You will join our IT team — five people including you — which handles both the build and the run of our entire infrastructure, over 300 machines across a genuinely varied environment. It's a small, enthusiastic team where everyone has real ownership of their subjects.
As a Cloud & Security IT Engineer, you will own our Microsoft 365 environment and drive our security and compliance practices forward. There is real room to grow how we use the platform, so you'll have a genuine say in what we deploy and how we structure it.
Your main responsibilities will include:
Own our Microsoft 365 platform
- Take end-to-end ownership of our tenant — administration, configuration, governance, and day-to-day reliability.
- Expand the platform's reach: information protection, device management, collaboration governance, and more.
- Keep our licensing rational and our costs under control.
Strengthen our security and compliance foundation (ISO 27001, NIS2)
- Put in place the tooling that keeps our fleet patched, monitored, and consistently configured — including endpoint protection, where you'll have a real say in what we choose.
- Harden our environments against recognized security baselines and drive remediation of the gaps you find.
- Translate framework requirements into technical controls — access control, logging, encryption, backup verification — and implement them yourself. This is a hands-on role: expect to spend most of your time building, not coordinating.
- Act as our technical point of contact for internal reviews and external audits.
Share in keeping our infrastructure running
- Take part in our rotating \"watchman\" duty — roughly one to one and a half days a week per person — covering first-line support and daily operations. The rotation protects everyone's focus time for the rest of the week.
- It's also hands-on exposure to the full breadth of our environment: Linux and Windows systems, virtualization, storage, networking.
What we are looking for:
Technical skills:
- Real hands-on experience administering Microsoft 365 in a business environment — this is the heart of the role.
- Practical command of security engineering: hardening, access control, patching, endpoint protection — you've configured these things, not just specified them.
- Experience contributing to a security or compliance program (ISO 27001, NIS2, SOC 2, or similar), where you implemented the controls yourself rather than only tracking them.
- Comfort working across a mixed fleet of Windows, macOS, and Linux systems.
Nice to have:
- Linux environments and infrastructure.
- Identity providers such as Okta, Entra ID, or Active Directory.
- Enterprise backup tooling (we use Commvault), endpoint management, or SIEM/EDR platforms.
- An interest in AI tools and how to deploy them safely across an organization.
- Certifications such as MS-102, SC-300, or SC-400 — welcome, but no substitute for practical experience.
Profile:
- Bachelor's to master's degree (Bac+3 to 5) in computer science or a related field.
- 5+ years of experience in IT, ideally as the reference owner of a Microsoft 365 environment rather than one contributor among several.
- Technical English required, alongside French for day-to-day work.
- A builder's mindset: you'd rather fix something than raise a ticket about it.
- A genuine security instinct — you notice weak configurations and fix them without being asked.
- Autonomy, rigor, and pragmatism: our engineers are demanding users, and the best security measure is the one people actually accept.
- Clear communication with technical and non-technical colleagues alike.
Of course, you might not have all of those required skills! But feel free to apply anyway and explain to us why you believe you are the right person for the job.
Contract information:
- Type of contract: Permanent contract
- Starting date: As soon as possible
What we can offer you:
- Competitive salary & performance-based RSU (free shares)
- Hybrid work model
- Additional paid leave (RTT)
- Sustainable mobility incentives
- Generous paternity leave
- Monthly team activities (laser game, hiking, sailing, karaoke …) and large-scale company events
Recruitment process:
- First interview with the line manager
- Second interview with the team
- Final interview with HRD or CEO
Equal Opportunity Statement:
KALRAY is committed to creating a diverse and inclusive environment, and we welcome applications from individuals of all backgrounds, identities, and experiences. We do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, skin color, national origin, gender, sexual orientation, age, marital status, disability status, or any other characteristic protected by law. Should you require any accommodations or adjustments throughout the interview process and beyond, please do not hesitate to let us know. We are committed to ensuring that all candidates have an equal opportunity to showcase their abilities and succeed in our organization.