Context Overall objective: To support the implementation of a new Continuous Integration (CI) platform and the integration of security controls.Key project constraint: Addressing security risks. As part of a cross-functional program to streamline and modernize its continuous integration (CI) and source code management tools (migrating thousands of Jenkins/Bitbucket projects to GitLab), the client is building its new software factory. The main objective of the mission is to integrate, automate, and industrialize security tools and processes within this new CI/CD pipeline, using templates that can be reused across the Group.MISSIONS: As part of the Software Factory team within the Application Security department, your main responsibilities will be: Security design and industrialization (Shift Left): Build and package the \"Application Security\" service offering as standardized GitLab CI templates reusable by all group projects. Integrate continuous security monitoring tools (SAST, DAST, SCA, secrets detection) directly into the GitLab workflow. Ensure the coordination and traceability of CI security results (GitLab) to the deployment and orchestration tools (XL Deploy, XL Release).Project Support and Guidance: Assist the group's development teams in adopting these new templates and integrating security into their sprints (false positive management, remediation). Write technical documentation, integration guides, and security best practice sheets for developers. Operational Maintenance and Improvement: Configure, test, execute, and monitor security pipelines to ensure their performance and prevent them from unduly blocking build chains (optimizing execution times).Profile and Skills Sought : Essential Technical Skills (Hard Skills): GitLab CI/CD Expertise: Proven experience in creating complex, managed, and shared CI/CD templates at enterprise scale (include mechanisms, component catalog, CI variables, etc.). Application Security Tools (AST): Operational experience with market solutions, including Checkmarx (SAST/SCA), Qualys WAS (DAST), or equivalents, and their integration via API or CLI into pipelines. DevOps & SDLC Ecosystem: Strong command of the legacy and target environment: GitLab, Jenkins, Bitbucket, XL Deploy, XL Release. Security-as-Code Culture: Ability to translate security compliance requirements into lines of code and automated configurations.Cross-functional skills (Soft Skills): Pedagogy and communication: Ability to explain security topics in simple terms to developers and to lead training sessions. Collaboration: Key role between the Application Security team and the Software Factory team. Rigor and writing skills: Ability to produce clear, structured, and easily actionable documentation.The deliverables are: Deployment and integration of SAST, SCA, and DAST solutions into the new CI platform; Implementation of Security by Design principles: authentication, traceability, SBOM management, Red Button processes, supply chain security, and security governanceTechnical Skills: • GitLab CI/CD – Expert – Essential • Application Security (AST) – Expert – Essential • DevOps & SDLC Ecosystem – Expert – Essential • Security-as-Code Culture – Confirmed – ImportantLanguage skills: Professional English (Essential) Proficiency with SAST, SCA, RASP, DAST tools... and vulnerability aggregatorsApplication: CV + cover letter + copies of diplomas to be sent to contact@keoni.frFounded in 2008, Kéoni Consulting is an IT consulting and engineering firm specializing in the banking, financial markets, insurance, and industrial sectors. We are the partner for major accounts in their digital transformation. We help them transform their business model, align their operational processes, select the best technologies, and mitigate and overcome the risks associated with digitalization. Kéoni Consulting helps companies to: Make a difference ; Innovate and create ; Reinvent their business ; Satisfy customers ; Gain a competitive advantage; Become the leader in their sector; Become the leader in your sector. Our activity covers the entire information systems lifecycle (Project Management, Business Analysis Consulting, Design, Implementation, Maintenance, Production, and Operation).**Job Category:** Digital Transformation**Job Type:** Full Time**Work location:** Europe