Application Security Engineer
il y a 23 heures
Founded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients. We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate experts in research, technology, and business to explore new ideas and challenge existing assumptions. ABOUT THE ROLE Are you passionate about application security and ready to serve as a subject matter expert in both application security and securing the software development lifecycle? In this role, you’ll be instrumental in protecting our low‑latency processing systems and trading platforms across diverse environments. Reporting directly to the Director of Application Security, you will work collaboratively with development, infrastructure, and operations teams to embed security into every phase of our process and in the company culture. Overview & Key Responsibilities Serve as the internal point of reference and Subject Matter Expert on application security and software factory security. Design, implement, and maintain the essential tools to ensure secure CI/CD pipelines with robust security controls including automated testing, secrets detection, compliance checks, software composition analysis, and vulnerability management. Support our development teams in addressing identified findings, ensuring compliance with secure coding practices to align with industry standards for both cloud and on‑premises environments, and promote a culture of ongoing security enhancement. Participate in design reviews, threat modeling, and architecture assessments to proactively identify and mitigate security risks in new and existing solutions. Work with our Core and Architecture team to establish and enforce solutions for encryption, authentication (both human and machine), access control (role‑ and attribute‑based), secret management, and secure configurations in cloud (AWS, GCP, or Azure) as well as on‑premises environments. Develop, monitor, and report indicators to track security performance and drive continuous improvement. Minimum Qualifications Bachelor’s degree (or equivalent practical experience) in Computer Science, Information Security, or a related field. A minimum of 4 years of hands‑on experience in application, with proven expertise securing modern architectures—including cloud environments, containerized applications, serverless platforms, APIs, and traditional on‑premises systems. Hands‑on experience with security testing tools (e.g., SAST, DAST, IAST, SCA, SBOM…). Ability to design, configure, implement, and maintain these tools as part of production CI/CD pipelines, ensuring accurate vulnerability detection, low noise, and minimal impact on deployment speed and stability. Ability to design, configure, implement, and maintain these tools as part of production CI/CD pipelines, ensuring accurate vulnerability detection, low noise, and minimal impact on deployment speed and stability. Demonstrable experience implementing and managing secure CI/CD pipelines and integrating DevSecOps practices. Proficiency in Linux environments, networking protocols (TCP/IP, UDP, HTTP, HTTPS), and microservices architectures. Expert on authentication and authorization protocols including but not limited to SAML, OAuth2, OpenID Connect. Strong coding skills in Python with the ability to read, analyze, and communicate code vulnerabilities to both technical and non‑technical audiences. Familiarity with common security frameworks and methodologies (e.g., OWASP Top 10, NIST SSDF). Excellent written and verbal communication skills, with proven ability to transform complex technical concepts into clear business and security recommendations. Preferred Qualifications An advanced certification such as Certified Secure Software Lifecycle Professional (CSSLP) is highly desirable. Demonstrated expertise in cloud security across AWS, GCP, or Azure, and extensive experience securing on‑premises systems to ensure a cohesive security posture across all environments. Strong background in implementing and managing Infrastructure as Code (IaC) and automation tools (e.g., Terraform, Ansible, CloudFormation). Experience with threat modeling or conducting comprehensive security audits is a plus. EQUAL OPPORTUNITIES STATEMENT We are continuously striving to be an equal opportunity employer and we prohibit any discrimination based on sex, disability, origin, sexual orientation, gender identity, age, race, or religion. We believe that our diversity, breadth of experience, and multiple points of view are among the leading factors in our success. CFM is a signatory of the Women Empowerment Principles. FOLLOW US Follow us on Twitter or LinkedIn or visit our website to find out more about CFM. #J-18808-Ljbffr
-
Remote-First Application Security Engineer
il y a 23 heures
Paris, France EPI Company Temps pleinA prominent European payment initiative based in Paris is seeking an Application Security Engineer to embed security at the core of their digital wallet platform. You will guide teams in designing secure systems and be influential in strategic decisions regarding security architecture. The ideal candidate has over 5 years of experience in web application...
-
Application Security Engineer – Remote-First
il y a 1 jour
Paris, France EPI Company Temps pleinApplication Security Engineer – Remote-First 🚀 Be part of a movement to change the way Europe pays. In today’s digital world, payments often still feel outdated: random delays and confusing rules make it harder than it should be to pay and get paid. The European Payments Initiative (EPI) is here to change all that, forever. With Wero, our digital...
-
Application Security Engineer
il y a 1 jour
Paris, France Capital Fund Management (CFM) Temps pleinAre you passionate about application security and ready to serve as a subject matter expert in both application security and securing the software development lifecycle? In this role, you’ll be instrumental in protecting our low‑latency processing systems and trading platforms across diverse environments. Reporting directly to the Director of Application...
-
Senior Application Security Engineer
il y a 1 jour
Paris, France Pennylane Temps pleinA leading fintech firm in France seeks an Application Security Engineer to bolster its security measures for applications and infrastructure. The ideal candidate will manage vulnerability assessments, ensure compliance with ISO 27001, and work closely with cross-functional teams. A background in offensive security and knowledge of programming languages is...
-
Application Security Engineer
il y a 24 heures
Paris, France Capital Fund Management (CFM) Temps pleinFounded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients.We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate...
-
Paris, France Agoda Temps pleinA leading global travel platform is looking for a Senior/Staff Application Security Engineer based in Paris. This role involves conducting security reviews, enhancing security measures, and providing technical guidance. Candidates should have extensive experience in application security and cloud environments, along with strong communication skills. The...
-
Senior Application Security Engineer
il y a 23 heures
Paris, France Pennylane Temps pleinAre you looking to have an impact on the daily life of millions of entrepreneurs in France (and tomorrow in Europe)? Are you looking for a work environment that values trust, proactivity, and autonomy? Are our Engineering principles aligned with your vision? Then Pennylane is the right place for you ! Our vision We aim to become the most beloved financial...
-
Senior Application Security Engineer
il y a 2 semaines
Paris, France Pennylane Temps pleinAre you looking to have an impact on the daily life of millions of entrepreneurs in France (and tomorrow in Europe)?Are you looking for a work environment that values trust, proactivity, and autonomy?Are our Engineering principles aligned with your vision?Then Pennylane is the right place for you !Our visionWe aim to become the most beloved financial...
-
Senior Application Security Engineer
il y a 1 semaine
Paris, Île-de-France PENNYLANE Temps pleinAre you looking to have an impact on the daily life of millions of entrepreneurs in France (and tomorrow in Europe)?Are you looking for a work environment that values trust, proactivity, and autonomy?Are our Engineering principles aligned with your vision?Then Pennylane is the right place for you Our visionWe aim to become the most beloved financial...
-
Senior Application Security Engineer
il y a 1 semaine
Paris, Île-de-France Pennylane Temps pleinAre you looking to have an impact on the daily life of millions of entrepreneurs in France (and tomorrow in Europe)?Are you looking for a work environment that values trust, proactivity, and autonomy?Are our Engineering principles aligned with your vision?Then Pennylane is the right place for you Our visionWe aim to become the most beloved financial...