> Markdown version of [/jobs/ext/2337218-kering-cybersecurity-vulnerability-engineer](https://www.wearedevelopers.com/jobs/ext/2337218-kering-cybersecurity-vulnerability-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # KERING Cybersecurity Vulnerability Engineer - **Company:** Kering - **Location:** Paris, France - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Bash Shell, Cyber Security, Information Systems, Python (Programming Language), Windows PowerShell, Software Engineering, Scripting, Vulnerability Analysis - **Published:** August 28, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=d7db38d89bf78c6d ## About the Role Idéalement diplômé(e) d'un Bac+4/5 (Master ou école d'ingénieur) avec une spécialisation en cybersécurité, systèmes, réseaux ou développement, vous justifiez d'une expérience significative en gestion des vulnérabilités, sécurité opérationnelle ou ingénierie sécurité. Une expérience en environnement CERT, SOC, VOC ou dans un programme de remédiation management constitue un atout important. Vous maîtrisez les fondamentaux de la gestion des vulnérabilités, notamment les logiques de scoring, de priorisation et de cycle de vie de la remédiation. Vous êtes à l'aise avec le scripting, notamment en Python, PowerShell ou Bash, et les API, pour automatiser des flux de reporting, administrer certains outils ou analyser des éléments techniques comme la validation d'exploit publique. Vous avez démontré des usages concrets de l'IA dans un lab personnel ou dans vos missions précédentes, avec un regard critique sur ses apports et ses limites. Vous possédez une bonne compréhension des environnements systèmes, réseaux et des architectures cloud. Rigueur, capacité d'analyse, sens de la coordination, qualités rédactionnelles et aisance relationnelle sont essentielles pour interagir avec des interlocuteurs variés et piloter des sujets transverses dans un environnement international. Vous maîtrisez l'anglais, à l'écrit comme à l'oral ; l'italien constitue un plus., You hold a Master's degree or have graduated from an Engineering school, with a specialization in cybersecurity, systems, networks, or software development. You have significant experience in vulnerability management, operational security, or security engineering. Experience within a CERT, SOC, VOC environment, or in a remediation management program, is considered a plus. You have a solid command of the fundamentals of vulnerability management, particularly scoring methodologies, prioritization mechanisms, and remediation lifecycle processes. You are comfortable with scripting, notably in Python, PowerShell, or Bash, as well as with APIs, to automate reporting workflows, administer certain tools, or analyze technical elements such as the validation of publicly available exploits. You have demonstrated practical uses of AI in a personal lab or in previous assignments, with a critical perspective on its benefits and limitations. You possess a strong understanding of system and network environments, as well as cloud architecture. On a personal level, rigor, analytical skills, coordination capabilities, strong written communication skills, and excellent interpersonal abilities are essential to interact with a wide range of stakeholders and drive cross-functional initiatives in an international environment. You have full proficiency in English, both written and spoken; Italian would be a plus. ## Description Au sein du Kering-CERT, en charge des activités de détection et de réponse aux incidents de cybersécurité (SOC, VOC, CTI et CSIRT), vous contribuez activement au renforcement des activités du Vulnerability Operation Center et au développement des capacités du CERT au sein d'un groupe international. Nous sommes actuellement à la recherche d'un(e) Cybersecurity Vulnerability Engineer pour intégrer l'équipe. Votre opportunité Au sein du CERT, vous contribuez au pilotage et à l'amélioration continue du programme de gestion des vulnérabilités du Groupe. Vous intervenez sur l'outillage, l'automatisation, l'analyse, la priorisation et le suivi des remédiations, en lien étroit avec les équipes cybersécurité, infrastructure, production et les différentes entités du Groupe. Ce poste vous place au cœur des enjeux de réduction de la surface d'exposition du système d'information. Vous participez à la structuration et à la montée en maturité du VOC, en renforçant la capacité du Groupe à identifier, qualifier et traiter efficacement les vulnérabilités. Comment vous allez contribuer En tant que Cybersecurity Vulnerability Engineer, vous assurez le maintien en condition opérationnelle et de sécurité des outils de scan et de gestion des vulnérabilités. Vous contribuez à leur évolution, à leur fiabilité et à leur bonne intégration dans l'écosystème de sécurité du Groupe. Vous développez également des automatisations pour faciliter l'administration, le reporting et le pilotage des activités de remédiation. Vous analysez les vulnérabilités identifiées, formulez des recommandations, contribuez à leur priorisation et accompagnez les équipes concernées dans le suivi des plans de remédiation, y compris sur des projets transverses à l'échelle du Groupe. Vous pilotez la gestion des vulnérabilités critiques et des situations à fort impact, en lien avec les équipes métiers et techniques concernées. Vous accompagnez également les campagnes mensuelles de patching avec les équipes en charge des postes de travail et des infrastructures, afin de garantir un niveau de mise à jour du parc conforme aux politiques internes. Membre à part entière du CERT, vous intervenez sur l'ensemble des sujets traités par l'équipe, de la détection à la réponse aux incidents, en passant par la CTI, en coordination avec le reste de l'équipe. Vous effectuez une veille active sur les nouvelles vulnérabilités et leur niveau d'exposition dans le contexte Kering, et contribuez à l'amélioration continue des méthodes de priorisation, notamment à partir d'indicateurs tels que le CVSS, les KEV et l'EPSS., Within the CERT, you contribute to the governance and continuous improvement of the Group's vulnerability management program. You are involved in tooling, automation, analysis, prioritization, and remediation tracking, working closely with cybersecurity, infrastructure, production teams, and the Group's various entities. This role places you at the heart of the challenges related to reducing the information system's exposure surface. You contribute to structuring and advancing the maturity of the Vulnerability Operations Center (VOC), strengthening the Group's ability to identify, assess, and effectively remediate vulnerabilities. How you will contribute As a Cybersecurity Vulnerability Engineer, you are responsible for maintaining the operational effectiveness and security of vulnerability scanning and management tools. You contribute to their evolution, reliability, and seamless integration within the Group's security ecosystem. You also develop automation solutions to streamline administration, reporting, and the management of remediation activities. You analyze identified vulnerabilities, provide recommendations, contribute to their prioritization, and support the relevant teams in tracking remediation plans, including on cross-functional projects at Group level. You oversee the management of critical vulnerabilities and high-impact situations, in collaboration with the relevant business and technical teams. You also support the monthly patching campaigns with the teams responsible for workstations and infrastructure, ensuring that asset update levels remain compliant with internal policies. As a fully integrated member of the CERT, you contribute to the whole spectrum of activities handled by the team, from detection and incident response to Cyber Threat Intelligence (CTI), in coordination with the rest of the team. You actively monitor emerging vulnerabilities and assess their exposure level within the Kering environment, while contributing to the continuous improvement of prioritization methodologies, leveraging indicators such as CVSS, KEV, and EPSS. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)