
Theodo · Paris
L’histoire du groupe Theodo et son succès Theodo accompagne depuis 2009 les entreprises innovantes dans la conception, le développement et le déploiement de pro...
L’histoire du groupe Theodo et son succès
Theodo accompagne depuis 2009 les entreprises innovantes dans la conception, le développement et le déploiement de produits digitaux ingénieux - tels que la plateforme TF1+, l'application LCL Pro ou l'application France Identité Numérique - en tirant parti du meilleur de la technologie et de l’approche Lean.
Theodo connait une croissance exceptionnelle depuis 15 ans : nos équipes rassemblent plus de 700 Theodoers, principalement des Software Engineers, passionnés de technologie et d’amélioration continue. En 2025, le groupe Theodo génère 100M€ de CA.
En 2021, Theodo lance une practice experte en cybersécurité pour aider nos clients à sécuriser leur environnement Cloud. Aujourd'hui, l'équipe compte 11 SecOps Engineers.
Nous intervenons en équipe sur l'essentiel de nos projets : Lead SecOps, SecOps et Project Manager travaillent main dans la main pour garantir l’impact de nos actions chez nos clients.
Tu auras également l'opportunité de t'impliquer sur des projets internes à Theodo Cloud : l'amélioration de nos standards de sécurité, la construction de formations, la veille technique et le thought leadership (articles, talks)...
Nous proposons une évolution possible à nos Leads SecOps vers un rôle d’Engineering Manager (Management et/ou Expertise)
Tu ne coches pas 100% des critères mais tu penses tout de même correspondre à notre recherche ? Ne t’auto-censure pas et envoie-nous ta candidature, on se fera un plaisir de l’étudier !
Nous répondons à toutes les candidatures dans un délai de 3 jours.
Si ton profil nous intéresse, nous te proposons le process suivant :
Notre process dure 2 à 3 semaines en moyenne.
Tu seras accompagné(e) par une personne de l’équipe recrutement, qui sera là pour te coacher tout au long du process.
At Qred, we’re building the bank for small businesses. Since launching 11 years ago, we’ve grown from startup to profitable fintech scale-up, now generating over 1 billion SEK in annual revenue and supporting 50,000+ entrepreneurs across Northern Europe. We combine smart technology, real data, and human judgment to make financing simple, fast, and fair. With bold growth plans and strong momentum across multiple markets, we’re now looking for a SecOps Engineer for the next phase of growth. About the Role As a SecOps Engineer within our Engineering Enablers domain, you will bridge the gap between rigorous security standards and high-velocity product delivery. You will have end-to-end ownership of the security guardrails that protect our platform, moving away from manual gates toward automated, self-service security. Your mission is to empower our engineering teams to ship code confidently by embedding security into the very fabric of our scaling financial systems. Key responsibilities Architect and implement automated security guardrails within our AWS environment to ensure proactive risk mitigation. Support and mentor product teams during the discovery phase to integrate security requirements into the initial design of new features. Define and manage company-wide security policies, translating complex compliance needs into actionable engineering practices. Lead the response to security incidents, driving the process from initial detection and analysis through to containment and long-term resolution. Drive the adoption of security awareness programs across the organization, using data to measure and improve our collective security posture. What we’re looking for We are looking for a professional who thrives in a decentralized environment and values enablement over enforcement. As we are highly invested in AI, you possess a strong understanding of how to enable secure development processes and data integrity within that space. You are motivated by the challenge of building scalable frameworks that reduce cognitive load for other engineers while maintaining the high integrity required of a regulated bank. Qualifications Several years of experience in security engineering or DevSecOps, ideally within Fintech or another highly regulated industry. Deep technical knowledge of AWS security services, IAM frameworks, and cloud infrastructure. Practical experience in incident management and the development of automated security tooling. Strong communication skills with the ability to influence technical roadmaps and drive alignment across distributed teams. Practical experience with EDR/XDR solutions and MDM frameworks is preferred. Why Qred? This is the place to be if you’re looking for a place to grow. Qred is growing fast, and our Qredsters along with it. With a non-bureaucratic organization and delegated responsibilities, we make sure there’s a short path from idea to action. In addition to our great culture, you get to work with the latest cutting-edge techniques, full ownership, and last but not least a bunch of great competent colleagues to learn from! One Last Thing This is a full-time, permanent position based in our headquarters in Stockholm. We believe our culture thrives when we work together, which is why we have an office-first approach. To balance this with some flexibility, we have the option of working remotely one day per week. We review applications on a rolling basis and while the start date is flexible, the right candidate can join us immediately. Qred celebrates diversity and does not discriminate based on ethnicity, religion, national origin, gender, sexual orientation, age, disability status, or any other applicable characteristics protected by law. #LI-LJ1
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. *Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. AN OVERVIEW OF THIS ROLE We’re looking for a manager to lead the GitLab security incident response team (SIRT) in the Americas region. GitLab SIRT manages and investigates cybersecurity incidents across all GitLab operating environments and operates in a tierless SOC model. The team is responsible for threat hunting, alert triage, security investigations, deep-dive DFIR, and large-scale incident response, among other responsibilities. In this role, you will manage the day-to-day work of a team of incident response engineers - setting clear performance expectations, coaching their growth, and holding the team accountable for delivering quality results. You should have a strong technical background, be comfortable owning the full incident lifecycle from alert triage to retrospective actions, and be skilled at developing others to do the same. We are looking for someone who makes sound operational decisions under pressure and who actively looks for opportunities to "shift left" - improving defenses and leveraging AI and automation to optimize team workflows. You will implement program direction, maintain a culture of high performance, and defend GitLab infrastructure and products including GitLab.com, GitLab Dedicated, and GitLab Dedicated for Government (FedRAMP). This role requires availability during US West Coast business hours. Candidates based on the West Coast are preferred, though candidates in other time zones who are comfortable working these hours are also welcome to apply. Some after-hours and weekend coverage may be required to support engineers during high-severity incidents. Learn more about the Security Operations Department: * Security Incident Response Team * Trust and Safety Team * Security Logging Team * Red Team * Signals Engineering Team WHAT YOU'LL DO * Manage day-to-day team operations - establish clear goals, performance expectations, and accountability for direct reports; monitor progress and ensure timely delivery of quality results. * Develop and coach incident responders - provide candid, real-time feedback; advise on career growth; and foster a culture of investigation excellence, prioritizing depth and accuracy of analysis. * Proactively identify and fill talent gaps - participate in hiring decisions with a focus on candidates who will amplify GitLab's values and raise the team's technical bar. * Drive engagement and retention - recognize team member contributions, address engagement risks early, and create an environment of open feedback and psychological safety. * Cascade organizational context - translate division and company-wide strategy into clear, actionable team priorities; keep team members informed in a timely manner. * Implement and mature incident response processes - build and improve runbooks, procedures, and team capabilities that translate functional plans into tactical execution. * Lead incident response - serve as an escalation point and incident commander for high-severity events, including occasional nights and weekends; model the standard for quality investigations. * Enable cross-functional collaboration - coordinate effectively with peer SecOps teams, Legal, Customer Support, and Infrastructure to resolve incidents and close defense gaps through actionable retrospective mitigations. * Align the team on defensive improvements - drive insights from alerts, investigations, and incidents to improve GitLab's security posture and support a "shift left" mindset. * Champion remote-first practices - consistently model and coach team members on GitLab's remote working best practices, async communication norms, and handbook-first culture. WHAT YOU'LL BRING * Proven people management experience - track record of managing and developing a team of security engineers, setting performance expectations, providing coaching, and driving accountability for results. * Incident response leadership - demonstrated experience leading complex incident response operations, including large-scale incident coordination and the full lifecycle from triage to retrospective. * Hands-on technical background - experience conducting security investigations and log analysis using SIEM tools (e.g., Splunk, Elastic); working knowledge of GCP and/or AWS, including cloud forensics. * Customer-facing credibility - comfortable representing GitLab Security during customer escalations and high-visibility cybersecurity discussions. * Proactive hunting and threat intelligence - proficiency in threat hunting based on intelligence, and familiarity with supply chain threats targeting SaaS platforms. * AI and automation mindset - experience using AI/LLMs to improve incident response workflows and automate repetitive processes. * Platform familiarity - experience using GitLab (or a comparable DevSecOps platform) for project tracking; bonus if you have experience responding to threats against a SaaS platform. * Prioritization under pressure - ability to make sound operational decisions quickly, escalate issues cleanly, and guide the team on balancing what is urgent versus what is important. Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position. ABOUT THE TEAM The Security Incident Response Team is a globally distributed team of incident response engineers split across three core regions; AMER, APAC and EMEA, and is at the forefront of security events that impact both GitLab’s products and company. We are both proactive and reactive, responding to security alerts, leading security investigations, conducting threat hunts and collaborating with peer Security Operations teams to conduct purple teaming exercises, build threat detections, improve security telemetry and investigate trending threats. Even though we’re a global team, we work together in a cross-regional manner and have automation and processes to facilitate collaboration when resolving incidents, handovers, and general collaboration for project work as well. The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary. United States Salary Range $150,000—$235,000 USD HOW GITLAB SUPPORTS FULL-TIME EMPLOYEES * Benefits to support your health, finances, and well-being * Flexible Paid Time Off * Team Member Resource Groups * Equity Compensation & Employee Stock Purchase Plan * Growth and Development Fund * Parental Leave Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application. ---------------------------------------------------------------------------------------------------------------------------------- Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process. Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us. GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. Technology, Data, and Insights (TDI) is on a mission to accelerate Okta's scale and growth. We bring world-class business acumen and technology expertise to every interaction. We also drive cross-functional collaboration and are focused on delivering measurable business outcomes. The TDI Infrastructure Engineering team owns the foundational platforms that power Okta's business — from cloud infrastructure and AI platform delivery to network engineering, developer productivity, observability, and client platforms. We are a team of builders who design and operate at scale, and we are in the middle of a strategic transformation: evolving our cloud practice from a self-service model into a managed, opinionated platform that the entire business can rely on. THE CLOUD PLATFORM ARCHITECT OPPORTUNITY Okta Federal, Inc. is looking for a dedicated Cloud Platform Architect for TDI Infrastructure Engineering — the technical authority for how we design, build, and evolve the cloud infrastructure that underpins our AI platform and the broader workloads running across the business. You will define the architectural standards, patterns, and strategies that the Cloud Platform Engineering team builds to, and you will serve as a key partner to AI, security, and productivity architects as we scale Okta's cloud capabilities to meet increasing business demand. This is a hands-on builder role. We are not looking for someone who advises from a distance — we need someone who has shipped cloud infrastructure at scale and brings the credibility and depth to make sound architectural decisions in a fast-moving environment. You will operate at a critical moment: Okta's AI platform is scaling rapidly, our cloud platform team is transforming, and the foundational decisions made now will define the trajectory of our infrastructure for years. This role reports directly to the Director of Infrastructure Engineering. WHAT YOU'LL BE DOING * Define and own Okta's Cloud Platform architecture — establish reference architectures, design standards, and guardrails that bring consistency, security, and reliability to workloads running across the business * Lead the architecture for Kubernetes and EKS — design and evolve our cluster strategy, multi-tenancy model, networking topology, and security posture as the platform scales to support AI agent workloads and diverse business unit deployments * Elevate Okta's AI platform — partner with AI architects and platform engineers to evolve our agent and model-serving infrastructure from its current state to a production-grade, scalable platform capable of supporting broad business adoption * Drive multi-cloud strategy — build the evaluation framework and decision criteria for when and how Okta leverages AWS, Azure, and Google Cloud; ensure workload placement is intentional and optimized for performance, cost, and capability * Serve as the technical anchor for the Cloud Platform Engineering team — raise the architectural quality of everything the team designs and builds as we complete the transformation from account vending to a managed platform model * Partner cross-functionally with AI, security, and productivity architects, product managers, and business unit stakeholders to ensure cloud infrastructure decisions align with Okta's product, compliance, and operational requirements — including support for federal programs and FedRAMP environments * Partner cross-functionally to design cloud-native solutions that can be effectively adapted for air-gapped, self-hosted environments like US Secret (SIPRNet) and US Top Secret (JWICS). * Help architect and validate foundational Kubernetes and infrastructure designs within unclassified AWS GovCloud sandboxes. You will ensure these commercial-side designs translate seamlessly when tested against emulators that simulate the strict constraints of air-gapped networks. * Ensure our commercial cloud platform architecture shares foundational DNA with our highly regulated deployments, aligning with DoD-centric frameworks like the USAF's "Big Bang" architecture and utilizing Iron Bank hardened containers where applicable. WHAT YOU'LL BRING TO THE ROLE * 10+ years of hands-on cloud infrastructure experience with deep, demonstrated expertise in one or more major cloud providers (AWS, GCP, or Azure) — including compute, networking, storage, IAM, and managed services at enterprise scale; AWS experience is preferred given our current environment, but strong multi-cloud or GCP backgrounds are equally valued * Proven experience designing and operating Kubernetes and EKS at scale — cluster architecture, multi-tenancy patterns, networking (CNI, service mesh), security hardening, and day-2 operations * Experience architecting infrastructure for AI and machine learning workloads — GPU compute, model serving, data pipeline infrastructure, and the security and access patterns that go with them * Demonstrated experience making intentional cloud provider placement decisions — evaluating workloads against provider capabilities, cost profiles, compliance requirements, and existing organizational footprint rather than defaulting to a single cloud * Strong cloud security background — IAM design, network segmentation, secrets management, policy-as-code, and experience with compliance frameworks (SOC 2, FedRAMP, or equivalent) * Solid understanding of enterprise identity and access management patterns — including federated identity, SSO, and SCIM — and experience integrating cloud workloads and platform services with identity providers such as Okta * Infrastructure-as-code fluency — Terraform, AWS CDK, or equivalent; experience building and maintaining reusable, modular IaC at enterprise scale * Demonstrated ability to influence without authority — experience driving architectural alignment across engineering, security, product, and business stakeholders in a fast-moving organization * Security Clearance: Active U.S. TS/SCI with polygraph. * The selected candidate may be subject to drug testing to the extent required by U.S. Government contracts. EXTRA CREDIT IF YOU HAVE EXPERIENCE IN ANY OF THE FOLLOWING * Experience designing or operating cloud infrastructure for FedRAMP authorized environments or federal programs * Designing infrastructure for completely air-gapped networks, Sovereign Clouds, or DoD Impact Level 6/7 environments. * Hands-on experience building or operating AI agent platforms — orchestration frameworks, vector databases, model routing, or inference optimization * FinOps experience — cloud cost governance, chargeback models, commitment-based discount strategies, and rightsizing at scale * Platform engineering for internal developer platforms (IDP) — developer self-service, golden paths, and guardrails * Service mesh technologies such as Istio or Linkerd in production Kubernetes environments * Kubernetes certifications (CKA, CKS, CKAD) or AWS certifications (Solutions Architect Professional, Security Specialty) * Familiarity with cloud-native security operations platforms such as Google SecOps (Chronicle) — including log ingestion architecture, data residency considerations, and GCP IAM integration patterns * Familiarity with DoD/IC DevSecOps reference architectures and networking, specifically traversing boundaries via cross-domain solution (CDS) and deploying DevOps tools like "Big Bang" via Iron Bank hardened containers. LOCATION This is a US-based role. Candidates must be located in the United States. Okta operates a flexible hybrid work model; specific in-office expectations will be discussed during the hiring process. Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy. Additional requirements: * U.S. soil status - the employee must be on U.S. soil, which means the 50 states, the District of Columbia, or outlying areas of the United States, as defined in Federal Acquisition Regulation (FAR) 2.101 * U.S. Security Clearance status - the employee must be able to obtain and maintain a U.S. security clearance (Secret or Top Secret) to the extent required by U.S. Government contracts. #LI-MK1 #LI-onsite P24721_3470431 Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us. The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $244,000—$336,000 USD The Okta Experience * Supporting Your Well-Being * Driving Social Impact * Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.