Security Engineer - Full Remote (France) or Hybrid
RemoteFrance
Job Summary
Strengthen the security posture across products, data, and infrastructure by implementing secure coding practices, threat modeling, and cloud hardening. Develop automated security guardrails integrated into CI/CD pipelines for SAST, SCA, and secrets scanning. Design secure architectures for applications and APIs while securing hybrid environments combining virtual machines and containerized workloads. Drive proactive risk identification through continuous scanning and architecture reviews, then enable engineering teams to build secure-by-design practices by acting as a trusted advisor and developing internal tools. Participate in on-call rotations to investigate security events and improve incident response workflows.
Required Qualifications
- 5–7 years of experience in software engineering, security engineering, DevSecOps, or equivalent technical security roles
- Strong development background (Python, Node.js, Java, Go, PhP or similar)
- Hands-on experience with modern CI/CD systems (GitHub Actions, GitLab, Jenkins)
- Solid understanding of cloud security principles (AWS, GCP, Azure)
- Experience securing both virtualized systems (VMs) and containerized workloads
- Strong knowledge of secure coding, OWASP Top 10, and application security fundamentals
- Experience with SAST, SCA, container/IaC scanning, runtime security tools, IAM, and secrets management
- Pragmatic, engineering-first mindset: able to balance security with developer experience, velocity, and real-world constraints
- Excellent communication skills: able to translate complex security issues into actionable guidance for both technical and non-technical stakeholders
- Proactive, autonomous, critical thinker with a continuous improvement mindset
- Fluent in French and English
Desired Qualifications
- Nice to have: previous experience or knowledge of compliance requirements (GDPR, PCI-DSS...)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.