Principal Security Engineer, Product & Infrastructure
Own the product and infrastructure security roadmap as a hands-on individual contributor, covering threat modeling, vulnerability management, detection, incident response, assurance, and secure SDLC practices. Requires 8+ years of security experience and deep technical breadth.
About the job
Responsibilities
- Own and execute the security roadmap for the product, infrastructure, and CI/CD environment.
- Design product security features and strengthen platform defense in depth.
- Threat-model new services and make security-sensitive architectural decisions.
- Conduct code, architecture, and infrastructure-configuration reviews; provide pragmatic risk assessments and solutions.
- Run assurance activities, including internal reviews, red-team exercises, bug-bounty operations, third-party auditor relationships, and certification control KPIs.
- Manage vulnerabilities from detection through verified remediation, including reproduction, scoring, triage, mitigation validation, and process improvement.
- Build detection capabilities, detection rules, signal collection, and incident-response playbooks.
- Lead production security and fraud investigations from initial signal through root cause.
- Define secure SDLC direction through guidance, paved paths, and engineering reviews.
- Secure AI features, including MCP Server and Modeler Agent implementations.
- Evaluate the appropriate use of AI-assisted security analysis alongside SAST and SCA.
- Migrate GitHub to managed identities and short-lived OIDC credentials.
- Design agent identity and delegated-access controls for the MCP Server.
- Advance least-privilege controls across production and CI/CD.
Requirements
- At least 8 years of professional security experience as a Security Engineer, Pentester, or Security Consultant.
- Deep experience in product and/or infrastructure security.
- Ownership of a security roadmap for a product or platform.
- Experience driving security initiatives through teams without direct authority.
- Experience making and escalating complex architectural security decisions.
- Hands-on experience across development, databases, networking, and web technologies.
- Fluent English.
- French is a strong plus.
- This is an individual-contributor role with no people-management responsibility.
Technical Environment
- GCP, Kubernetes, Terraform, Postgres, SingleStore, Vault
- Okta, OAuth, JWT, C#, .NET Core, TypeScript, React, Python, Go
- Datadog, Cloudflare ZTNA, Falco, Wiz, Riot, HackerOne, TruffleHog
- GitHub, CircleCI, ArgoCD
- SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001
- macOS, Windows, Linux
Compensation and Benefits
- Annual compensation of €80,000–€120,000.
- Stock options.
- Fully paid health insurance for the employee and family.
- Weekly lunches and flexible lunch vouchers.
- Egym Wellpass membership across France.
- Annual learning stipend.
- Remote-work stipend.
- Annual company offsite.
- High-end work equipment.
Skills
GCP, Kubernetes, Terraform, Postgres, Vault, Okta, OAuth, Jwt, C#, .Net Core, TypeScript, React, Python, Go, Datadog
Similar jobs
Security Engineering jobsMaintains Mozilla’s information security management system and leads ISO 27001 and SOC 2 compliance activities, including audit readiness, policy governance, remediation tracking, and stakeholder coordination. Requires at least five years in information security, GRC, or compliance and strong audit experience.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.
Secures Datadog’s cloud infrastructure, platform building blocks, and SaaS applications by implementing scalable solutions across a multi-cloud Kubernetes environment. The role requires hands-on software engineering, application and cloud security experience, and expertise with modern security frameworks and technologies.