Application Security Engineer

Sumár práce
Plný úväzok
Paris
Niekoľko dní doma
Plat: Neuvedené
skúsenosti: > 4 roky
Vzdelanie: Bakalársky stupeň vzdelania
Zručnosti & odborná znalosť
Znalosť kybernetickej bezpečnosti
Infrastructure as Code (IaC)
Komunikačné zručnosti
DevSecOps
Linux
+7

Capital Fund Management
Capital Fund Management

Máte záujem o túto ponuku?

Otázky a odpovede ohľadne ponuky

Pozícia

Popis pracovnej ponuky

 

ABOUT THE ROLE 

  

Are you passionate about application security and ready to serve as a subject matter expert in both application security and securing the software development lifecycle? In this role, you’ll be instrumental in protecting our low-latency processing systems and trading platforms across diverse environments. Reporting directly to the Director of Application Security, you will work collaboratively with development, infrastructure, and operations teams to embed security into every phase of our process and in the company culture. 

 
Overview & Key Responsibilities: 

  

  • Serve as the internal point of reference and Subject Matter Expert on application security and software factory security. 
  • Design, implement, and maintain the essential tools to ensure secure CI/CD pipelines with robust security controls including automated testing, secrets detection, compliance checks, software composition analysis, and vulnerability management. 
  • Support our development teams in addressing identified findings, ensuring compliance with secure coding practices to align with industry standards for both cloud and on-premises environments, and promote a culture of ongoing security enhancement. 
  • Participate in design reviews, threat modeling, and architecture assessments to proactively identify and mitigate security risks in new and existing solutions. 
  • Work with our Core and Architecture team to establish and enforce solutions for encryption, authentication (both human and machine), access control (role- and attribute-based), secret management, and secure configurations in cloud (AWS, GCP, or Azure) as well as on-premises environments. 
  • Develop, monitor, and report indicators to track security performance and drive continuous improvement. 

  

 


Preferované skúsenosti

Profile description:

Minimum Qualifications: 

  

  • Bachelor’s degree (or equivalent practical experience) in Computer Science, Information Security, or a related field. 
  • A minimum of 4 years of hands-on experience in application security, with proven expertise securing modern architectures—including cloud environments, containerized applications, serverless platforms, APIs, and traditional on-premises systems. 
  • Hands-on experience with security testing tools (e.g., SAST, DAST, IAST, SCA, SBOM…) 
  • Ability to design, configure, implement, and maintain these tools as part of production CI/CD pipelines, ensuring accurate vulnerability detection, low noise, and minimal impact on deployment speed and stability. 
  • Ability to design, configure, implement, and maintain these tools as part of production CI/CD pipelines, ensuring accurate vulnerability detection, low noise, and minimal impact on deployment speed and stability. Demonstrable experience implementing and managing secure CI/CD pipelines and integrating DevSecOps practices. 
  • Proficiency in Linux environments, networking protocols (TCP/IP, UDP, HTTP, HTTPS), and microservices architectures. 
  • Expert on authentication and authorization protocols including but not limited to SAML, OAuth2, OpenID Connect. 
  • Strong coding skills in Python with the ability to read, analyze, and communicate code vulnerabilities to both technical and non-technical audiences. 
  • Clear understanding of web development fundamentals like REST APIs, cookies, same-origin policy, cross-origin resource sharing etc. 
  • Familiarity with common security frameworks and methodologies (e.g., OWASP Top 10, NIST SSDF). 
  • Excellent written and verbal communication skills, with proven ability to transform complex technical concepts into clear business and security recommendations. 

 
Preferred Qualifications: 

 

  • An advanced certification such as Certified Secure Software Lifecycle Professional (CSSLP) is highly desirable. 
  • Demonstrated expertise in cloud security across AWS, GCP, or Azure, and extensive experience securing on-premises systems to ensure a cohesive security posture across all environments. 
  • Strong background in implementing and managing Infrastructure as Code (IaC) and automation tools (e.g., Terraform, Ansible, CloudFormation). 
  • Experience with threat modeling or conducting comprehensive security audits is a plus. 

 

 

Chcete sa dozvedieť viac?

Tieto pracovné ponuky by vás mohli zaujímať!

Tieto spoločnosti tiež prijímajú pracovníkov na pozíciu "{profesia}".

  • Mistral Ai

    Software Engineer, QA

    Mistral Ai
    Mistral Ai
    Plný úväzok
    Paris
    Niekoľko dní doma
    Umelá inteligencia / Machine Learning, IT / Digitálne technológie
    280 zamestnanci

  • H Company

    Senior Software Engineer

    H Company
    H Company
    Plný úväzok
    Paris
    Žiadna práca na diaľku
    Softvér, Umelá inteligencia / Machine Learning
    75 zamestnanci

  • Diffusely

    Senior Flutter Engineer

    Diffusely
    Diffusely
    Plný úväzok
    Paris
    Niekoľko dní doma
    Softvér, Umelá inteligencia / Machine Learning
    200 zamestnanci

  • Artefact

    Senior Software Engineer

    Artefact
    Artefact
    Plný úväzok
    Paris
    Niekoľko dní doma
    Umelá inteligencia / Machine Learning, Digitálny marketing / Dátový marketing
    1 500 zamestnanci

  • digeiz.

    C/C++ developer

    digeiz.
    digeiz.
    Plný úväzok
    Boulogne-Billancourt
    Príležitostná práca na diaľku
    Plat: 55K až 70K €
    Umelá inteligencia / Machine Learning, SaaS / Cloudové služby
    17 zamestnanci

  • Dataiku

    Fullstack Software Engineer - Business Solutions

    Dataiku
    Dataiku
    Plný úväzok
    Paris
    Žiadna práca na diaľku
    Softvér, Umelá inteligencia / Machine Learning
    1 000 zamestnanci

Zobraziť všetky pracovné ponuky