Aller au contenu principal
Capital Fund Management recrutement

Application Security Engineer H/F Capital Fund Management

  • Paris 7e - 75
  • CDI
  • Télétravail occasionnel
  • Bac +5
  • Banque • Assurance • Finance
  • Exp. 4 ans min.
Lire dans l'app

Les missions du poste

ABOUT THE ROLE

Are you passionate about application security and ready to serve as a subject matter expert in both application security andsecuring thesoftwaredevelopmentlifecycle? In this role,you'llbe instrumental in protecting our low-latency processing systems and trading platforms across diverse environments. Reporting directly to theDirector of Application Security, you will work collaboratively with development, infrastructure, and operations teams to embed security into every phase of ourprocess and in the company culture.

Overview & Key Responsibilities:

- Serve as the internal point of reference and Subject Matter Expert on application security and software factory security.

- Design, implement, andmaintainthe essential tools to ensure secure CI/CD pipelines with robust security controls including automated testing,secretsdetection,compliance checks, software composition analysis, and vulnerability management.

- Supportour development teamsin addressing identifiedfindings, ensuringcompliance withsecure coding practicesto align withindustry standardsforboth cloud and on-premisesenvironments, andpromotea culture ofongoingsecurityenhancement.

- Participate indesign reviews, threat modeling, and architecture assessments to proactivelyidentifyand mitigate security risks in new and existing solutions.

- Work with our Core and Architecture team toestablishand enforcesolutionsfor encryption, authentication (both human and machine), access control (role- and attribute-based), secret management, and secure configurations in cloud (AWS, GCP, or Azure) as well as on-premises environments.

- Develop, monitor, and report indicators to track security performance and drive continuous improvement.

Profile description:

Minimum Qualifications:

- Bachelor's degree (or equivalent practical experience) in Computer Science, Information Security, ora relatedfield.

- A minimum of4years of hands-on experience in application security, with provenexpertisesecuring modern architectures-including cloud environments, containerized applications, serverless platforms, APIs, and traditional on-premises systems.

- Hands-on experience with security testing tools (e.g., SAST,DAST, IAST, SCA, SBOM...)

- Ability to design, configure,implement,andmaintainthesetools as part ofproductionCI/CD pipelines, ensuringaccuratevulnerability detection, low noise, and minimal impact on deployment speed and stability.

- Ability to design, configure, implement, andmaintainthese tools as part ofproductionCI/CD pipelines, ensuringaccuratevulnerability detection, low noise, and minimal impact on deployment speed and stability.Demonstrableexperience implementing and managing secure CI/CD pipelines and integratingDevSecOpspractices.

- Proficiencyin Linux environments, networking protocols (TCP/IP, UDP, HTTP, HTTPS), andmicroservicesarchitectures.

- Expert onauthentication and authorization protocols including but not limited to SAML, OAuth2, OpenIDConnect.

- Strong coding skillsinPython with the ability to read, analyze, and communicate code vulnerabilities to both technical and non-technical audiences.

- Clear understanding ofweb developmentfundamentalslike REST APIs, cookies, same-originpolicy, cross-origin resourcesharingetc.

- Familiarity with common security frameworks and methodologies (e.g., OWASP Top 10, NIST SSDF).

- Excellent written and verbal communication skills, with proven ability to transform complex technical concepts into clear business and security recommendations.

Preferred Qualifications:

- An advanced certification such as Certified Secure Software Lifecycle Professional (CSSLP) is highly desirable.

- Demonstratedexpertisein cloud security across AWS, GCP, or Azure, and extensive experience securing on-premises systems to ensure a cohesive security posture across all environments.

- Strong background in implementing and managing Infrastructure as Code (IaC) and automation tools (e.g., Terraform, Ansible, CloudFormation).

- Experience with threat modelingorconducting comprehensive security auditsis a plus.

CAPITAL FUND MANAGEMENT S. A.

Publiée le 23/12/2025 - Réf : CFM_bJ71p1O

Application Security Engineer H/F

Capital Fund Management
  • Paris 7e - 75
  • CDI
Publiée le 23/12/2025 - Réf : CFM_bJ71p1O

Finalisez votre candidature

sur le site du recruteur

Créez votre compte pour postuler

sur le site du recruteur !

Ces offres pourraient aussi
vous intéresser

Dassault Systèmes recrutement
Voir l’offre
il y a 13 jours
Cybermaker recrutement
Saint-Cloud - 92
CDI
40 000 - 65 000 € / an
Télétravail occasionnel
Voir l’offre
il y a 3 jours
Colas SA recrutement
Vélizy-Villacoublay - 78
CDI
Voir l’offre
il y a 3 jours
Voir plus d'offres
Initialisation…
Les sites
L'emploi
  • Offres d'emploi par métier
  • Offres d'emploi par ville
  • Offres d'emploi par entreprise
  • Offres d'emploi par mots clés
L'entreprise
  • Qui sommes-nous ?
  • On recrute
  • Accès client
Les apps
Application Android (nouvelle fenêtre) Application ios (nouvelle fenêtre)
Nous suivre sur :
Informations légales CGU Politique de confidentialité Gérer les traceurs Accessibilité : non conforme Aide et contact