
Qube Research & Technologies · Paris
Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a ...
Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset
classes across the world. We are a technology and data driven group implementing a scientific approach to investing. Combining
data, research, technology and trading expertise has shaped QRT’s collaborative mindset which enables us to solve the most complex
challenges. QRT’s culture of innovation continuously drives our ambition to deliver high quality returns for our investors.
As a Senior Security Engineer, you will help define and raise the security bar for applications and services across QRT. Working
closely with engineering teams, you will conduct security assessments, review system designs, identify vulnerabilities, and drive
security best practices across the software development lifecycle. You will propose pragmatic mitigations and help ensure services
are secure and resilient before launch. This role offers exposure to the full breadth of QRT's technology landscape, from cloud
platforms to low-latency trading infrastructure.
designs for potential security risks.
is built in at every stage of the development lifecycle.
securing large‑scale software systems.
advise development teams on secure coding practices.
business applications across both Windows and Linux environments.
Python, C++, Rust, Go and Kotlin/Java.
cloud services and operating systems environments.
threat detection across cloud services and on-prem systems.
internal applications. Reasons about threats and risks in terms of real impact, not abstract severity scores.
severity.
infrastructure.
and suggest a safer pattern.
environment.
QRT is an equal opportunity employer. We welcome diversity as essential to our success. QRT empowers employees to work openly and
respectfully to achieve collective success. In addition to professional achievement, we are offering initiatives and programs to
enable employees achieve a healthy work-life balance.
Vestiaire Collective is the leading global platform for desirable pre-loved fashion and a pioneer in transforming how people consume fashion. Our mission is simple: make circular fashion the norm, not the exception. Through technology, expertise, and a highly engaged global community, we enable millions of people to buy and sell fashion in a more sustainable way. Founded in Paris in 2009, Vestiaire Collective is now a globally scaled marketplace with offices in Paris, London, Berlin, New York, Singapore, and Ho Chi Minh City, and logistics hubs across Europe, Asia, and the US. Today, we are a team of around 600 people from over 50 nationalities, united by a shared ambition: to drive meaningful change in the fashion industry. Our values, Activism, Transparency, Dedication, Greatness, and Collective, shape how we build, collaborate, and grow every day. Please upload your CVs in English About the role : As a Senior Security Analyst at Vestiaire Collective, you will be part of our Security team. Your objective will be to provide a safe, secure, and trustworthy experience for our users, while safeguarding their privacy and personal data, as well as protecting our company assets and internal employees. Additionally, you will ensure compliance with regulatory requirements. This role is focused on security operations, risk, and assurance: you will be the person who keeps continuous watch over our security posture — monitoring and investigating alerts, driving vulnerabilities through to remediation, supporting incident response, and producing the evidence and metrics that demonstrate our security and compliance to auditors, regulators, and leadership. Reporting to the Head of Security, you will work alongside a talented team of security engineers and collaborate closely with engineering teams and other stakeholders such as legal, finance, and corporate IT. You will work daily with our security stack: Datadog (SIEM), SentinelOne (EDR), Upwind (CSPM), Cloudflare (WAF and Cloudflare One), and Grafana/Prometheus, on top of our AWS and GCP cloud environments. What you will do : Operate and continuously improve our security monitoring: triage and investigate alerts across our detection stack (Datadog SIEM, SentinelOne EDR, Cloudflare), tune detections to reduce noise, and escalate confirmed threats. Review and prioritize cloud security posture findings (Upwind CSPM) across our AWS and GCP environments, and drive misconfigurations through to resolution with the relevant teams. Own the vulnerability management lifecycle: consolidate findings from penetration tests, application security reviews, and our bug bounty program; validate and prioritize them; and drive remediation with engineering teams against defined SLAs. Triage incoming bug bounty submissions: reproduce and assess reported issues, determine severity, and coordinate fixes with the relevant code owners. Support incident response from detection to closure: first-line investigation, coordination during incidents, documentation, and post-incident follow-up actions. Support audit and assurance activities: prepare and maintain evidence for external audits, run periodic access reviews (joiners/movers/leavers, privileged access), and keep compliance documentation up to date. Contribute to security metrics and reporting: maintain and enrich the KPIs and dashboards (Grafana) we use to report our security posture to leadership. Assess third-party vendors and tools from a security and data-protection standpoint. Handle day-to-day security requests from across the company (reported phishing, the security inbox, employee questions) and deliver security awareness initiatives to promote a security-conscious culture. Who you are : Proven experience (3+ years) in a security analyst, SOC, or security operations role, preferably in a fast-paced startup/scaleup environment. Strong analytical and problem-solving abilities, rigorous documentation habits, and the ability to communicate clearly with both technical and non-technical stakeholders. Hands-on experience with SIEM and log analysis platforms (e.g., Datadog, Splunk, Elastic) for alert triage, threat detection, and investigation; familiarity with EDR tooling (e.g., SentinelOne, CrowdStrike) is a strong plus. Working familiarity with cloud environments (AWS and/or GCP) and cloud security fundamentals - enough to understand, prioritize, and follow up on CSPM and WAF findings. Solid understanding of vulnerability management and common application threats (e.g., OWASP Top 10) - enough to validate findings, assess real-world impact, and discuss remediation credibly with engineers. Understanding of compliance frameworks and regulations (e.g., ISO 27001, PCI DSS, SOC 2, GDPR, DSA), with the ability to translate requirements into practical controls, procedures, and audit evidence. Scripting or query skills (e.g., Python, SQL), for automating routine analysis and digging into data during investigations. Ability to adapt to a rapidly changing environment and manage multiple priorities. NICE TO HAVE: Bachelor's or Master's degree in Computer Science, Information Security, or a related field. Relevant certifications (e.g., CompTIA Security+/CySA+, GIAC GCIH/GCIA, CISA, ISO 27001 Lead Auditor/Implementer) are a plus. Our Tech Stacks includes Datadog SIEM Upwind CSPM Cloudflare (WAF, One) SentinelOne AWS, GCP Grafana, Prometheus Snowflake Tableau
About Mirakl: Founded in 2012, Mirakl has been at the forefront of marketplace innovation, empowering every business to compete in the platform economy. Today, Mirakl’s operating system combines an enterprise marketplace solution (Mirakl Platform) that enables retailers and B2B organizations to launch, scale, and operate marketplaces and dropship, AI-powered multichannel selling (Mirakl Connect), retail media (Mirakl Ads) and an agentic commerce infrastructure (Mirakl Nexus). With dual headquarters in Boston and Paris, Mirakl helps a global ecosystem of 450+ marketplaces (B2C and B2B) and a network of over 100k third-party marketplace sellers. Brands like Macy’s, Decathlon, Carrefour, Asos, and Airbus Helicopters use Mirakl to grow their businesses in new and remarkable ways. For more information, visit www.mirakl.com. Mirakl in Numbers: * 🗓️ Founded in 2012 | Member of French Tech Next40 * 👥 750+ employees in 9 offices worldwide: Paris, Barcelona, Bordeaux, Boston, London, Munich, New York, Sydney, Tokyo Our Values: Working at Mirakl means accelerating your career alongside ambitious, passionate, and supportive colleagues. We're proud of the diversity of backgrounds, perspectives, and experiences that make our teams unique. Our 5 values guide how we collaborate: * 💡 Work Hard Together: Teamwork and collaboration are the foundation of our success * 🏆 Get Things Done: We prioritize action and efficiency for impactful results * 🚀 Go Above & Beyond: We tackle challenges proactively and always aim for excellence * 🎓 Succeed Through Expertise: Knowledge sharing and continuous learning are core to our culture * 🤝 Satisfy & Empower Clients: We're committed to our clients' success THE TEAM YOU'LL JOIN You'll be part of our Security team within the Platform, Data & AI Security pillar, led by Maxime Lahaye, Senior Security Officer, based in Paris. AI is fundamentally transforming how we work, and you'll join a team at the forefront of this evolution. This is your opportunity to build the GRC infrastructure of tomorrow, where automation, scripting, and security converge to enable Mirakl's next phase of growth. This is a permanent position (CDI) based in Paris or Bordeaux, with 4 days on-site per week. YOUR IMPACT 1 · COMPLIANCE & CERTIFICATIONS — AUTOMATION-FIRST * Contribute to maintaining Mirakl's ISO 27001, ISO 27018 and SOC 2 certifications, leveraging automated GRC platforms to enable continuous compliance monitoring * Automate evidence collection, control monitoring and documentation workflows using modern GRC tooling, AI-powered agents and scripting (Python, N8N) * Help manage and evolve the ISMS (Information Security Management System), ensuring it reflects both regulatory requirements and Mirakl's evolving AI-driven operations 2 · AI GOVERNANCE * Co-design and evolve Mirakl's AI usage governance framework: acceptable use policies, data classification for AI inputs, shadow AI detection and AI vendor risk assessment * Maintain a live inventory of AI tools used across the company and contribute to the risk-based process for evaluating and onboarding new tools * Monitor the AI governance regulatory landscape and help adapt Mirakl's framework proactively 3 · SECURITY BY DESIGN ACROSS ALL COMPANY PROJECTS * Partner with Product and Engineering teams early in project lifecycles to embed security and compliance requirements from the start * Participate in risk reviews across product and platform initiatives, with specific attention to AI-related threat vectors (prompt injection, data leakage in LLMs, access control for models) WHAT YOU'LL BRING TO THE ROLE Experience: * Master's degree (Bac+5) * Minimum 3 years of experience in cybersecurity * You participated in ISO 27001 audit as a security contributor at least * Proven experience in scripting and automation (Python, N8N or equivalent) * Experience in a consulting firm or technology company is a plus * Strong understanding of compliance frameworks and security standards Skills: * Strong technical profile with hands-on experience developing scripts and automating processes * Proactive and autonomous, with strong organizational and problem-solving abilities * Excellent communication skills to engage both technical and non-technical stakeholders * Integrity and ethics as core values * Ability to work collaboratively in cross-functional teams * Experience with web application and cloud (SaaS) security is a plus TOOLS USED * Python * N8N * Drata * AWS, GCP * Office Suite / Google Workspace LANGUAGES * Fluent in French and conversational English OUR HIRING PROCESS 1. 30-40 minute call with a Talent Acquisition Specialist 2. 1-hour technical interview with the hiring manager 3. Two 45-minute values interviews using the STAR methodology The STAR method and structured interviews will hold no secrets for you. We welcome collaborators with their diverse perspectives and experiences to power us forward. These often far exceed conventional job requirements and help us create a culture of continuous learning. If you’re ready to join a global leader powering digital transformation for 450+ of the world’s most innovative retailers and B2B organizations. As part of our recruitment process, Mirakl processes your personal data to review and manage your application and, where appropriate, to consider your profile for future opportunities. You can exercise your data protection rights at any time, and as further detailed in our policies. For more information about how we process your personal data and your rights, please consult our Recruitment Privacy Notice, here in English and here in French. We may use Artificial Intelligence (AI) solutions to help streamline our hiring process, including screening applications, analyzing resumes, and assessing responses. While AI helps us work efficiently, all final hiring decisions are made by humans. For more information, visit our AI Guidelines for Candidates and Interviews.
🧡 ABOUT ALMA At Alma, we believe sustainable commerce depends on fair, well‑balanced trade. Because finance plays a pivotal role in business, our mission is to put it back in its rightful place - serving merchants and consumers. Our installment and deferred payment solutions help merchants boost sales by 20% or more, increase customer loyalty, and deliver a seamless shopping experience - without encouraging bad debt. As the buy now pay later leader in France and active in 10 European countries, we've empowered over +25,000 merchants and 10 million consumers. With 380+ Almakers and €100M+ ARR, Alma is scaling rapidly across Europe as a member of the Next40, and we're just getting started! 👐 ABOUT THE TEAM The Developer Experience (DevX) squad is part or the Engineering’s Platform Tribe. The Platform Tribe groups the DevX squad and the Site Reliability Engineering quad. The members of the tribe are responsible for building the foundational infrastructure, security layers, and core systems that empower Alma's entire product and engineering organization to scale reliably. You will join a dedicated squad focused entirely on the daily lives of our engineers: Our mission is to eliminate friction from a developer's machine all the way to production. We build, optimize, and maintain the delivery systems, local development environments, and CI/CD automation that allow our product teams to ship high-quality code safely, frequently, and with absolute confidence. We operate in a highly dynamic, polyglot environment. We are looking for an engineer driven by technical curiosity, who loves exploring new tools and technologies to continuously elevate our engineering standards. This is a full-time position, based in Paris or fully remote in France. 💼 ABOUT THE JOB * Own and continuously optimize our CI/CD pipelines and delivery workflows, ensuring fast feedback loops and secure deployments. * Build and evolve the local developer experience, making it seamless for engineers to spin up, test, and debug services locally across a variety of languages and frameworks. * Own and maintain part of our cloud infrastructure and container orchestration platforms using Terraform and Kubernetes. This will also require participating in identifying and solving infrastructure-related production issues and performance troubleshooting, upgrading our platforms for long-term resilience. * Be a technical referent and drive engineering standards forward by acting as a trusted partner for product engineering squads on delivery and infrastructure best practices, sharing expertise and providing guidance. * Encourage a culture of technical curiosity by frequently evaluating, benchmarking, and prototyping emerging technologies to bring the best tool sets to the team and promoting a culture of continuous learning across the org. 🧰 YOU WILL WORK WITH Python, TypeScript, PHP, Docker, Kubernetes, Terraform, GitHub Actions, GCP, Postgres and Datadog. 🧩 ABOUT YOU To succeed in this job * You've built at least 5 years of experience in a relevant role, ideally in DevOps or Platform Engineering. * You take ownership of cross-functional infrastructure initiatives, driving complex projects from design to delivery alongside multiple teams. * You have hands-on experience designing, building, and optimizing CI/CD pipelines end to end (GitHub Actions or equivalent). * You're comfortable building robust automation pipelines and modernizing local development environments. * You are fluent in french (primary working language) with a good level of English, for documentation, cross-team exchanges, and technical reading, writing as well as presenting. And it will be nice if you also * Have production-grade proficiency with Infrastructure as Code (not necessarily Terraform) and container orchestration (not necessarily Kubernetes). * Are familiar with an observability and monitoring stack (Datadog, Prometheus, or equivalent). * Have worked with local development environment tooling (Nix, mise, asdf, devenv, devcontainers, etc.). * Working knowledge of at least one language from Alma's stack (Python, TypeScript, or PHP), enough to read, debug, and contribute when needed. Don't meet every single requirement? At Alma, we believe great hires come from diverse paths. If this role excites you, we encourage you to apply. We value potential, curiosity and the ability to grow as much as experience. 🧘 WHAT’S IN IT FOR YOU If you join, you will be able to grow and impact on: * The infrastructure and tooling that directly shapes the productivity and confidence of every engineer at Alma. You'll have real ownership over your scope, the space to explore and prototype freely, and the support to take initiative. * The DevX squad, a dynamic, polyglot team where learning together is a core habit, not an afterthought. * Alma's growth across Europe, as the infrastructure you build directly enables us to scale reliably across 10 markets and more in the future, your work has a clear and measurable line to the business. 🤑 COMPENSATION & BENEFITS * Competitive salary based on 12 months * Profit-sharing and employee savings plan * Health insurance: 100% covered by Alma including family package * Disability insurance: 100% covered by Alma * Sport: partnerships with Gymlib and Classpass, or €30/month reimbursement for your sports activities * Maternity/paternity leave: salary maintained at 100% during leave with no seniority requirement. Return to work at 4/5 schedule paid at 100% for 8 weeks. * Sustainable Mobility Package (FMD): €544.80/year (excluding full-remote contracts) * Meal vouchers: €10/day, 50% covered by Alma * Mental health: free access to MindDay platform * Paid time off: 25 days/year ****(+ additional paid leave granted for employees on executive contracts) * Access to our Learning & Development Platform * 2 weeks of full remote possible per year in summer for people working in hybrid remote 🎯 INTERVIEW PROCESS * Video call with a Talent Acquisition team member to understand your path, motivation & present you the role. * Video call with your future manager to deep dive the role, the team, your profile and answer all your questions. * Case study presentation with 2 - 3 team members (ideally in house) to assess your practical knowledge**.** * Take-home coding test, followed by a remote feedback session. * Live system design interview to assess your practical and architectural knowledge. * A coffee chat with the squad you’ll join to further assess your skills and team fit. 🌍 DIVERSITY & INCLUSION At Alma, we believe that diversity fuels innovation and makes our community stronger. We are committed to building a workplace where every person feels seen, respected, and empowered to do their best work whatever their gender, background, ethnicity, age, sexual orientation, religion, disability or lived experience. As an equal opportunity employer, we welcome applicants from all walks of life, and all employment decisions are made based on qualifications, merit, and business needs.