Appsec/DevSecOps Security Expert – Level 4

Keoni

France

Hybride

EUR 65 000 - 90 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

N’envoyez pas de CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.

Passez les filtres ATS

Résumé du poste

Keoni Consulting seeks a Senior DevSecOps Specialist to drive security-embedded CI pipelines in a major transformation program. You will design reusable GitLab CI templates, integrate SAST/DAST/ SCA tools, and ensure traceability to deployment tools while helping teams adopt secure practices.

You will author integration guides, coach developers, and optimize pipelines for performance, reliability, and compliance across the project portfolio.

Qualifications

  • GitLab CI/CD – Expert, able to design complex enterprise templates.
  • Operational experience with AST tools (SAST/SCA/DAST) and API/CLI integration.
  • Strong command of GitLab/Jenkins/Bitbucket XL Deploy/XL Release in SDLC ecosystems.
  • Experience translating security requirements into code and automated configs.

Responsabilités

  • Deploy and integrate SAST, SCA, DAST into the new CI platform.
  • Industrialize security templates and SBOM management within pipelines.
  • Provide guidance and training to development teams on secure CI practices.

Connaissances

GitLab CI/CD
Application Security Tools
DevOps & SDLC Ecosystem
Security-as-Code Culture

Outils

Checkmarx
Qualys WAS

Description du poste

Context Overall objective: To support the implementation of a new Continuous Integration (CI) platform and the integration of security controls.Key project constraint: Addressing security risks. As part of a cross-functional program to streamline and modernize its continuous integration (CI) and source code management tools (migrating thousands of Jenkins/Bitbucket projects to GitLab), the client is building its new software factory. The main objective of the mission is to integrate, automate, and industrialize security tools and processes within this new CI/CD pipeline, using templates that can be reused across the Group.MISSIONS: As part of the Software Factory team within the Application Security department, your main responsibilities will be: Security design and industrialization (Shift Left): Build and package the \"Application Security\" service offering as standardized GitLab CI templates reusable by all group projects. Integrate continuous security monitoring tools (SAST, DAST, SCA, secrets detection) directly into the GitLab workflow. Ensure the coordination and traceability of CI security results (GitLab) to the deployment and orchestration tools (XL Deploy, XL Release).Project Support and Guidance: Assist the group's development teams in adopting these new templates and integrating security into their sprints (false positive management, remediation). Write technical documentation, integration guides, and security best practice sheets for developers. Operational Maintenance and Improvement: Configure, test, execute, and monitor security pipelines to ensure their performance and prevent them from unduly blocking build chains (optimizing execution times).Profile and Skills Sought : Essential Technical Skills (Hard Skills): GitLab CI/CD Expertise: Proven experience in creating complex, managed, and shared CI/CD templates at enterprise scale (include mechanisms, component catalog, CI variables, etc.). Application Security Tools (AST): Operational experience with market solutions, including Checkmarx (SAST/SCA), Qualys WAS (DAST), or equivalents, and their integration via API or CLI into pipelines. DevOps & SDLC Ecosystem: Strong command of the legacy and target environment: GitLab, Jenkins, Bitbucket, XL Deploy, XL Release. Security-as-Code Culture: Ability to translate security compliance requirements into lines of code and automated configurations.Cross-functional skills (Soft Skills): Pedagogy and communication: Ability to explain security topics in simple terms to developers and to lead training sessions. Collaboration: Key role between the Application Security team and the Software Factory team. Rigor and writing skills: Ability to produce clear, structured, and easily actionable documentation.The deliverables are: Deployment and integration of SAST, SCA, and DAST solutions into the new CI platform; Implementation of Security by Design principles: authentication, traceability, SBOM management, Red Button processes, supply chain security, and security governanceTechnical Skills: • GitLab CI/CD – Expert – Essential • Application Security (AST) – Expert – Essential • DevOps & SDLC Ecosystem – Expert – Essential • Security-as-Code Culture – Confirmed – ImportantLanguage skills: Professional English (Essential) Proficiency with SAST, SCA, RASP, DAST tools... and vulnerability aggregatorsApplication: CV + cover letter + copies of diplomas to be sent to contact@keoni.frFounded in 2008, Kéoni Consulting is an IT consulting and engineering firm specializing in the banking, financial markets, insurance, and industrial sectors. We are the partner for major accounts in their digital transformation. We help them transform their business model, align their operational processes, select the best technologies, and mitigate and overcome the risks associated with digitalization. Kéoni Consulting helps companies to: Make a difference ; Innovate and create ; Reinvent their business ; Satisfy customers ; Gain a competitive advantage; Become the leader in their sector; Become the leader in your sector. Our activity covers the entire information systems lifecycle (Project Management, Business Analysis Consulting, Design, Implementation, Maintenance, Production, and Operation).**Job Category:** Digital Transformation**Job Type:** Full Time**Work location:** Europe
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Application Security/AppSec Team Lead – DevSecOps
Application Security/AppSec Team Lead – DevSecOps

Demartino Law • France

Sur place
EUR 90 000 - 140 000
Operational Security Engineer – Openshift and Container Security – Level 4
Operational Security Engineer – Openshift and Container Security – Level 4

Keoni • Paris

Hybride
EUR 90 000 - 130 000
Agile Coach – DevSecOps – N4
Agile Coach – DevSecOps – N4

Keoni • Paris

Hybride
EUR 90 000 - 120 000
Security Project Management – Security Solutions Integration – Level 3
Security Project Management – Security Solutions Integration – Level 3

Demartino Law • Paris

Sur place
EUR 55 000 - 75 000
DevOps / DevSecOps – Senior
DevOps / DevSecOps – Senior

Keoni • Paris

Hybride
EUR 75 000 - 105 000
Senior AppSec & DevSecOps Engineer - GitLab CI/CD Expert
Senior AppSec & DevSecOps Engineer - GitLab CI/CD Expert

Keoni • France

Hybride
EUR 65 000 - 90 000
Technical Expert Platform As A Service (Openshift & Kubernetes)
Technical Expert Platform As A Service (Openshift & Kubernetes)

Demartino Law • Paris

Sur place
EUR 90 000 - 130 000
AI Expert – DevSecOps
AI Expert – DevSecOps

Keoni • Paris

Hybride
EUR 90 000 - 130 000
Project Manager (Business Analyst) – IT Project Management
Project Manager (Business Analyst) – IT Project Management

Keoni • France

Hybride
EUR 60 000 - 90 000
Expert DevSecOps / Sécurité Applicative
Expert DevSecOps / Sécurité Applicative

SmartRecruiters, Inc. • Paris

Hybride
EUR 65 000 - 95 000