This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a visionary and hands-on Principal Security Engineer to architect and lead our Application and Cloud Security domains. This is a critical leadership role for a "player-coach" who will bridge the gap between security, engineering, and product delivery. You will not only identify risks but actively build solutions to mitigate them. You will be responsible for embedding security into the earliest stages of the development lifecycle ("Shift Left"), securing our multi-cloud footprint, and pioneering our approach to AI and Large Language Model (LLM) security.
Job Responsibility:
Draft and own technical security policies and procedures for Engineering and Product teams
Serve as the primary security liaison to the Engineering and Delivery teams
Partner with the Head of InfoSec and GRC teams to maintain our Unified Control Framework
Architect and mature the Secure Software Development Lifecycle (SSDLC)
Lead threat modeling for new features and major architectural changes
Manage the Vulnerability Assessment and Penetration Testing (VAPT) program
Act as a mentor to developers, providing "just-in-time" training on secure coding practices
Own the security architecture for our multi-cloud environment (AWS, Azure, GCP)
Pioneer our AI Security Strategy
Design and maintain Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP) strategies
Act as a key stakeholder and technical lead during high-severity Incident Response investigations
Partner with the SecOps team to configure and optimize our SIEM and MXDR platforms
Perform root cause analysis on security incidents to feedback lessons learned into the policy and architecture phases
Requirements:
10+ years of progressive experience in cybersecurity
At least 5 years dedicated to Application Security or Cloud Security engineering
Deep technical proficiency in AWS, including native security services (GuardDuty, Inspector, WAF, KMS) and IAM policy architecture
Strong coding/scripting background
Must be able to read and review code in languages such as Python, Go, Java, or Node.js
Expert knowledge of modern application security frameworks and standards, specifically OWASP Top 10, OWASP API Security Top 10
Proven experience implementing and managing DevSecOps pipelines (Jenkins, GitHub Actions) and toolchains (SonarQube, Snyk, Veracode, etc.)
Hands-on experience with Container Security (Docker, Kubernetes) and securing serverless architectures
Demonstrated ability to write clear, concise technical policies and procedures
Nice to have:
Experience securing AI/ML pipelines and familiarity with ISO 42001 or the NIST AI Risk Management Framework
Experience with Terraform or managing Infrastructure as Code
Advanced professional certifications such as CISSP, CCSP, OSCP (Offensive Security Certified Professional), or AWS Certified Security – Specialty
Previous experience in a "Security Champion" leadership role, bridging the gap between security and development teams