Senior Security Engineer

Kestra Technologies

Villeneuve-d'Ascq

À distance

EUR 85 000 - 120 000

Plein temps

14 jours+
Générateur de candidature

Une candidature sur mesure pour ce poste — un CV personnalisé et une lettre de motivation qui correspondent directement à l’offre.

Passez les filtres ATS

Avantages offerts par ce poste

Work from anywhere
Health coverage
Home office setup on us

Résumé du poste

Kestra Technologies is seeking a Senior Security Engineer to own the end-to-end security posture of our platform, infrastructure, and open-source ecosystem. This remote-first role combines hands-on security work with engineering delivery.

You will conduct pentesting, threat modeling, vulnerability management, and patch remediation while hardening our cloud infra and CI/CD pipelines. Ambitious, autonomous builders will thrive here.

Qualifications

  • 5+ years of experience in Security Engineering, DevSecOps, or related roles.
  • Strong hands-on penetration testing background.
  • Builder/fixer mindset: read code, understand exploits, and guide remediation.
  • Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker).
  • Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).
  • Fluent in English and able to work autonomously in a remote environment.
  • Adaptability to a fast-paced open-source startup environment.

Responsabilités

  • Conduct hands-on penetration testing and threat modeling across web apps, APIs, control plane, and cloud environments.
  • Manage end-to-end vulnerability tracking across codebases, dependencies, containers, and cloud infra.
  • Proactively fix security flaws by writing patches, PRs, or guiding remediation with product teams.
  • Audit and harden cloud infrastructure (GCP, Kubernetes, networking) against threats.
  • Automate security tooling into CI/CD pipelines (SAST, DAST, scanners) to catch CVEs before production.
  • Perform security code reviews and evaluate dependencies, open-source integrations, and supply-chain risks.
  • Lead incident response efforts and establish monitoring, detection, and mitigation strategies.
  • Own our public security posture as an open-source project: disclosures, CVEs, advisories.

Connaissances

Penetration testing
Threat modeling
Cloud security
Kubernetes / Docker
Open-source security / SCA
English fluency

Outils

Trivy
GitHub Security
Dependabot
Elastic Security
Docker
Kubernetes
Terraform
GCP
PostgreSQL
Elasticsearch
Redis
Kafka
AMQP
ELK
Prometheus
Grafana
GitHub Actions
ArgoCD

Description du poste

About Kestra

Kestra is the universal orchestration platform: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.

Trusted by over 10,000 organizations worldwide, including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars, hundreds of contributors, and a fast-growing global community.

About the role

Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise.
You would be our first dedicated security hire. We're looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.
This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.
This is a hands-on engineering role, not a GRC or compliance one.

What you would do

Your first six months would focus on the first three points below. The rest is where the role grows.

  • Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.

  • Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.

  • Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.

  • Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.

  • Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.

  • Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.

  • Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.

  • Own our public security posture as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem.

Our Tech Stack
  • Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security

  • Infrastructure: Docker, Kubernetes, Terraform

  • Cloud: GCP

  • Programming language: Java, Typescript, Javascript

  • Datastore: PostgreSQL, Elasticsearch

  • Queuing: Redis, Kafka, AMQP

  • Monitoring & Logs: ELK, Prometheus, Grafana

  • Deployment & Repository: GitHub Actions, ArgoCD

What we are looking for
  • 5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.

  • Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities.

  • A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.

  • Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker).

  • Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).

  • Fluent in English and comfortable working autonomously in a fully remote environment.

  • Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.

Perks & Benefits
  • Work from anywhere: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.

  • Health coverage: From medical support, dental, and vision, we've got you covered.

  • Home office setup on us: We’ll provide all the equipment you need to work comfortably.

Our Hiring Process

We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.

  • Intro call with the hiring manager (30 min)

  • Technical scenario / Practical assessment (2 hours, asynchronous homework focusing on threat assessment and remediation)

  • Team chat with one of your future colleagues (30 min)

  • Final discussion with one of our co-founders (30 min)

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Security Engineer — Hands-On, Remote, Open-Source
Senior Security Engineer — Hands-On, Remote, Open-Source

Kestra Technologies • Villeneuve-d'Ascq

À distance
EUR 85 000 - 120 000
Work from anywhere
Health coverage
Home office setup on us
Associate Security Engineer
Associate Security Engineer

Spendesk • Paris

Sur place
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2
Senior Security Engineer
Senior Security Engineer

Spendesk • Paris

Sur place
EUR 90 000 - 140 000
Full Stack Engineer, Data Orchestration
Full Stack Engineer, Data Orchestration

Kestra Technologies • Villeneuve-d'Ascq

Sur place
EUR 60 000 - 90 000
Ownership in distributed team
Exposure to product strategy
Health insurance
+2
Senior Security Engineer
Senior Security Engineer

Spendesk • Paris

Hybride
EUR 90 000 - 130 000
Senior Security Operations Engineer
Senior Security Operations Engineer

Lever, Inc. • France

À distance
EUR 70 000 - 110 000
Fully remote
Health benefits
Pension plan
+8
Senior DevSecOps Engineer (Offensive Security Focus)
Senior DevSecOps Engineer (Offensive Security Focus)

Neotrust • France

Sur place
EUR 60 000 - 80 000
Staff Security Engineer
Staff Security Engineer

Swile • Paris

Sur place
EUR 120 000 - 180 000
Head of Security
Head of Security

Spiko • Paris

Hybride
EUR 120 000 - 180 000
Stock options
Offices Paris & London
Remote work 2 days/wk
+5
Lead Security Researcher
Lead Security Researcher

Escape • Paris

Sur place
EUR 75 000 - 95 000
Significant equity
Top-tier health insurance
Meal vouchers
+5