CyberSecurity Engineer, DevSecOps
Remote • Paris • Full-time
Posted 4mo ago
Job Location
Paris
Tech Stack
Remote Work Policy
Fully remote
Employment Type
Full-time
Categories
AI Infrastructure Engineer
About the job
Mistral AI is seeking a DevSecOps Engineer to architect and maintain the security of its rapidly scaling AI infrastructure and application lifecycle. The role involves treating security as a seamless enabler for research and engineering teams, embedding robust security controls into CI/CD pipelines, infrastructure, and developer workflows without compromising deployment velocity. The company is a dynamic, collaborative team passionate about AI, democratizing it through open-source models and products, and aims to make a meaningful impact by shaping the future of AI.
Responsibilities
- Drive threat modeling and risk prioritization, acting as the security counterpart to system-design reviews.
- Own end-to-end vulnerability management across CI/CD pipelines and runtime environments.
- Secure Kubernetes deployments and containerized workloads, implementing advanced pod and node hardening.
- Define and enforce Infrastructure-as-Code security with Terraform guardrails and policy-as-code integration.
- Design and execute a security tooling strategy including CNAPP, CSPM, SAST, SCA, secrets management, and SBOM-CVE tracking.
- Champion developer enablement by building secure defaults, streamlining remediation, and drafting security guidelines.
- Build foundational security automation to scale with growth and establish a pragmatic security culture.
Requirements
- 5+ years of experience in DevSecOps, Security Engineering, or Cloud Security, preferably as an early security hire.
- Deep understanding of Kubernetes and container security.
- Strong experience securing Infrastructure-as-Code (Terraform) across major cloud providers.
- Strong programming and scripting skills (Python, Go, or similar) for security automation and tool integration.
- Extensive experience deploying and tuning modern security tooling with a pragmatic approach to vulnerability management and threat modeling.
- Strong communication skills with a proven track record of partnering with developers and researchers to embed secure defaults.