DevSecOps Engineer
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• You have solid experience in AppSec, DevSecOps or Pentester roles • You have hands on experience integrating SAST, SCA, DAST, and secret scanning into CI/CD pipelines • You understand containerized environments and modern CI/CD workflows • You are comfortable with cloud environments, ideally GCP • You have experience handling security alerts and participating in incident response • You focus on automation and scalability rather than manual processes • You value pragmatic solutions over theoretical perfection
Responsibilities
• Own and improve our code security tooling and automation, including SAST, SCA, and secret detection tools • Enforce and evolve our DAST stack and contribute to preparing Red Team processes • Integrate security checks and gates directly into CI/CD pipelines (partner with DevOps) • Reduce false positives and improve the overall quality of vulnerability signals, ensuring positive developer feedbacks • Investigate alerts from multiple sources including bug bounty, SIEM, and EDR • Support IAM related operational needs • Contribute to the investigation and remediation of code related vulnerabilities • Collaborate closely with Backend Engineers to drive adoption of secure practices • Google Workspace • Get familiar with our platform architecture, CI/CD pipelines, and security stack • Review existing code security tooling and current pain points • Build relationships with Backend, DevOps, and Security stakeholders • Investigate a few real alerts to understand our operational workflows • Identify quick wins to improve signal quality or developer experience • Audit and stabilize our existing code security tooling • Reduce false positives and improve the quality of vulnerability reporting • Implement or standardize security gates in CI/CD pipelines • Contribute to at least one post mortem with actionable prevention measures • Improve documentation around secure development practices • Significantly reduce remediation lead time for critical vulnerabilities • Automate recurring security workflows and reduce manual effort • Ensure secure by default principles are embedded into our CI/CD standards • Be recognized by engineering teams as a reliable and pragmatic security partner • Contribute to a measurable improvement in production resilience and risk reduction • If you want to build security systems that scale with the product and genuinely support engineers rather than slow them down, we would be glad to meet you. • THE RECRUITMENT PROCESS • Phone screen with Nicolas, our Tech Recruiter • Interview with Yohan, our Security Lead • Technical test and debrief • Cultural fit assessments
Benefits
• A highly competitive salary range as well as equity in the company • A highly flexible remote work policy, 2 days at the office per month, with monthly team events. • We also cover fees for external professional events and meetups (Android Makers, etc…) • Great health insurance coverage for both you and your family by Alan, fully paid for by Yubo ! • Numerous benefits for parents: additional parental leave, easy access to nurseries and daycare facilities in France. • OUR APPROACH TO PRIVACY & SAFETY • As part of your role, you may handle tools and features involving personal data. We expect all employees to demonstrate strong awareness of privacy and safety issues, and to actively support our Privacy & Safety by Design efforts. • Here’s how we live our mission every day: • You own the impact: Step up, adapt, and make it matter • Unconventionally Smart: Hack with intent, borrow smart, build better • Be Bold & Resilient: Raise your head, break barriers, keep moving forward • One team, one mission: No egos, no passengers, just shared wins • Trust & Flexibility: Our hybrid model calls for only two office days a month; the rest is up to the rhythm that works best for you. • Culture is central at Yubo, hence the numerous benefits: • Cool Workplace: enjoy our amazing Parisian office and our many hybrid work options • Team Activities: participate in get-togethers, events, and team-building activities • Family-Friendly: we support parents with childcare options and family-friendly policies • Wellness Programs: benefit from comprehensive health insurance, wellness programs, sports classes, and mental well-being initiatives