> Markdown version of [/jobs/ext/2362191-senior-sre-engineer-security](https://www.wearedevelopers.com/jobs/ext/2362191-senior-sre-engineer-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SRE Engineer - Security - **Company:** Gorgias - **Location:** Paris, France (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Bash Shell, Software as a Service, Cloud Computing Security, Computer Networks, Continuous Integration, Disaster Recovery, Github, Identity and Access Management, Intrusion Detection Systems, Python (Programming Language), PostgreSQL, Networking Basics, OAuth, Octopus Deploy, OpenID, Peering, RabbitMQ, Role-Based Access Control, Redis, Zero Trust Network Access, Runbook, Security Assertion Markup Language (SAML), Security Information and Event Management, Policy as Code, Data Logging, Scripting, Cloud Platform System, Amazon Virtual Private Cloud (VPC), Debezium, Kubernetes, Apache Flink, Deployment Automation, Apache Kafka, Terraform, Golang - **Published:** August 5, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=4c3b4009a6413ff2 ## About the Role * 5+ years in infrastructure security, cloud security, or security engineering - ideally in a high-growth SaaS environment * Deep GCP and Kubernetes expertise - GKE, workload identity, network policies, RBAC; you know where the bodies are buried * Strong networking fundamentals - VPC design, peering, firewall architecture, zero-trust networking * Hands-on CI/CD and IaC hardening - GitHub Actions, ArgoCD, Terraform security patterns * Auth expertise - OAuth 2.0, OIDC, SAML; you can design and audit identity flows, not just enable SSO * Policy-as-code experience - OPA, Kyverno, or equivalent; guardrails at the platform layer * Detection and response background - SIEM, IDS, runtime security tools, and experience writing real runbooks * Compliance experience - SOC 2 (Type II preferred), ISO 27001, GDPR/PII data protection * Scripting fluency - Python Go, Bash for automation, tooling, and incident response scripts ## Description As a Gorgias Platform Security Engineer, you will contribute to our security program, working directly with our SRE team and engineering leadership You will implement and manage essential security tools and processes, with a particular focus on ensuring resilience against potential external threats and attacks. This role will be critical in setting up proactive security measures and responding to incidents, making a tangible impact on Gorgias' ability to meet enterprise-grade security standards. What you will do Platform & cloud security * Own cloud and Kubernetes security - IAM, RBAC, network policies, workload identity, and GKE hardening across 10+ global clusters * Design secure-by-default platforms - build guardrails and policy enforcement (OPA, Kyverno, or similar) that guide teams without blocking them * Harden CI/CD and IaC pipelines - secure GitHub Actions, ArgoCD, and Terraform workflows end-to-end * Lead secrets management - design and implement decoupled secrets architecture so credentials never live in deploys or repos * Strengthen networking fundamentals - VPC design, peering, cross-cloud connectivity, and zero-trust segmentation Detection & response * Build security-focused logging and monitoring - design the observability layer that actually catches threats, not just collects noise * Implement runtime detection - IDS, file integrity monitoring, and behavioral anomaly detection across GKE workloads * Develop incident response playbooks - practical, tested runbooks for common incident types; own the response process end-to-end * Manage and evolve the SIEM - drive meaningful signal-to-noise improvements and build automated mitigation where it matters Auth & identity * Design and enforce strong auth standards across internal tools, APIs, and customer-facing surfaces * Audit and mature privileged access management - ensure least-privilege is real, not theoretical Compliance & enterprise enablement * Own the ongoing health of SOC 2 Type II - keep controls tight between audits, not just before them * Drive the next compliance milestones - ISO 27001 and data protection (PII, GDPR) as we expand enterprise and global reach, You'll be working closely with our SRE team, a group of experienced engineers who are building and maintaining: * Multi-TB Postgres clusters * RabbitMQ and Redis with tens of thousands of operations per second * 10+ full-featured GKE clusters globally with over 15k tenants * A new stack of Kafka, Debezium, and Apache Flink * Github Actions CI and ArgoCD for scalable deployment strategies * Best practices around Kubernetes/Helm/Operators, SLIs/SLOs, Incident Management, Observability, Security, and Disaster Recovery ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)