DevSecOps Engineer

Capital Fund Management (CFM)

Paris

Sur place

EUR 70 000 - 120 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Capital Fund Management is seeking a software security automation engineer to design and implement automation that strengthens our security posture. You will report to the Director of Application Security and collaborate with the Information Security team as well as development, infrastructure, and operations across the firm.

The role focuses on building automation for identity governance integrations, secure API design, and reliable synchronization between cloud and on‑premises directory

Qualifications

  • Proficiency in Python backend development with web frameworks and asynchronous programming.
  • Hands-on experience designing, developing, documenting, and operating RESTful APIs with authentication.
  • Working knowledge of IAM/IGA concepts such as identities, roles, provisioning, aggregation, and lifecycle workflows.
  • Experience with at least one identity platform (e.g., SailPoint, Okta, Ping Identity, Keycloak).
  • Understanding of LDAP/AD fundamentals, including schemas, authentication and directory APIs.
  • Familiarity with secure credential management, audit logging, and data protection for identity data.
  • Solid software engineering practices: clean code, Git, unit testing, API documentation.
  • Familiar with secure coding practices including OWASP Top 10.
  • Ability to troubleshoot complex integration issues across APIs and identity platforms.
  • Hands-on experience with agentic coding tools (e.g., Claude Code).
  • Excellent written and verbal communication skills for security recommendations.

Responsabilités

  • Design, build, and maintain automation services integrating with IGA, directory services, and security systems via APIs.
  • Develop RESTful APIs and backend services in Python for identity aggregation, provisioning workflows, and group management.
  • Implement secure API authentication, authorization, rate-limiting, retries, and transformations for SaaS and enterprise integrations.
  • Support synchronization between cloud identity platforms and on‑premises or cloud directories, including conflict handling.
  • Collaborate with security, infrastructure, identity, and development teams to translate access-management requirements into scalable designs.
  • Produce clear technical documentation for APIs, workflows, and operational procedures.

Connaissances

Python backend
REST APIs
IAM/IGA concepts
Identity platforms
LDAP/AD basics
Secure credentials
Git & tests
OWASP Top10
Troubleshooting
Claude Code
Communication skills

Description du poste

Select how often (in days) to receive an alert:

Founded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients.
We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate experts in research, technology, and business to explore new ideas and challenge existing assumptions.

ABOUT THE ROLE

Are you passionate about software development and security? In this role, you’ll be instrumental in designing and implementing automation that is critical to our security posture. Reporting directly to the Director of Application Security, you will work collaboratively with the whole Information Security team as well as development, infrastructure, and operations teams across the company.


Overview & Key Responsibilities:

  • Design, build, and maintain automation services that integrate with an IGA (Identity Governance & Administration) platform, directory services, and security systems through well-documented APIs.
  • Develop RESTful APIs and backend services in Python to support identity aggregation, provisioning workflows, access profile management, and group membership automation.
  • Implement secure API authentication, authorization, rate-limit handling, retries, circuit breakers, and request/response transformations for SaaS and enterprise integrations.
  • Support reliable synchronization between cloud identity platforms and on-premises or cloud directory services, including conflict handling, consistency strategies, and failure recovery.
  • Partner with security, infrastructure, identity, and development teams to translate access-management requirements into scalable technical designs and maintainable production systems.
  • Produce clear technical documentation for APIs, workflows, operational procedures, and integration behaviors.

Minimum Qualifications:

  • Proficiency in Python backend development, including experience with web service frameworks and asynchronous or concurrent programming patterns.
  • Hands-on experience designing, developing, documenting, and operating RESTful APIs, including authentication, authorization, versioning, and contract management.
  • Working knowledge of IAM and IGA concepts such as identities, roles, access profiles, provisioning, aggregation, and lifecycle workflows.
  • Experience with at least one IGA or identity platform such as SailPoint, Saviynt, Okta, Ping Identity, Keycloak, or a comparable solution.
  • Understanding of LDAP, Active Directory, or Entra ID fundamentals, including schemas, authentication, group management, and directory APIs.
  • Familiarity with secure credential management, audit logging, data protection, and security controls for systems handling identity data.
  • Solid software engineering practices, including clean code, Git, unit testing, API documentation, and maintainable architectural patterns.
  • Familiar with secure coding best practices including but not limited to the OWASP Top 10.
  • Ability to troubleshoot complex integration issues across APIs, identity platforms, directory services, authentication flows, and authorization failures.
  • Hands-on experience with agentic coding tools such as Claude Code or Codex.
  • Excellent written and verbal communication skills, with proven ability to transform complex technical concepts into clear business and security recommendations.


Preferred Qualifications:

  • Experience with threat modeling or conducting comprehensive security audits is a plus.
  • Experience consuming and integrating third-party SaaS and Cloud APIs, including quota management, retry strategies, exponential backoff, and resilient failure handling.
  • Experience with Secret Managers such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or similar tools.
  • Knowledge of identity standards and protocols such such as OpenID Connect, OAuth, SAML, and SCIM.
  • Familiarity with microservices, API gateways, event-driven or batch processing patterns, distributed systems, and data pipeline design.
  • Experience with relational databases, SQL, caching strategies, indexing, and eventual consistency for performance-critical identity data queries.
  • DevSecOps experience, including CI/CD pipelines such as GitLab and Jenkins, Infrastructure as Code (Terraform, CloudFormation), integration testing, performance testing, containerization, and Linux scripting or administration.
  • Exposure to Kafka, provisioning connectors, web front-end development with React or Angular..
  • A passion for being informed about the latest security research, tools, and adversarial tactics, techniques and procedures — and applying that knowledge to improve enterprise security.
EQUAL OPPORTUNITIES STATEMENT


We are continuously striving to be an equal opportunity employer and we prohibit any discrimination based on sex, disability, origin, sexual orientation, gender identity, age, race, or religion. We believe that our diversity, breadth of experience, and multiple points of view are among the leading factors in our success.
CFM is a signatory of the Women Empowerment Principles .

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

DevSecOps Engineer
DevSecOps Engineer

London Stock Exchange Group • France

Sur place
EUR 65 000 - 85 000
Senior Security Operations Engineer
Senior Security Operations Engineer

Capital Fund Management (CFM) • Paris

Hybride
EUR 60 000 - 80 000
GenAI Security Engineer
GenAI Security Engineer

Capital Fund Management (CFM) • Paris

Sur place
EUR 75 000 - 95 000
DevSecOps Engineer
DevSecOps Engineer

LSEG • Paris

Sur place
EUR 50 000 - 70 000
Associate Security Engineer
Associate Security Engineer

Spendesk • Paris

Sur place
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2
Senior Security Engineer
Senior Security Engineer

Xpandium Coberon Ltd • Eu

Hybride
EUR 70 000 - 90 000
DevSecOps Engineer: IAM & API Automation
DevSecOps Engineer: IAM & API Automation

Capital Fund Management (CFM) • Paris

Sur place
EUR 70 000 - 120 000
Security Automation Engineer
Security Automation Engineer

Contentsquare • Paris

Hybride
EUR 42 000 - 60 000
Stock options
Lifestyle allowance
Generous paid time-off
+1
Security Consultant (DevSecOps)
Security Consultant (DevSecOps)

Palo Alto Networks, Inc. • Paris

Sur place
EUR 65 000 - 90 000
Security Consultant (DevSecOps)
Security Consultant (DevSecOps)

Palo Alto Networks • Paris

Sur place
EUR 70 000 - 100 000