Senior Security Engineer
Summary
Secure quantum-computing R&D infrastructure and corporate systems by designing security controls, automating compliance, and embedding DevSecOps across labs, Kubernetes, and CI/CD pipelines.
Responsibilities
- Corporate security — identity and access management (SSO, SCIM), security observability and audit logging, and operational cybersecurity (EDR/XDR, SIEM, vulnerability management, incident response).
- Application security — vulnerability management, CI/CD security (SAST, DAST, secret detection, IaC scanning), software supply chain security (SCA, SBOM), and threat modeling embedded into the development lifecycle.
- Infrastructure and industrial security — Infrastructure as Code (Terraform), Kubernetes security, and — uniquely for this role — securing the lab environment itself: instrumentation, control systems, embedded/firmware security, and OT/ICS hardening across our quantum R&D equipment.
- Leadership — mentoring engineers, driving continuous improvement, and partnering closely with engineering, IT, hardware, and physics teams to embed security by design without slowing down research.
Requirements
- 5+ years of experience in cybersecurity or a closely related engineering role
- Proven hands-on experience with Infrastructure as Code (Terraform)
- Solid experience securing containers and Kubernetes environments
- Strong fundamentals across both application and corporate security — vulnerability management, incident response, threat modeling
- Strong hands-on experience with identity technologies (SSO/SAML/OIDC, SCIM)
- Proficiency with security monitoring tooling (EDR/XDR, SIEM, audit logging)
- Solid scripting and automation skills (Python, Bash, or similar)
- Practical experience with application security tooling (SAST/DAST, SCA) and CI/CD security integration
- Degree in Computer Science, Cybersecurity, or a related field (Bac+3 to Bac+5), or an equivalent self-taught/bootcamp background with a proven track record
- Strong ownership and autonomy, clear communication with technical and non-technical stakeholders, and a genuine mentoring mindset
Nice to have
- Experience with cloud platforms (GCP, AWS, or Azure)
- Familiarity with security frameworks (ISO 27001, SOC 2, NIST)
- Exposure to embedded, firmware, or operational technology (OT/ICS) security — ideally in a lab or industrial setting
- Experience defining or maturing a DevSecOps program
Recruitment Process
- Screening Call with Grace, Talent Acquisition Specialist (30 min)
- Hiring Manager Interview with Matthew (45 min)
- Onsite Technical Interview with the Team & Take home test (120 min)
- Leadership Team Interview (30 min)
- Fit Interview (45 min)
- Reference check
Skills
As published by lever · 6 questions · 1 written answer
Basics
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website
Short answers (3)
- Do you currently hold a valid work permit for France?
- Are you currently located in the Paris region or seeking relocation?
- Are you seeking a full-time role?
Pick from a list (2)
- Do you speak Fluent French? optional
- Do you speak Fluent English? optional
Written answers (1)
- What is your expected salary range for this role (annual gross in EUR)?