> Markdown version of [/jobs/ext/2288399-director-of-cloud-infrastructure-security-h-f](https://www.wearedevelopers.com/jobs/ext/2288399-director-of-cloud-infrastructure-security-h-f). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director Of Cloud Infrastructure & Security H/F - **Company:** Bienvenue Chez Vestiaire Collective - **Location:** Paris, France (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** PHP (Programming Language), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing, Encodings, Databases, Continuous Integration, Data Stores, DevOps, Disaster Recovery, Github, Identity and Access Management, Key Management, Network Security, MongoDB, Node.Js, Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Reliability Engineering, Phishing, Security Information and Event Management, Vault (Revision Control System), Software Vulnerability Management, Datadog, Data Logging, Amazon ElastiCache, Software Security, Kubernetes, Cloudflare, Apache Kafka, Terraform, Jenkins, Microservices - **Published:** August 29, 2026 - **Apply:** https://www.hellowork.com/fr-fr/emplois/82783789.html ## About the Role 8+ years in engineering, with 5+ years leading infrastructure, platform, or security teams : ideally in a fast-paced scaleup or marketplace environment. - Proven experience managing multiple teams or functions, including hiring and developing senior engineers. - Deep, hands-on-credible expertise in public cloud (AWS strongly preferred), Kubernetes, and infrastructure-as-code (Terraform). - Track record establishing reliability practice at scale - SLOs, incident management, on-call, capacity planning, disaster recovery. - Demonstrable cloud cost optimisation / FinOps results at meaningful scale. - Strong grounding in cloud and application security fundamentals - IAM, network security, secrets management, CSPM, OWASP Top 10 - and the judgement to know when to hire the depth you don't have. - Working knowledge of compliance frameworks (GDPR, DORA, PCI DSS, NIS2) and how to turn requirements into practical controls. - Experience leading through incidents and security events under pressure. - Excellent communication skills: able to make a technical trade-off legible to a CFO and a risk decision legible to an engineer. - Comfortable operating with a lean team - ruthless prioritisation, automation over headcount, pragmatism over perfection. ## Description Vestiaire Collective runs a global marketplace on AWS and GCP - Kubernetes, Kafka, Terraform, Vault, Cloudflare, Datadog, a large PHP application under active modernisation, a series of microservices in different tech stacks (Goland, PHP, Node) and a fast-growing surface of AI-powered services. As Director of Cloud Infrastructure and Security, you will own that entire foundation. You will lead two distinct teams - Cloud Infrastructure (DevOps/SRE) and Security - and be accountable, alongside product development teams for the reliability, cost-efficiency and security posture of everything we run in production. What you will do: Leadership across two teams - Lead, grow and retain two teams - Cloud Infrastructure and Security - each small, senior and high-leverage. Hire well; we cannot afford mediocre hires at this size. - Define a joint roadmap for both teams, aligned to business priorities and risk appetite, and make explicit calls on what we will not do. - Establish clear KPIs, SLOs and risk metrics, and report regularly to leadership on reliability, cost and security posture. - Set the operating model: what product teams self-serve behind guardrails versus what your teams own centrally. - Foster a culture where reliability and security are shared accountabilities, not tickets thrown over a wall, including establishing a Security Champions model across engineering. Cloud infrastructure, reliability and platform - Own our AWS and GCP footprint end to end: EKS, networking, secrets (Vault), data stores (RDS/Aurora, MSK, ElastiCache, MongoDB Atlas, OpenSearch) and the edge (Cloudflare). - Establish real reliability engineering practice: SLOs and error budgets, capacity planning, and a business continuity plan. - Drive infrastructure-as-code maturity: Automating Terraform change application, advancing our move to GitOps (ArgoCD), and enforcing guardrails at creation time with policy-as-code (Kyverno/OPA) so provisioning is safe, self-serve and reviewable. - Consolidate observability into a single source of truth for metrics, logs and traces. - Improve developer experience and delivery throughput: CI/CD (Jenkins, GitHub Actions), paved roads, test environments on demand, and delivery metrics that hold up. - Own FinOps: infrastructure cost per unit of business value, cost accountability pushed back to each team, and continued run-rate reduction. Cost discipline is a first-class objective. - Support the modernisation of our core platform: Tech migrations, runtime and framework upgrades, and continuous database and Kubernetes upgrades. - Attack toil systematically: automate the recurring requests, and hand safe self-service back to product teams rather than absorbing the work. - Grow the foundations for AI-augmented engineering and operations Security - Own security strategy and posture across cloud, application, identity, detection and response, building and improving the governance: risk register, published roadmap, remediation SLAs, and a recurring reporting cadence for leadership. - Strengthen cloud security posture management (CNAPP) and secure-by-default configurations across all environments. - Improve Embedding security into the SDLC and CI/CD: establish full static-analysis and dependency-scanning coverage with clear criteria for when critical findings block a release. - Mature vulnerability management, penetration testing and our bug bounty program into one prioritised program with SLAs and aging reports that measurably reduce risk. - Advance identity and access management toward least privilege and zero trust: automated provisioning from groups, and periodic access reviews. - Mature logging, detection and incident response, closing SIEM coverage gaps - Set guardrails for safe AI adoption (shadow AI outside approved paths, data and prompt leakage, prompt injection, model abuse) and defend against AI-enabled fraud and phishing. - Ensure compliance with GDPR, PCI DSS v4, NIS2, and CIS v8, including a maintained, reusable evidence library rather than evidence gathered on request. - Collaboration with legal and finance teams on compliance and forensic investigation topics - Manage third-party and supply-chain risk with vendor tiering and a recurring review cadence. - Own the security-built services your team already runs (back-office authentication and ACL, banning/fraud tooling, phone verification) and decide what to keep, hand over or retire. - Own endpoint security and partner closely with Corporate IT on device and identity coverage. - Keep security awareness and training relevant to a threat landscape that now includes AI-enabled social engineering. ## Related Videos - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Software Engineering Social Connection: Yubo’s lean approach to scaling an 80M-user infrastructure](https://www.wearedevelopers.com/videos/1583-software-engineering-social-connection-yubo-s-lean-approach-to-scaling-an-80m-user-infrastructure) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Best Companies to Work For in Paris: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/190-best-companies-to-work-for-in-paris-top-25-companies-in-2023) - [Best Companies to Work For in France: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/189-best-companies-to-work-for-in-france-top-25-companies-in-2023) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)