Devsecops Engineer

Capital Fund Management (CFM)

Paris

Sur place

EUR 70 000 - 110 000

Plein temps

Il y a 6 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature sur mesure pour ce poste — un CV et une lettre de motivation personnalisés qui correspondent à l’offre.

Passez les filtres ATS

Résumé du poste

Capital Fund Management (CFM) is seeking a software security engineer focused on automation and IAM/IGA integrations. You will design and implement backend services in Python, develop RESTful APIs, and ensure secure authentication and authorization across cloud and on‑prem identity platforms.

You will partner with security, infrastructure, and development teams to translate access-management requirements into scalable solutions, while producing comprehensive technical documentation for APIs and

Qualifications

  • Proficiency in Python backend development with web frameworks and async patterns.
  • Experience designing, documenting, and operating RESTful APIs with authentication and authorization.
  • Working knowledge of IAM/IGA concepts: identities, roles, provisioning, aggregation, lifecycle workflows.
  • Experience with at least one identity platform (SailPoint, Okta, Ping, Keycloak) or comparable solution.
  • Understanding LDAP/AD fundamentals and directory APIs.
  • Familiarity with secure credential management, audit logging, and data protection for identity data.
  • Solid software practices: clean code, Git, unit tests, API documentation.
  • Familiarity with OWASP Top 10 security practices.
  • Ability to troubleshoot complex API identity integration issues.
  • Experience with agentic coding tools (Claude Code, Codex)
  • Excellent communication skills for translating technical concepts into business security recommendations.

Responsabilités

  • Design, build, and maintain automation services integrating with IAM/IGA and directory services.
  • Develop Python backend services to support identity provisioning and group automation.
  • Implement secure API authentication, authorization, rate limiting, and retries for SaaS and on‑premise integrations.
  • Ensure reliable synchronization between cloud and on‑premises identity platforms and directory services.
  • Collaborate with security, infra, identity, and dev teams to translate access requirements into scalable designs.
  • Produce clear API and workflow documentation for production use.

Connaissances

Python backend
RESTful APIs
IAM/IGA concepts
Identity platforms
LDAP/AD basics
Secure coding (OWASP)
Git & CI/CD
API security
Troubleshooting complex integrations
Claude Code or Codex tooling

Outils

SailPoint
Okta
Keycloak
HashiCorp Vault/OpenID Connect/OAuth/SAML/SCIM

Description du poste

Founded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients.


We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate experts in research, technology, and business to explore new ideas and challenge existing assumptions.


ABOUT THE ROLE

Are you passionate about software development and security? In this role, you’ll be instrumental in designing and implementing automation that is critical to our security posture. Reporting directly to the Director of Application Security, you will work collaboratively with the whole Information Security team as well as development, infrastructure, and operations teams across the company.


Overview & Key Responsibilities:


  • Design, build, and maintain automation services that integrate with an IGA (Identity Governance & Administration) platform, directory services, and security systems through well-documented APIs.

  • Develop RESTful APIs and backend services in Python to support identity aggregation, provisioning workflows, access profile management, and group membership automation.

  • Implement secure API authentication, authorization, rate-limit handling, retries, circuit breakers, and request/response transformations for SaaS and enterprise integrations.

  • Support reliable synchronization between cloud identity platforms and on-premises or cloud directory services, including conflict handling, consistency strategies, and failure recovery.

  • Partner with security, infrastructure, identity, and development teams to translate access-management requirements into scalable technical designs and maintainable production systems.

  • Produce clear technical documentation for APIs, workflows, operational procedures, and integration behaviors.


Minimum Qualifications:


  • Proficiency in Python backend development, including experience with web service frameworks and asynchronous or concurrent programming patterns.

  • Hands-on experience designing, developing, documenting, and operating RESTful APIs, including authentication, authorization, versioning, and contract management.

  • Working knowledge of IAM and IGA concepts such as identities, roles, access profiles, provisioning, aggregation, and lifecycle workflows.

  • Experience with at least one IGA or identity platform such as SailPoint, Saviynt, Okta, Ping Identity, Keycloak, or a comparable solution.

  • Understanding of LDAP, Active Directory, or Entra ID fundamentals, including schemas, authentication, group management, and directory APIs.

  • Familiarity with secure credential management, audit logging, data protection, and security controls for systems handling identity data.

  • Solid software engineering practices, including clean code, Git, unit testing, API documentation, and maintainable architectural patterns.

  • Familiar with secure coding best practices including but not limited to the OWASP Top 10.

  • Ability to troubleshoot complex integration issues across APIs, identity platforms, directory services, authentication flows, and authorization failures.

  • Hands-on experience with agentic coding tools such as Claude Code or Codex.

  • Excellent written and verbal communication skills, with proven ability to transform complex technical concepts into clear business and security recommendations.


Preferred Qualifications:


  • Experience with threat modeling or conducting comprehensive security audits is a plus.

  • Experience consuming and integrating third-party SaaS and Cloud APIs, including quota management, retry strategies, exponential backoff, and resilient failure handling.

  • Experience with Secret Managers such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or similar tools.

  • Knowledge of identity standards and protocols such as OpenID Connect, OAuth, SAML, and SCIM.

  • Familiarity with microservices, API gateways, event-driven or batch processing patterns, distributed systems, and data pipeline design.

  • Experience with relational databases, SQL, caching strategies, indexing, and eventual consistency for performance-critical identity data queries.

  • DevSecOps experience, including CI/CD pipelines such as GitLab and Jenkins, Infrastructure as Code (Terraform, CloudFormation), integration testing, performance testing, containerization, and Linux scripting or administration.

  • Exposure to Kafka, provisioning connectors, web front-end development with React or Angular..

  • A passion for being informed about the latest security research, tools, and adversarial tactics, techniques and procedures — and applying that knowledge to improve enterprise security.


EQUAL OPPORTUNITIES STATEMENT

We are continuously striving to be an equal opportunity employer and we prohibit any discrimination based on sex, disability, origin, sexual orientation, gender identity, age, race, or religion. We believe that our diversity, breadth of experience, and multiple points of view are among the leading factors in our success.


CFM is a signatory of the Women Empowerment Principles.


FOLLOW US

Follow us on Twitter or LinkedIn or visit our website to find out more about CFM.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

DevSecOps Engineer
DevSecOps Engineer

Capital Fund Management (CFM) • Paris

Sur place
EUR 70 000 - 120 000
Senior Security Operations Engineer
Senior Security Operations Engineer

Capital Fund Management (CFM) • Paris

Hybride
EUR 60 000 - 80 000
IAM-Focused DevSecOps Engineer • Python & API Automation
IAM-Focused DevSecOps Engineer • Python & API Automation

Capital Fund Management (CFM) • Paris

Sur place
EUR 70 000 - 110 000
Senior Software Engineer
Senior Software Engineer

Capital Fund Management (CFM) • Paris

Sur place
EUR 60 000 - 80 000
Senior platform Engineer - Portfolio Construction
Senior platform Engineer - Portfolio Construction

Capital Fund Management (CFM) • Paris

Hybride
EUR 90 000 - 130 000
Senior platform Engineer - Portfolio Construction
Senior platform Engineer - Portfolio Construction

Capital Fund Management (CFM) • Paris

Hybride
EUR 120 000 - 180 000
Hybrid work environment
Hands-on ownership on a technical core
Small, high-caliber team
GenAI Security Engineer
GenAI Security Engineer

Capital Fund Management (CFM) • Paris

Sur place
EUR 75 000 - 95 000
DevSecOps Engineer
DevSecOps Engineer

London Stock Exchange Group • France

Sur place
EUR 65 000 - 85 000
Data Reliability Engineer & Support
Data Reliability Engineer & Support

Capital Fund Management (CFM) • Paris

Sur place
EUR 85 000 - 110 000
ML platform Engineer
ML platform Engineer

Capital Fund Management (CFM) • Paris

Hybride
EUR 90 000 - 130 000