Security Engineer

ALICE SERVICE
Nice, France
6 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Audit Trail Microsoft Azure Bash Shell Cyber Security Continuous Integration Firmware Identity and Access Management Python (Programming Language) OpenID Security Assertion Markup Language (SAML)
+9 more
Security Information and Event Management Software Vulnerability Management Software Security Kubernetes Information Technology Terraform Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

We’re looking for a Senior Security Engineer to help secure and evolve our IT infrastructure and applications, spanning everything from corporate identity systems to the security of our quantum R&D labs. You’ll own key security initiatives end to end, set standards and best practices across the company, and mentor junior engineers as you help shape our strategic security roadmap., * Corporate security - identity and access management (SSO, SCIM), security observability and audit logging, and operational cybersecurity (EDR/XDR, SIEM, vulnerability management, incident response).

  • Application security - vulnerability management, CI/CD security (SAST, DAST, secret detection, IaC scanning), software supply chain security (SCA, SBOM), and threat modeling embedded into the development lifecycle.
  • Infrastructure and industrial security - Infrastructure as Code (Terraform), Kubernetes security, and - uniquely for this role - securing the lab environment itself: instrumentation, control systems, embedded/firmware security, and OT/ICS hardening across our quantum R&D equipment.
  • Leadership - mentoring engineers, driving continuous improvement, and partnering closely with engineering, IT, hardware, and physics teams to embed security by design without slowing down research.

Requirements

  • 5+ years of experience in cybersecurity or a closely related engineering role
  • Proven hands-on experience with Infrastructure as Code (Terraform)
  • Solid experience securing containers and Kubernetes environments
  • Strong fundamentals across both application and corporate security - vulnerability management, incident response, threat modeling
  • Strong hands-on experience with identity technologies (SSO/SAML/OIDC, SCIM)
  • Proficiency with security monitoring tooling (EDR/XDR, SIEM, audit logging)
  • Solid scripting and automation skills (Python, Bash, or similar)
  • Practical experience with application security tooling (SAST/DAST, SCA) and CI/CD security integration
  • Degree in Computer Science, Cybersecurity, or a related field (Bac+3 to Bac+5), or an equivalent self-taught/bootcamp background with a proven track record
  • Strong ownership and autonomy, clear communication with technical and non-technical stakeholders, and a genuine mentoring mindset, * Experience with cloud platforms (GCP, AWS, or Azure)
  • Familiarity with security frameworks (ISO 27001, SOC 2, NIST)
  • Exposure to embedded, firmware, or operational technology (OT/ICS) security - ideally in a lab or industrial setting
  • Experience defining or maturing a DevSecOps program

Benefits & conditions

Our success is your success: own it with our BSPCE plan

  • Direct IP Compensation: Earn substantial bonuses for driving the core patents that define our quantum architecture.
  • Flexible remote policy, up to 40 % a month
  • A Parental plan including additional benefits such as crèche support or additional days-off to take care of under 12 years old children
  • Subsidized membership with Urban Sports Club
  • Mental health support with moka.care
  • 25-day vacation policy (as per French law) + RTT
  • Half of transportation cost coverage (as per French law), or yearly allowance for the die-hard bicycle users
  • Competitive health coverage, with Alan.
  • Meal vouchers with Swile, as well as access to a fully equipped and regularly stocked kitchen
  • French language courses covered by the company for those interested Research shows that women might feel hesitant to apply for this job if they don’t match 100% of the job requirements listed. This list is a guide, and we’d love to receive your application even if you think you’re only a partial match. We are looking to build teams that innovate, not just tick boxes on a job spec. You will join of one of the most innovative startups in France at an early stage, to be part of a passionate and friendly team on its mission to build the first universal quantum computer! We love to share and learn from one another, so you will be certain to innovate, develop new ideas, and have the space to grow.

About the company

Alice & Bob is developing the first universal, fault-tolerant quantum computer to solve the world’s hardest problems. The quantum computer we envision building is based on a new kind of superconducting qubit: the Schrödinger cat qubit . In comparison to other superconducting platforms, cat qubits have the astonishing ability to implement quantum error correction autonomously! We’re a diverse team of 250+ brilliant minds from over 35 countries united by a single goal: to revolutionise computing with a practical fault-tolerant quantum machine. Are you ready to take on unprecedented challenges and contribute to revolutionising technology? Join us, and let’s shape the future of quantum computing together! About the Mission As Alice & Bob scales from research breakthroughs to industrial-grade quantum systems, protecting the integrity of our infrastructure, our applications, and the intellectual property behind years of R&D becomes mission-critical. Security is a core enabler of how fast and how safely we can move.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all