Role Description
As a Senior DevSecOps Engineer, your mission is to make our infrastructure secure by design, detectable by default, and provable at audit time. You will be the bridge between security and platform engineering, with responsibilities including:
-
Completing onboarding and learning how we work through our platform and Convexity culture.
-
Mapping our Azure and AKS environment, detection and logging coverage, and ISO 27001 and SOC 2 control scope.
-
Meeting the DevOps, platform engineering, and IT teams.
-
Shadowing alert triage and one customer security assessment end to end.
Within 3 months, you will:
-
Be autonomous on our AKS and Azure environment and handle infrastructure-related alerts end to end.
-
Have shipped at least one concrete hardening or automation improvement in production.
-
Own the infrastructure scope of vulnerability management, from triage to remediation follow up.
Within 6 months, you will:
-
Have the honeypot live and producing high fidelity alerts.
-
Have measurably widened SIEM connector coverage, with documented log sources and retention.
-
Run infrastructure vulnerability remediation on a predictable cycle with SLA reporting.
Within 12 months, you will:
-
Manage detection content as code, with reviewed and tested rules and documented runbooks.
-
Have largely automated audit evidence on the infrastructure scope.
-
Have eliminated long-lived credentials on critical paths, enabling secure defaults for engineering teams.
Qualifications
-
5+ years in infrastructure, cloud or platform engineering with a strong security focus, or in security engineering with hands-on infrastructure practice.
-
Production experience with Kubernetes: RBAC, network policies, admission controllers, secrets handling, workload identity, runtime security.
-
Solid cloud experience, ideally Azure. Strong AWS or Google Cloud experience with a genuine interest in converting works too.
-
Infrastructure as code: Terraform, GitOps workflows, CI/CD pipelines.
-
Scripting and automation: Python or Go, plus shell. Comfortable reading and writing code, and opening pull requests on repositories owned by other teams.
-
Log analysis and investigation: cloud audit logs, query languages, correlation across identity, network and application sources.
-
Fluent English (US/UK) / B2 level or equivalent (FR).
Requirements
Benefits
-
Compensation package includes base salary, a variable component, and equity π.
-
Work From Home stipend.
-
RTT, lunch vouchers, medical insurance, gym subscription.
-
1 month parental leave for the second parent.
-
Flexible hours, full remote work possible anywhere in France π .
-
Diversity, Equity, and Inclusion initiatives with 6 active ERGs.
-
Corporate Social Responsibility initiatives.
-
A framework that will help you make an impact.
Interview Process
-
Phone Screen with our Talent Acquisition Manager.
-
Discovery Meeting with our Head of Security.
-
Live exercise with our Head of Security and our Head of DevOps.
-
Clarification Meeting with the Security Engineer and a DevOps engineer.
-
Culture Fit Meeting with our VP of Engineering.
-
Offer!