Jobs and Careers
CO

Security Engineer (Devsecops & Incident responder)

Contentsquare
Spainfull_timeVerifiedPosted 29 Sept 2023

About the role

Contentsquare is a global digital analytics company empowering the brands you interact with every day to build better online experiences for all. Since our founding in France in 2012, we have grown to be a truly global and distributed team – known as the CSquad – representing more than 70 nationalities across the world.<br/>In 2022, we raised $600M in Series F funding and were recognised as a certified Great Place to Work in France, Germany, Israel, US and UK.<br/>Please Note: Scammers are posing as Contentsquare and Contentsquare team members. We’ll never initially contact you via text or GChat, and never solicit money from you. Please visit our careers blog for more information.<br/><br/>The Contentsquare security team is looking for a focused security engineer who can take on a leadership role in responding to security issues. As such, you’ll need to have practical security experience and knowledge of the state of the art for detecting and responding to attacks. The ideal candidate will thrive in high-pressure situations and drive relevant teams to take the right decisions to mitigate the security risks in a timely manner.As part of the Security Team, you will be reporting directly to the Senior Manager, Cyber Security. You will be working closely with our R&amp;D team. Your main task will be to ensure the integrity of Contentsquare’s products and for keeping Contentsquare’s users and customers safe. You will work out of our Paris (Headquarters), Barcelona or Remotely. <h3>What you will do as a Security Engineer </h3> <ul> <li>Confidently and thoughtfully respond to security incidents, and proactively consider how to prevent the same type of incidents from occurring in the future</li><li>Design and coordinate cohesive responses to security events that involve multiple teams across the organisation</li><li>Develop security utilities and tools for internal use that enable you and your fellow Security Engineers to operate at high speed and wide scale</li><li>Design and maintain a portfolio of security alerts, automated actions and escalation workflows in support of an impactful 24/7 incident response capability</li><li>Improve the ability to respond to threats by leading new technology selection, configuration, internal product development, obtaining-buy-in, and implementations with a heavy emphasis on automation</li><li>Evaluate the impact to the organisation of current security trends, advisories and public exploits. Coordinate responses as necessary across affected teams to do the right thing for our customers and our organisation</li><li>Handle and extend our security detection capabilities (SIEM, WAF, honeypot, open source tools)</li><li>Constantly audit our technical platform and application to ensure the follow-up of security best-practices and identify security misconfigurations</li><li>Recognize, embrace and share the best practices on security engineering fields throughout the organisation: development, network security, application security, cryptography, security operations, incident responses</li><li>Communicate efficiently (in English) at multiple levels of sensitivity and multiple audiences</li><li>Fulfil regular on-call responsibilities</li><li>Establish metrics that demonstrate continuous improvements of the Security Incident Response Engineering capabilities and execute on your proposed strategy for improvements</li></ul> <h3>What you will need to succeed in this role</h3> <ul> <li>2-3 years of previous practical experience on Security Operations, especially experience coordinating responses to security incidents </li><li>Experience in building effective partnerships with internal customers </li><li>Experience building out detection and response programs for a SaaS or cloud-native company</li><li>Solid experience with developing security toolings and integrating security layers to Devops pipelines</li><li>Extensive knowledge of web protocols, security issues, common attacks, Linux/Unix tools, cloud architectures and threat landscape</li><li>Expertise with Security Information and Event Management (SIEM), such as: Wazuh / OSSEC and ELK</li><li>Familiarity with incident platforms, e.g. PagerDuty, TheHive</li><li>Deep knowledge of our technical stack and how to secure it :</li><li>AWS and Azure</li><li>Kubernetes / Docker</li><li>Ansible, Terraform</li><li>Datadog ASM as WAF</li><li>Github Action, Jenkins</li><li>Solid scripting skills: shell, python</li><li>Nestjs, Vuejs, Angular</li><li>Solid understanding of security concepts, standard methodologies and how to apply them, such as SSH, public key encryption, access credentials, certificates, TLS, data encryption, OWASP top 10</li><li>Analytical skills, Autonomy and Accountability</li><li>Fluent in english (French is a plus)</li><li>Solid understanding of MITRE ATTACK, NIST or similar threat frameworks is strongly preferred</li></ul>Why you should join Contentsquare:<br/><br/>▪️ We’re humans first. We hire dedicated people and provide them

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Contentsquare

View company profile →