile and the role you want — no resume, no cover letter, five minutes. That simplicity is intentional. It filters for candidates who can follow a direct instruction and present themselves clearly without the crutch of a polished PDF.
The first live touchpoint is a 30-minute intro call. A recruiter or hiring manager walks you through Stoïk's business (cyber insurance for European SMEs, backed by its own underwriting capacity) and the specific role. The conversation covers the mission to strengthen the European economic fabric and the day-to-day realities of the position.
If both sides want to continue, the technical test arrives. It's a take-home exercise, untimed, designed to take roughly two hours. The GitHub description says "~2 hours, untimed", a deliberate choice that respects candidates' schedules and reduces the pressure-cooker dynamic of live coding. Glassdoor reviews confirm the format: a coding test sent beforehand, then a review session. One candidate noted the exercise involved a live design test for a security screening platform, suggesting the work product mirrors actual Stoïk engineering challenges.
The review session is a 90-minute video call where you walk through your solution with engineers. This is where the filter tightens. The conversation shifts from "does it run?" to "how did you think about the trade-offs?" Candidates describe sitting with an engineer and a higher-up, a panel that blends technical depth with organizational perspective. The discussion covers your code, your architecture choices, and how you'd extend the system under real constraints.
Glassdoor data shows three interview questions and three reviews posted anonymously for one role, and one question and one review for another, a small but consistent sample. The pattern holds: Stoïk keeps the panel small, the stages few, and the evaluation grounded in work product rather than hypotheticals. The careers portal notes that information about your application and profile is usually created by the company, or in cooperation with you, during the recruitment process, including notes from interviews, assessments and tests made. That documentation trail means every interviewer enters the room with context.
Glassdoor reviewers emphasize that the hiring team puts serious time and effort into tracking down not only qualified candidates but also folks who are inclusive and supportive of their teammates. That cultural signal appears after technical validation.
The funnel is short, transparent, and weighted toward demonstrated work. The process selects for engineers who can build, explain, and iterate, exactly what the role demands.
The Skill Matrix: Two Tracks, One Baseline
Stoïk's two open engineering roles (Senior Backend AI Engineer (IMS track) and Senior Backend AI Engineer (Endpoint Agent track)) share a baseline but diverge sharply on the specialties that determine whether a candidate clears the technical test. The company publishes its stack plainly: Go or Python at production grade, PostgreSQL, AWS, Terraform, Kubernetes. That list is the entry ticket, not the filter.
| Competency | IMS / AI Workflow Track | Endpoint Agent Track | Shared Baseline |
|---|---|---|---|
| Primary language | Python (agent orchestration, LLM tooling) | Go (agent binary, cross-platform) | Strong in at least one; 4+ years production backend |
| Core problem | Extend Incident Management System to ransomware, underwriting, CSM, sales prep | Build inventory/risk agent that runs quietly on customer endpoints | Speed-vs-reliability trade-offs in live environments |
| Must-have experience | Shipping agentic workflows: understand a team's process, ship useful iteration fast | Endpoint agent architecture: footprint, reliability, Windows/macOS/Linux behavior | Running PostgreSQL at scale; infra-as-code (Terraform) on AWS/K8s |
| Cyber domain | Decent knowledge or "very curious" — must map AI output to CERT workflows | Deep endpoint telemetry: software inventory, risk detection, EDR integration | Awareness of attack trends; the company reimburses €15M+ annually so it knows what costs money |
| AI/ML applied | Design prompts, eval loops, tool-use agents; iterate with CERT analysts | Light — may embed local models for classification | No attachment to any single model or framework; "ruthlessly update your way of working" |
The IMS track demands someone who can sit with the 30-person CERT (handling 150+ incidents monthly), learn their forensics and communication playbooks, then encode that logic into Python agents that survive edge cases. The job description phrases it as "ability to ramp up fast and to deploy agentic capabilities solving the issue: understand a new team's workflow, ship something useful, and iterate." That is a product-engineering skill masquerading as an AI role.
The Endpoint Agent track is a systems problem dressed in security clothing. "Footprint, reliability, cross-platform behavior, and running quietly on someone else's production machines," the job description calls this a hard and critical problem. Because of that, the company looks for someone with strong previous experience in endpoint agent deployment and architecture.
Both roles require "decent knowledge of cyber, or very curious about it." Stoïk's advantage — and its hiring signal — is that it literally pays claims. The CERT sees ransomware negotiations, business-email compromise, cloud misconfigurations. Engineers who can translate that telemetry into prevention code (the EASM scanner, phishing campaigns, AD scans, cloud scans processing 10M+ emails/day) gain an edge. The screening tests for that translation instinct.
Soft skills are codified in five public values under the acronym SPORT, and the fit round (two hours with founders and future colleagues) scores them directly:
- Simplicity: "No matter how noble our mission or how successful our journey, we're not saving the world. Let's stay humble. Ambitious, yes, but grounded." In practice: you avoid performative complexity; you explain a vulnerability finding to a broker in plain French or German.
- Progress: "We value a learning mindset over strong expertise." The company hires for trajectory, not a static skill set, a practical stance for a team that has grown to 180 people since 2021 while rolling out MDR services, expanding into Germany and Austria, and integrating AI-driven risk scoring.
- Ownership: "Everyone is free to set their own rules as long as they act in accordance with the company's other values." The take-home is open-ended; candidates who over-engineer or wait for spec clarification fail.
- Reliability: "We can't succeed without building trust. Working at Stoïk means committing to delivering exactly what you promise to colleagues, partners, and customers." In a business where brokers rely on Stoïk's 24/7 response capability, a missed deadline or vague commitment breaks the model.
- Team Spirit: "A team only succeeds if each member can prioritize the company's interests above his personal ones." The IMS track especially requires negotiating scope with underwriting, CSM, and sales, not just CERT.
These aren't posters on a wall. They map directly to the work. The mission (serving European SMEs that lack in-house CISOs) demands a specific kind of pragmatism. Candidates who have operated in resource-constrained environments, who understand the broker channel, or who have built products for non-technical buyers carry an advantage that no certification can substitute.
The European dimension sharpens the filter. Stoïk operates from Paris, Munich, Madrid, Vienna, Mechelen, and Rotterdam. Its contracts sit on the balance sheets of major insurers including Tokio Marine HCC, Swiss Re, and Axeria. A candidate who treats "European expansion" as a slide deck topic rather than a daily operational reality (compliance regimes, data sovereignty, broker licensing) will struggle to convince the hiring panel they can execute. The cultural fit filter isn't a separate gate. It's embedded in the technical questions, the case studies, and the reference calls. The mission does the filtering.
The team has seen only two engineering departures since 2021. Stoïk's offer includes equity for everyone and competitive salary discussed late in the process; they're not optimizing for compensation negotiation theater. Fluency in French is non-negotiable for spoken communication; English covers written. If you're not Paris-based, address relocation readiness upfront; the policy is flexible remote but Paris-based, full-time only.
The Signal in the Noise
Three roles. One funnel. A mission that doubles as a filter. Stoïk isn't hiring to fill seats — it's hiring to extend a model that has already survived contact with 150 monthly incidents, €15M in annual claims, and a broker network that relies on a 24/7 response capability. The candidates who clear the screen aren't the ones with the longest keyword lists. They're the ones who understand that in this business, the code you ship tonight is the policy someone else will invoke when the ransomware note lands tomorrow morning.
Working in frontier tech? Zero G Talent tracks the openings: see every open ASML role, browse frontier tech jobs, openings at Stripe, and the people building the field.