Lead Offensive Security & Red Team

IDEMIA

Paris

On-site

EUR 120,000 - 180,000

Full time

18 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

IDEMIA Secure Transactions, a division of IDEMIA Group, is seeking an experienced Senior Offensive Security Lead in Paris to shape and execute the company’s offensive security program. You will lead testing, ROE development, and capability roadmaps while coordinating with security, IT, and product teams.

You will drive red-team engagements, adversary emulation, and automated testing, building AI-assisted capabilities and ensuring risk-based remediation with stakeholders across the enterprise.

Qualifications

  • 6–10 years of cybersecurity experience with hands-on offensive security, red teaming, or security research.
  • Ability to independently scope, design, and run complex engagements from hypothesis to retesting.
  • Strong depth in two areas such as AD/Entra ID, cloud, apps/APIs, containers, or Kubernetes.
  • Knowledge of MITRE ATT&CK, attack-path analysis, privilege escalation, and C2 concepts.

Responsibilities

  • Define and execute the offensive security strategy, testing plan, rules of engagement, and capability roadmap.
  • Lead red-team campaigns, adversary emulation, and testing across cloud, identity, apps, networks, and data centers.
  • Develop automated testing models and AI-assisted capabilities for faster validation of findings.
  • Translate technical findings into business risk and drive remediation with stakeholders.

Skills

Offensive security
Red team operations
Penetration testing
Adversary emulation
Python
MITRE ATT&CK
Cloud platforms
Security automation
Adversary tooling

Job description

Purpose

IDEMIA Secure Transactions, a division of IDEMIA Group, is the leading technology provider making it safer and easier to pay and connect. With unmatched expertise in cryptography and credential issuance, IST is trusted by over 2,000 financial institutions, mobile operators, automotive manufacturers, and IoT providers worldwide. Every day, IST secures billions of essential transactions, ensuring the highest levels of data protection and convenience.

Key Missions
  • Define and execute the Company’s offensive security strategy, annual testing plan, operating model, and capability roadmap.
  • Lead red-team campaigns, adversary emulation, penetration testing, attack-path analysis, and security-control validation across cloud, on-premises, identity, applications, networks, data centers, and production environments.
  • Prioritize offensive security activities based on business criticality, exposure, threat intelligence, technology changes, incidents, regulatory requirements, and emerging AI-enabled threats.
  • Develop a continuous and automated testing model to complement periodic assessments and enable faster validation of vulnerabilities, attack paths, and defensive controls.
  • Build and operationalize AI-assisted and agentic Red Team capabilities for reconnaissance, attack-hypothesis generation, attack-path discovery, adversary simulation, testing automation, controlled exploit validation, campaign orchestration, analysis, and reporting.
  • Evaluate emerging AI-enabled offensive security technologies and determine where they can safely improve testing coverage, efficiency, and quality.
  • Lead Purple Team activities with the Cybersecurity Defense Center and ensure offensive findings translate into improved detections, investigation procedures, SOC playbooks, vulnerability prioritization, architecture improvements, and stronger defensive controls.
  • Define and maintain rules of engagement, authorization, safety controls, confidentiality requirements, escalation paths, and production safeguards for offensive activities.
  • Translate technical findings into clear business risks and drive material findings through remediation, retesting, risk treatment, or escalation.
  • Manage and optimize the use of external penetration-testing and Red Team providers, progressively internalizing and automating repeatable activities to improve responsiveness, quality, and cost efficiency.
  • Build and maintain the offensive security toolchain, laboratories, controlled testing environments, and automation capabilities.
  • Support critical projects, cloud transformations, new production environments, and major technology changes through targeted offensive security validation.
  • Support major cyber incidents when required through attack reconstruction, compromise-path analysis, exposure validation, and lessons learned.
  • Develop the technical capability and autonomy of the Offensive Security team through coaching, knowledge sharing, and practical technical exercises.
  • Produce meaningful KPIs/KRIs covering testing coverage, findings, remediation, Purple Team outcomes, provider performance, control improvements, and business value.
Profile & Other Information
Experience & technical skills
  • 6–10 years of relevant cybersecurity experience, including substantial hands‑on experience in offensive security, red teaming, penetration testing, adversary simulation, or security research.
  • Ability to independently scope, design, and execute complex offensive-security engagements from attack hypothesis and rules of engagement through execution, reporting, remediation, and retesting.
  • Strong technical depth in at least two areas such as Active Directory / Entra ID, cloud platforms, applications and APIs, endpoint and network infrastructure, containers, or Kubernetes.
  • Practical knowledge of MITRE ATT&CK, attack-path analysis, privilege escalation, lateral movement, persistence, command-and‑control concepts, operational security, and detection‑aware testing.
  • Ability to develop, adapt, and automate offensive-security capabilities using Python and at least one additional language or scripting environment such as PowerShell, Bash, Go, C#, Rust, or equivalent.
  • Experience with adversary‑emulation tooling, offensive-security infrastructure, controlled laboratories, and testing automation.
  • Demonstrated interest or experience in AI‑assisted security testing, LLMs, tool‑using agents, agentic workflows, or automated security research.
  • Ability to translate technical findings into business‑relevant risk and communicate effectively with technical teams, operational stakeholders, and senior management.
  • Strong understanding of safe‑testing practices, rules of engagement, confidentiality, evidence handling, production safeguards, and escalation.
Leadership profile
  • Strong player‑coach mindset: able to lead complex technical engagements while remaining directly involved when needed.
  • Autonomous, pragmatic, curious, and comfortable challenging traditional approaches.
  • Able to mentor practitioners, coordinate specialist providers, and build new capabilities in a fast‑evolving threat environment.
  • Strong learning agility and interest in how AI and automation are reshaping offensive security.
Preferred
  • Experience in cloud‑native, identity‑centric, payment, telecom, data‑center, or other business‑critical environments.
  • Experience testing AI‑enabled applications, RAG systems, LLMs, or autonomous agents.
  • Evidence of continuous technical learning through research, open‑source contributions, CTFs, bug bounty, CVEs, publications, or security‑community involvement.Certifications such as OSCP, OSEP, OSCE3, CRTO, CRTE, GXPN, GPEN, or equivalent are valued but not mandatory.

At IST, we believe in an inclusive environment where every talent can thrive. We welcome applicants from all backgrounds, identities, and abilities. If you require any accommodation during the process, let us know.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Offensive Security & Red Team
Lead Offensive Security & Red Team

IDEMIA • Courbevoie

On-site
EUR 90,000 - 130,000
Offensive Security Engineer
Offensive Security Engineer

Jobgether SRL • France

Remote
EUR 90,000 - 150,000
Competitive compensation with equity
Remote-first environment
Career growth
+3
Snr Penetration Tester - IT/OT
Snr Penetration Tester - IT/OT

integrity360 • Paris

On-site
EUR 55,000 - 75,000
Head of Red Team & Offensive Security
Head of Red Team & Offensive Security

IDEMIA • Courbevoie

On-site
EUR 90,000 - 130,000
Senior Red Team & Offensive Security Lead
Senior Red Team & Offensive Security Lead

IDEMIA • Paris

On-site
EUR 120,000 - 180,000
Senior Security Operations Engineer
Senior Security Operations Engineer

Jobgether SRL • France

On-site
EUR 70,000 - 110,000
Fully remote
Health benefits
Pension plan
+8
Prinicipal (L3) SOC Analyst
Prinicipal (L3) SOC Analyst

Integrity360 • Paris

On-site
EUR 65,000 - 95,000
Senior DevSecOps Engineer (Offensive Security Focus)
Senior DevSecOps Engineer (Offensive Security Focus)

Neotrust • France

On-site
EUR 60,000 - 80,000
Prinicipal (L3) SOC Analyst
Prinicipal (L3) SOC Analyst

Integrity360 • Paris

On-site
EUR 70,000 - 110,000
Lead Vulnerability Intelligence Analyst
Lead Vulnerability Intelligence Analyst

Jobgether SRL • France

On-site
EUR 110,000 - 150,000
Competitive compensation
Remote-friendly culture
Wellness programs
+6