372,956open jobs
9,661companies
50,233added this week
Browse all
Salary
$93k – $139k per year
Location
Remote (France)
Seniority
Principal · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Pigment is a SaaS company that builds planning and performance management software for organisations that need a clearer, faster way to budget, forecast and track results. Many finance and business teams still rely on spreadsheets or older planning tools that are difficult to maintain, slow to update, and hard to share across departments. Pigment’s product is designed to bring financial and operational planning into a single platform, so teams can model different scenarios, collaborate on assumptions, and keep plans aligned as business conditions change.

Reporting to the CISO, you'll own the security roadmap for Pigment's product, infrastructure, and CI/CD environment, and you'll build much of it yourself.

This is a hands-on role: expect to read code, threat model new services, reproduce and triage vulnerabilities, dig through infrastructure configuration and build the automation that closes gaps.

You'll also set direction and bring product and engineering with you, but that influence comes from technical credibility and not process: the engineers you work with will take you seriously because you've been in the same code they have.

The scope is broad: application security, infrastructure security, detection and response, and the assurance work that keeps our certifications standing. You won't be covering it alone. The security team is seven people and growing, with colleagues already owning compliance, governance and security operations, so this role can go deep on product and infrastructure and not be spread too thin across everything. Nobody arrives fluent in all of it: we're looking for real depth in several of these areas and the judgement to grow into the rest.

Key responsibilities include:

  • Product & Infrastructure Security Design - Design security features into the product itself and strengthen defence-in-depth across the platform. Threat model new services before they ship, and make the architectural calls that are expensive to reverse later.

  • Security Review & Risk Assessment - Review code, architecture and configuration yourself, and be the person developers and PMs bring problems to early rather than late. Deliver solutions that balance risk against business benefit, and escalate the calls that genuinely need senior arbitration.

  • Assurance & Testing - Run our assurance programme: internal code, architecture and configuration reviews, red team exercises, and the bug bounty. Own the relationship with third-party auditors, and measure the control KPIs that keep our certifications defensible.

  • Vulnerability Management - Own vulnerabilities from detection through to verified fix: reproduce them, score and triage them, design or validate the mitigation, and confirm it actually worked. Improve the KPIs that tell you whether the process is holding.

  • Detection Engineering - Build and improve our detection capability alongside the infrastructure and engineering teams: identify the signals worth collecting, write rules that catch real attacks without drowning us in noise, and build the response playbooks behind them.

  • Incident Response - Lead security investigations into the production environment end to end, from first signal to root cause, across incidents and fraud. Flag the repetitive work worth automating and the detections worth building, and hand those to the security operations team.

  • SDLC - Set the technical direction for how engineers at Pigment build securely: guidance, paved paths, and reviews that teach and not just gate. Contribute to company-wide awareness where it counts, but your primary audience is product, engineering and SRE.

Example projects that would fall under your responsibilities (actual examples of recently completed or currently on the roadmap):

  • Secure the design and development of our AI features, including the MCP Server and Modeler Agent: threat modelling, design reviews, working alongside the engineers building them, and security assessments.

  • Work out where AI-assisted analysis actually belongs in our pipeline. AI-powered security reviews reason about a diff semantically rather than pattern-matching it, which is genuinely different from classic SAST - but it's not a drop-in replacement, and figuring out the split between AI review, traditional SAST and SCA is an open question we'd like you to answer with evidence rather than vendor claims.

  • Migrate GitHub to managed identities: provisioning through Okta, retiring personal accounts and long-lived PATs, and moving CI to short-lived OIDC credentials instead of stored keys.

  • Design agent identity for the MCP Server - delegated access tokens, token exchange, and making sure an agent acting for a user can never exceed what that user could do themselves.

  • Push least privilege further across production and CI/CD. Better than it was, not where we want it.

For a concrete example: here 's how we built a sandboxed execution environment for LLM-generated code.

Technical Environment

Mostly production, with the occasional internal IT-adjacent project:

  • Main sites in Paris, London, Toronto and NYC

  • MacOS, Windows, Linux workstations

  • GCP, Kubernetes, Terraform, Postgres, SingleStore, Vault

  • Okta, OAuth, JWT, C#, .NET Core, TypeScript, React, Python, Go

  • Datadog (SIEM), CloudFlare ZTNA, Falco, Wiz, Riot, HackerOne, TruffleHog

  • Google Workspace, Jumpcloud, Vanta, Hibob, Slack

  • GitHub, CircleCI, ArgoCD

  • SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001

Who you are

You have at least 8 years of experience in security as a Security Engineer, Pentester or Security consultant, with real depth in product and/or infrastructure security. We care more about the scope of what you've owned than the exact number of years.

What you've done

  • Owned a security roadmap for a product or platform end to end, rather than delivering items on someone else's

  • Driven security work through engineering teams you had no authority over

  • Been the person your organisation escalated to on hard architectural calls

  • Worked hands-on across a broad technical surface - development, databases, networking, web

How you work

  • You're hands-on and intend to stay that way (this position does not include people management)

  • You look for the workable answer, not the blocking one

  • You have a good dose of humility, and you help the people around you get better

  • You speak English fluently, French is a strong plus

How we hire

After a first call with our recruiter, five conversations, around four hours in total, usually over two to three weeks:

  • Ways of working (45 min) - how you operate with people, and what draws you to this role specifically.

  • Technical deep dive (1h30) with a security engineer - including a practical. We'll give you a real problem we've already solved and talk through how you'd approach it.

  • Cross-functional (45 min) with an engineer from product or platform - someone who'd be on the receiving end of your work.

  • Ownership and career (1h) with the CISO and a member of the security team.

  • Final (45 min) with our co-founder and CTO.

What we offer

  • Competitive package
  • Stock options to ensure you have a stake in Pigment's growth
  • The best health insurance with Alan Blue, entirely free for you and your family
  • Weekly Lunch and Lunch vouchers (Swile card) to cover your lunch breaks with total flexibility
  • Subscription to Egym Wellpass (ex-Gymlib) for full access to gyms, studios, and wellness spaces across France
  • A Learning Stipend per year, for you to develop into areas that amplify impact for your careers or personal development
  • Remote work stipend to have the best work station possible at home
  • Along with one company offsite every year, we have brand new offices at the heart of major cities including New York, San Francisco, Toronto, Paris, and London
  • High-end equipment (based on stock/availability) to do your work in the best conditions
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
372,956 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$17k – $43k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Hyderabad
Node JS
Python
SQL
JavaScript
Databases
Databricks
Google BigQuery
Snowflake
AI/ML
Anomaly Detection
Frontend
GraphQL
React.js
DevOps
AWS
Azure
Azure DevOps
CI/CD
GCP
Git
GitHub Actions
Jenkins
GitHub
Analytics
ETL/ELT
QA
Cypress
JMeter
k6
Locust
Playwright
Postman
Pytest
Selenium
Apply
$110k – $186k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Alpharetta
DevOps
CI/CD
Git
Cybersecurity
ISO 27001
PCI DSS
Threat Modeling
Least Privilege
Apply
$25k – $65k per year (Estimated) • In office • Full-Time • 10+ years exp • India
Java
SQL
Java
Hibernate
Spring Boot
Spring Framework
Databases
Apache Kafka
AI/ML
Airflow
DevOps
AWS
Azure
Azure DevOps
CI/CD
Docker
GCP
GitHub
GitHub Actions
Incident Management
Jenkins
Kubernetes
Rest API
Apply
SDET Specialist 1 hour ago
$26k – $56k per year (Estimated) • In office • Full-Time • 9+ years exp • Bachelor's Degree • India
C#
JavaScript
PowerShell
Python
SQL
Databases
Oracle
AI/ML
AI Agents
Copilot
LLM
Model Context Protocol
Prompt Engineering
RAG
DevOps
Bamboo
CI/CD
GitHub
Jenkins
Cybersecurity
SonarQube
QA
Cucumber
Playwright
Postman
Selenium
Apply
$26k – $65k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Pune
PowerShell
Python
AI/ML
AI Agents
LLM
LLM Guardrails
Model Context Protocol
DevOps
AWS
Azure
CI/CD
GCP
Git
Rest API
Splunk
Cybersecurity
Crowdstrike
Microsoft Entra ID
Microsoft Sentinel
MITRE ATT&CK
Okta
SentinelOne
Apply
$76k – $139k per year • Remote/Hybrid • Full-Time • Paris
C#
C++
Go
Java
Python
Ruby
Rust
TypeScript
JavaScript
C#
.NET
Databases
PostgreSQL
RabbitMQ
Snowflake
Frontend
React.js
DevOps
CircleCI
Docker
GCP
Kubernetes
Terraform
Apply
Senior AI Scientist 20 days ago
$94k – $192k per year (Estimated) • Equity • Remote • Master's Degree • London
Python
Databases
Snowflake
AI/ML
Fine-tuning
LangChain
LangGraph
LLM
NLP
PyTorch
Scikit-learn
TensorFlow
Time Series Forecasting
AI Agents
Apply
$86k – $163k per year (Estimated) • Equity • Remote • 8+ years exp • London
C#
C++
Go
Java
Python
Ruby
Rust
TypeScript
JavaScript
C#
.NET
Databases
PostgreSQL
RabbitMQ
Snowflake
Frontend
React.js
DevOps
CircleCI
Docker
GCP
Kubernetes
Terraform
Apply
$64k – $152k per year (Estimated) • Remote/Hybrid • Full-Time • PhD • London
Python
Apply
$65k – $157k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • Master's Degree • Paris
Apply
See all jobs
This is one of many
372,956 more open roles from verified company boards, updated every day.