Application Security Engineer

il y a 7 jours


Paris, France Capital Fund Management (CFM) Temps plein

Are you passionate about application security and ready to serve as a subject matter expert in both application security and securing the software development lifecycle? In this role, you’ll be instrumental in protecting our low‑latency processing systems and trading platforms across diverse environments. Reporting directly to the Director of Application Security, you will work collaboratively with development, infrastructure, and operations teams to embed security into every phase of our process and in the company culture. Overview & Key Responsibilities Serve as the internal point of reference and Subject Matter Expert on application security and software factory security. Design, implement, and maintain the essential tools to ensure secure CI/CD pipelines with robust security controls including automated testing, secrets detection, compliance checks, software composition analysis, and vulnerability management. Support our development teams in addressing identified findings, ensuring compliance with secure coding practices to align with industry standards for both cloud and on‑premises environments, and promote a culture of ongoing security enhancement. Participate in design reviews, threat modeling, and architecture assessments to proactively identify and mitigate security risks in new and existing solutions. Work with our Core and Architecture team to establish and enforce solutions for encryption, authentication (both human and machine), access control (role‑ and attribute‑based), secret management, and secure configurations in cloud (AWS, GCP, or Azure) as well as on‑premises environments. Develop, monitor, and report indicators to track security performance and drive continuous improvement. Minimum Qualifications Bachelor’s degree (or equivalent practical experience) in Computer Science, Information Security, or a related field. A minimum of 4 years of hands‑on experience in application security, with proven expertise securing modern architectures—including cloud environments, containerized applications, serverless platforms, APIs, and traditional on‑premises systems. Hands‑on experience with security testing tools (e.g., SAST, DAST, IAST, SCA, SBOM). Ability to design, configure, implement, and maintain the tools as part of production CI/CD pipelines, ensuring accurate vulnerability detection, low noise, and minimal impact on deployment speed and stability. Demonstrable experience implementing and managing secure CI/CD pipelines and integrating DevSecOps practices. Proficiency in Linux environments, networking protocols (TCP/IP, UDP, HTTP, HTTPS), and microservices architectures. Expertise in authentication and authorization protocols including but not limited to SAML, OAuth2, OpenID Connect. Strong coding skills in Python with the ability to read, analyze, and communicate code vulnerabilities to both technical and non‑technical audiences. Familiarity with common security frameworks and methodologies (e.g., OWASP Top 10, NIST SSDF). Excellent written and verbal communication skills, with proven ability to transform complex technical concepts into clear business and security recommendations. Preferred Qualifications An advanced certification such as Certified Secure Software Lifecycle Professional (CSSLP) is highly desirable. Demonstrated expertise in cloud security across AWS, GCP, or Azure, and extensive experience securing on‑premises systems to ensure a cohesive security posture across all environments. Strong background in implementing and managing Infrastructure as Code (IaC) and automation tools (e.g., Terraform, Ansible, CloudFormation). Experience with threat modeling or conducting comprehensive security audits is a plus. Seniority Level Entry level Employment Type Full‑time Job Function Information Technology Industry Investment Management Location Greater Paris Metropolitan Region #J-18808-Ljbffr



  • Paris, France Capital Fund Management (CFM) Temps plein

    Founded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients.We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate...

  • Senior Security Engineer

    il y a 1 semaine


    Paris, France Swile Temps plein

    At Swile, we believe that good products can help reduce friction in daily professional life and boost employee satisfaction. Today, we provide innovative solutions in various areas such as Fintech, Travel, HR, and Employee Benefits to more than 5.5 million users in 85,000 companies in France and Brazil. Your role as a DevSecOps Engineer centers around...

  • Application Security Engineer

    il y a 2 semaines


    Paris, France Pennylane Temps plein

    Are you looking to have an impact on the daily life of millions of entrepreneurs in France and Europe? Do you thrive in a trustful, fast-paced environment? Do you feel like our Engineering principles are aligned with your vision ? Then Pennylane might be the right place for you — and you, might be the perfect fit for this role **Our vision** We aim to...


  • Paris, France Pennylane Temps plein

    Are you looking to have an impact on the daily life of millions of entrepreneurs in France and Europe? Do you thrive in a trustful, fast-paced environment? Do you feel like our Engineering principles are aligned with your vision ? Then Pennylane might be the right place for you — and you, might be the perfect fit for this role **Our vision** We aim to...


  • Paris, France ProtonMail Temps plein

    OverviewA better internet, where privacy is the default, is possible. Building this better internet might seem daunting or even unthinkable, but at Proton, this is what we do every day.Proton was founded in 2014 by a group of scientists who met at the European Organization for Nuclear Research (CERN). Our first product, Proton Mail, is now the world’s...

  • Security Engineer

    il y a 1 semaine


    Paris, Île-de-France Shift Technology Temps plein

    Shift is the leading AI platform for insurance.  Shift combines generative, agentic, and predictive AI to transform underwriting, claims, and fraud and risk - driving operational efficiency, exceptional customer experiences and measurable business impact.  Trusted by the world's leading insurers, Shift delivers AI when and where it matters most, at scale...


  • Paris, France Blackfluo.ai Temps plein

    About the job Endpoint Security EngineerEndpoint Security EngineerImplementing and managing comprehensive endpoint security solutions to protect servers, workstations, and mobile devicesPosition OverviewWe are seeking a skilled Endpoint Security Engineer with expertise in securing a variety of endpoints including servers, desktops, laptops, and mobile...


  • Paris, France Amazon Temps plein

    Key Job ResponsibilitiesAs a Senior Security Engineer, you’ll help to build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon’s infrastructure. You’ll work with data scientists, software development engineers, and other security engineers across multiple teams to develop innovative security solutions....

  • Senior Security Engineer

    il y a 3 jours


    Paris, Île-de-France Doctolib Temps plein

    We are looking for an Application Security Engineer to join the Security team in Paris.   As an Application Security Engineer, your mission will be to safeguard the security and privacy of millions of practitioners and patients while helping deliver an exceptional user experience across Europe's leading healthcare products. You will build and scale...

  • Security Engineer

    il y a 2 semaines


    Paris, France Dashlane Temps plein

    Join to apply for the Security Engineer role at Dashlane Get AI-powered advice on this job and more exclusive features. About Dashlane Dashlane’s mission is to deliver the credential security every business and employee needs to thrive. Millions of consumers, and over 25,000 brands worldwide, such as Michelin, Air France, and Forrester, trust Dashlane for...