Recherchez une offre d'emploi

Lead Application Security Engineer H/F - 75

Description du poste

CFMABOUT CFM

Founded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients.
We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate experts in research, technology, and business to explore new ideas and challenge existing assumptions.

ABOUT THE ROLE

Are you passionate about application security and ready to serve as a subject matter expert in both application security and DevSecOps? In this role, you'll BE instrumental in protecting our low-latency processing systems and trading platforms across diverse environments. Reporting directly to the Group's CISO, you will work collaboratively with development, infrastructure, and operations teams to embed security into every phase of our software development lifecycle.

Overview & Key Responsibilities :
- Serve as the internal point of reference and Subject Matter Expert for application security and DevSecOps practices.
- Advise on best practices and long-term strategy for secure automation, ensuring security is integrated at all stages-from design and development to deployment and operations.
- Lead the development and implementation of robust security controls in our CI/CD pipeline, including automated testing, compliance checks, and vulnerability management.
- Collaborate with cross-functional teams (software developers, infrastructure engineers, and security officers) to ensure all solutions follow secure coding practices and meet industry standards (e.g., ISO 27001, NIST CSF, SOC 2).
- Conduct comprehensive design reviews, threat modeling, and architecture assessments to proactively identify and mitigate security risks in new and existing solutions.
- Establish and enforce policies for encryption, authentication (both human and machine), access control (role- and attribute-based), secret management, and secure configurations in cloud (AWS, GCP, or Azure) as well as on-premises environments.
- Champion Infrastructure as Code (IaC) practices by integrating security checks into automated deployment processes using tools such as Terraform, CloudFormation, or Ansible.
- Develop, monitor, and report Key Risk Indicators (KRIs) to track security performance and drive continuous improvement.
- Provide leadership and training-both informally and through scheduled workshops-to upskill teams on secure development practices, DevSecOps tools, and emerging industry trends.

Je postule sur HelloWork

Offres similaires

Expert en Sécurité des Systèmes d'Information H/F

  • CAISSE FEDERALE DE CREDIT MUTUEL

  • Paris 9e - 75

  • CDI

  • 5 Septembre 2025

Expert Proxy H/F

  • Huxley

  • Paris - 75

  • Freelance

  • 5 Septembre 2025

Ingenieur SSI H/F

  • La Bonne Alternance

  • Paris 13e - 75

  • Alternance

  • 5 Septembre 2025


Recherches similaires

Déposez votre CV

Soyez visible par les entreprises qui recrutent à Paris.

J'y vais !

Chiffres clés de l'emploi à Paris

  • Taux de chomage : 9%
  • Population : 2165423
  • Médiane niveau de vie : 28570€/an
  • Demandeurs d'emploi : 205650
  • Actifs : 1177663
  • Nombres d'entreprises : 490838

Sources :


Un site du réseaux :

Logo HelloWork Logo HelloWork

Offres de Stage à Paris