DevSecOps Engineer
Paris, 75, FR
ABOUT CFM
Founded in 1991, we are a global quantitative and systematic asset management firm applying a scientific approach to finance to develop alternative investment strategies that create value for our clients.
We value innovation, dedication, collaboration, and the ability to make an impact. Together, we create a stimulating environment for talented and passionate experts in research, technology, and business to explore new ideas and challenge existing assumptions.
ABOUT THE ROLE
Are you passionate about software development and security? In this role, you’ll be instrumental in designing and implementing automation that is critical to our security posture. Reporting directly to the Director of Application Security, you will work collaboratively with the whole Information Security team as well as development, infrastructure, and operations teams across the company.
Overview & Key Responsibilities:
- Design, build, and maintain automation services that integrate with an IGA (Identity Governance & Administration) platform, directory services, and security systems through well-documented APIs.
- Develop RESTful APIs and backend services in Python to support identity aggregation, provisioning workflows, access profile management, and group membership automation.
- Implement secure API authentication, authorization, rate-limit handling, retries, circuit breakers, and request/response transformations for SaaS and enterprise integrations.
- Support reliable synchronization between cloud identity platforms and on-premises or cloud directory services, including conflict handling, consistency strategies, and failure recovery.
- Partner with security, infrastructure, identity, and development teams to translate access-management requirements into scalable technical designs and maintainable production systems.
- Produce clear technical documentation for APIs, workflows, operational procedures, and integration behaviors.
Minimum Qualifications:
- Proficiency in Python backend development, including experience with web service frameworks and asynchronous or concurrent programming patterns.
- Hands-on experience designing, developing, documenting, and operating RESTful APIs, including authentication, authorization, versioning, and contract management.
- Working knowledge of IAM and IGA concepts such as identities, roles, access profiles, provisioning, aggregation, and lifecycle workflows.
- Experience with at least one IGA or identity platform such as SailPoint, Saviynt, Okta, Ping Identity, Keycloak, or a comparable solution.
- Understanding of LDAP, Active Directory, or Entra ID fundamentals, including schemas, authentication, group management, and directory APIs.
- Familiarity with secure credential management, audit logging, data protection, and security controls for systems handling identity data.
- Solid software engineering practices, including clean code, Git, unit testing, API documentation, and maintainable architectural patterns.
- Familiar with secure coding best practices including but not limited to the OWASP Top 10.
- Ability to troubleshoot complex integration issues across APIs, identity platforms, directory services, authentication flows, and authorization failures.
- Hands-on experience with agentic coding tools such as Claude Code or Codex.
- Excellent written and verbal communication skills, with proven ability to transform complex technical concepts into clear business and security recommendations.
Preferred Qualifications:
- Experience with threat modeling or conducting comprehensive security audits is a plus.
- Experience consuming and integrating third-party SaaS and Cloud APIs, including quota management, retry strategies, exponential backoff, and resilient failure handling.
- Experience with Secret Managers such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or similar tools.
- Knowledge of identity standards and protocols such as OpenID Connect, OAuth, SAML, and SCIM.
- Familiarity with microservices, API gateways, event-driven or batch processing patterns, distributed systems, and data pipeline design.
- Experience with relational databases, SQL, caching strategies, indexing, and eventual consistency for performance-critical identity data queries.
- DevSecOps experience, including CI/CD pipelines such as GitLab and Jenkins, Infrastructure as Code (Terraform, CloudFormation), integration testing, performance testing, containerization, and Linux scripting or administration.
- Exposure to Kafka, provisioning connectors, web front-end development with React or Angular..
- A passion for being informed about the latest security research, tools, and adversarial tactics, techniques and procedures — and applying that knowledge to improve enterprise security.
EQUAL OPPORTUNITIES STATEMENT
We are continuously striving to be an equal opportunity employer and we prohibit any discrimination based on sex, disability, origin, sexual orientation, gender identity, age, race, or religion. We believe that our diversity, breadth of experience, and multiple points of view are among the leading factors in our success.
CFM is a signatory of the Women Empowerment Principles.
FOLLOW US
Follow us on Twitter or LinkedIn or visit our website to find out more about CFM.