Recherchez une offre d'emploi
Lead Application Security Engineer H/F - 75
Description du poste
- Capital Fund Management
-
Paris - 75
-
Stage
-
Publié le 27 Août 2025
CFMABOUT CFM
Founded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients.
We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate experts in research, technology, and business to explore new ideas and challenge existing assumptions.
ABOUT THE ROLE
Are you passionate about application security and ready to serve as a subject matter expert in both application security and DevSecOps? In this role, you'll BE instrumental in protecting our low-latency processing systems and trading platforms across diverse environments. Reporting directly to the Group's CISO, you will work collaboratively with development, infrastructure, and operations teams to embed security into every phase of our software development lifecycle.
Overview & Key Responsibilities :
- Serve as the internal point of reference and Subject Matter Expert for application security and DevSecOps practices.
- Advise on best practices and long-term strategy for secure automation, ensuring security is integrated at all stages-from design and development to deployment and operations.
- Lead the development and implementation of robust security controls in our CI/CD pipeline, including automated testing, compliance checks, and vulnerability management.
- Collaborate with cross-functional teams (software developers, infrastructure engineers, and security officers) to ensure all solutions follow secure coding practices and meet industry standards (e.g., ISO 27001, NIST CSF, SOC 2).
- Conduct comprehensive design reviews, threat modeling, and architecture assessments to proactively identify and mitigate security risks in new and existing solutions.
- Establish and enforce policies for encryption, authentication (both human and machine), access control (role- and attribute-based), secret management, and secure configurations in cloud (AWS, GCP, or Azure) as well as on-premises environments.
- Champion Infrastructure as Code (IaC) practices by integrating security checks into automated deployment processes using tools such as Terraform, CloudFormation, or Ansible.
- Develop, monitor, and report Key Risk Indicators (KRIs) to track security performance and drive continuous improvement.
- Provide leadership and training-both informally and through scheduled workshops-to upskill teams on secure development practices, DevSecOps tools, and emerging industry trends.

Offres similaires
Expert en Sécurité des Systèmes d'Information H/F
-
CAISSE FEDERALE DE CREDIT MUTUEL
-
Paris 9e - 75
-
CDI
-
5 Septembre 2025
Expert Proxy H/F
-
Huxley
-
Paris - 75
-
Freelance
-
5 Septembre 2025
Ingenieur SSI H/F
-
La Bonne Alternance
-
Paris 13e - 75
-
Alternance
-
5 Septembre 2025
Recherches similaires
Déposez votre CV
Soyez visible par les entreprises qui recrutent à Paris.
Chiffres clés de l'emploi à Paris
- Taux de chomage : 9%
- Population : 2165423
- Médiane niveau de vie : 28570€/an
- Demandeurs d'emploi : 205650
- Actifs : 1177663
- Nombres d'entreprises : 490838
Sources :


Un site du réseaux :