Senior DevSecOps Engineer (Offensive Security Focus)

Neotrust

France

Hybride

EUR 60 000 - 80 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

A cybersecurity firm is seeking a Senior DevSecOps Engineer to enhance application security across the SDLC. The ideal candidate will have extensive experience in penetration testing and secure coding practices, alongside strong DevSecOps knowledge. This role supports automation and security integration in cloud-native environments, offering the flexibility of a hybrid or remote work arrangement. Experience with Azure Cloud and tools like Snyk is preferred.

Qualifications

  • Strong track record in application penetration testing (OWASP Top 10, API attacks).
  • Deep knowledge of authentication protocols (OAuth2, OIDC).
  • Experience in Azure Cloud services.

Responsabilités

  • Perform targeted penetration tests on various applications.
  • Conduct threat modeling and adversarial analysis.
  • Automate security controls in CI/CD pipelines.

Connaissances

Application penetration testing
Secure coding
Manual exploitation techniques
DevSecOps architecture
Analytical thinking

Outils

Azure
Snyk
Docker
Kubernetes

Description du poste

Senior DevSecOps Engineer (Offensive Security Focus)
Helps Executives, CISO and CIO to successfully complete their security transformation journey

Job Description — Senior DevSecOps Engineer (Offensive Security Focus)

Location: Hybrid (Paris) or Remote (France/Europe)

Department: Cybersecurity / DevSecOps

Seniority: Senior / Expert

Duration: 1 year (renewable)

Contract: Full-time (Freelance)

We’re looking for a Senior DevSecOps Engineer with a strong Offensive Security mindset to elevate our application security across the full SDLC. You’ll combine hands‑on penetration testing skills with modern DevSecOps practices to find real‑world risks, automate security controls, and help engineering teams ship secure software faster.

You’ll work closely with developers, cloud/platform teams, and architects to integrate security into CI/CD, strengthen cloud‑native workloads, and build a strong secure engineering culture.

What you’ll do
Offensive Security / Application Security
  • Perform targeted penetration tests on web, API, mobile, and cloud‑native applications.
  • Conduct threat modeling and adversarial analysis on critical services.
  • Identify, exploit, and validate vulnerabilities to assess real impact and exploitability.
  • Perform secure code reviews (manual and tooling/AI‑assisted).
DevSecOps Integration
  • Improve SAST, SCA, DAST, IaC, and container scanning in Azure DevOps pipelines (Snyk experience is a major plus).
  • Automate security gates and enforce quality thresholds in CI/CD.
  • Build custom security checks, scripts, and DevSecOps automations.
  • Improve developer workflows by providing secure coding guidance and actionable fixes.
  • Run security reviews for new applications and major releases.
  • Support Security Champions and coach development teams.
  • Participate in incident response and post‑mortems for security issues.
  • Collaborate with Cloud Security on posture management and remediation.
Security Automation & AI
  • Develop or tune AI agents to support vulnerability analysis and remediation.
  • Automate correlation of findings across tools (SAST/SCA/Cloud).
  • Contribute to internal security dashboards and metrics (Power BI, API integrations).
What we’re looking for
Required experience
  • Strong track record in application penetration testing (OWASP Top 10, API attacks, auth bypass, RCE, business logic flaws).
  • Strong understanding of secure coding (C#, Java, JS/TS, Python, etc.).
  • Familiarity with DAST tools plus manual exploitation techniques.
  • Deep knowledge of authN/authZ (OAuth2, OIDC, JWT).
  • Strong grasp of DevSecOps architecture and SDLC best practices.

Hands‑on experience with:

  • Azure Cloud (App Services, Functions, IAM, Storage, Key Vault)
  • Container security (Docker, Kubernetes basics)
  • Snyk (SAST/SCA/IaC/Cloud) (highly valued)
Tooling & frameworks
  • Threat modeling methods (MITRE ATT&CK, STRIDE).
  • Source code review with or without tooling.
  • Ability to challenge designs and architectures from an attacker’s POV.
  • Clear communication with technical and non‑technical stakeholders.
  • Strong ownership, mentoring mindset, and leadership on security topics.
  • Analytical thinking, problem‑solving, pragmatism.
Nice to have
  • Certifications (preferred, not required): OSWE / OSCP / OSEP / GWAPT, AZ-500 / AZ-400 or similar.
  • Experience in large enterprise environments.
  • Experience with AI‑assisted AppSec tooling and workflows.
  • High‑impact role with real ownership over AppSec and DevSecOps practices.
  • Modern cloud‑native stack (Azure) and a strong focus on automation.
  • Opportunity to blend offensive security with engineering enablement and AI‑powered security.
Seniority level

Mid‑Senior level

Employment type

Full‑time

Job function

Consulting and Engineering

Industries

Computer and Network Security and Software Development

Referrals increase your chances of interviewing at Neotrust by 2x

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Senior Security Engineer
Senior Security Engineer

Xpandium Coberon Ltd • Eu

Hybride
EUR 70 000 - 90 000
Senior Security Engineer
Senior Security Engineer

Spendesk • Paris

Sur place
EUR 90 000 - 140 000
Senior Offensive DevSecOps Engineer: AppSec & Automation
Senior Offensive DevSecOps Engineer: AppSec & Automation

Neotrust • France

Hybride
EUR 60 000 - 80 000
Associate Security Engineer
Associate Security Engineer

Spendesk • Paris

Sur place
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2
DevSecOps Engineer
DevSecOps Engineer

London Stock Exchange Group • France

Sur place
EUR 65 000 - 85 000
Senior Security Engineer
Senior Security Engineer

Adrixis • Paris

Sur place
EUR 90 000 - 130 000
Senior Security Engineer - freelance
Senior Security Engineer - freelance

Netcompany • France

Sur place
EUR 65 000 - 90 000
Diverse working environment
Opportunity for professional growth
Senior Security Engineer - freelance
Senior Security Engineer - freelance

Netcompany Group • Strasbourg

Sur place
EUR 65 000 - 90 000
Freelance Senior Security Engineer (onsite)
Freelance Senior Security Engineer (onsite)

Netcompany • Strasbourg

Sur place
EUR 120 000 - 160 000
Senior Security Operations Engineer
Senior Security Operations Engineer

Capital Fund Management (CFM) • Paris

Hybride
EUR 60 000 - 80 000