Retour aux offres d’emploi

Cybersecurity engineer - DevSecOps expert (f/m/d)

Our Security Engineering team is seeking a Cybersecurity engineer based in Paris or Lille. 

The Cybersecurity team is at the heart of the company, fueling the existing business model, building the new digital ecosystem, protecting the Decathlon brand and building customer trust.  The team is made up of 3 core areas (digital risk management, architecture, security operations) and a network of over 80 security referents worldwide.

As part of the Group's Cybersecurity teams, we are looking for a Cybersecurity engineer with DevSecOps expertise. Possessing excellent communication skills in an international context, the main mission will be to lead our Secret Management, Key Rotation initiative and to ensure the Maintenance in Operational Condition (MCO) of DevSecOps tools.

Your responsibilities:

  • Implement a comprehensive Secret Scanning solution for the company and develop tools around this solution (scripting/reporting).
  • Build a unified enterprise-wide process to automate key renewal (Automated Key Rotation) by collaborating with business, development, and infrastructure teams.
  • Effectively communicate complex security concepts to diverse audiences, from technical teams to management.
  • Create clear and concise documentation and presentations on best practices for Secret Management and Key Rotation and keep them up to date.
  • Regularly lead workshops and training sessions to educate teams across the organization.
  • Define and maintain Key Performance Indicators (KPIs) for the Secret Management and our Key Rotation program.
  • Drive the integration of Secret Scanning and Key Rotation tools into our DevSecOps pipeline.
  • Analyze the results from Secret Scanning tools and provide actionable insights to the relevant teams.
  • Act as a security ambassador, promoting a culture of security awareness throughout the organization.

 

  • Be responsible for MCO (Maintaining Operational Conditions) or MRO (Maintain, Repair & Operations) and the continuous improvement of DevSecOps tools, namely SAST, SCA, and Secret Detection, in collaboration with another Technical Security Engineer.
  • Manage our customer tickets related to our application security tools.
  • Actively participate in the DevSecOps program within Decathlon Digital as a direct contributor and expert through active involvement in:
    • the training of the Security Champions community
    • awareness events
    • promoting the culture and best practices of DevSecOps

 

What you will need to succeed:

  • A degree in Computer Science, Cybersecurity, or related field
  • Minimum of 3 years of experience in IT security, with a focus on AppSec (Application Security)
  • Strong communication skills, both written and oral, with proficiency in:
    • Simplification: Explaining technical concepts to non-technical audiences
    • Documentation: Writing and maintaining up-to-date documentation and providing regular, clear, and comprehensive reports
    • Presentation: Delivering presentations and training
    • Collaboration: Facilitating communication among various stakeholders outside the Security teams
  • Solid knowledge of Secret Scanning tools, key management systems, and automated rotation techniques
  • Familiarity with SAST (Static Application Security Testing) & SCA (Software Composition Analysis) tools
  • Experience with DevSecOps practices in CI/CD pipelines
  • Proficiency in Python programming language
  • Familiarity with the application development lifecycle
  • Mastery of authentication and authorization tools and protocols
  • Experience with cloud environments (AWS, GCP, Azure)
  • Understanding of common security vulnerabilities (OWASP) and attack vectors
  • Demonstrated ability to work effectively with diverse teams in business, development, and infrastructure domains
  • Proficiency in English; additional languages are a plus

Compétences souhaitées :

  • Expérience en technical writing (documentation, blog posts, whitepapers, etc)
  • Expérience avec SAST (Static Application Security Testing) , SCA  (Software Composition Analysis), DAST (Dynamic Application Security Testing) et autres application security tools
  • Connaissance de la conteneurisation et de la sécurité du runtime et cloud accounts
  • Familiarité avec les compliance standards relatifs à la data protection et best practices liées au key management
  • Familiarisation avec les security audits ou penetration testing

WHAT YOU GET

  • Work from home up to 2 days per week
  • Opportunity to work in either of Decathlon Technology's offices in Lille or Paris (with regular travel to Lille, at a frequency of 2 or 3 days every 15 days).
  • Hardware provided in accordance with your missions and our social commitments (Mac, Windows, Chromebooks)
  • A local project team and within a global network (international career path)
  • Skills development and mentorship (diversity of projects, technical certification from the first year, internal and external training, etc.).

Remuneration package (employee share ownership, monthly/quarterly bonuses)

 

DECATHLON DIGITAL CONTEXT 

What if technology allowed us to push the boundaries and take sports experiences to new levels? That's exactly our goal at Decathlon Digital! We are a team of 5,000+ experts in software engineering, product management, data, cloud, and cybersecurity, distributed across Paris, Lille, and Amsterdam. Together, we are creating the largest digital sports platform, leveraging tech innovation from design to value chain optimization, connected experiences and product second life.


Changing the game for good. We are in this for the love of sports. And like everything we love, we want it to last. That’s why we are embarking on a journey to create a more sustainable tech model, reducing our direct environmental impact while maintaining a safe, diverse, and inclusive space for all our people to learn and thrive together. Team up with us to design the digital future of sports.

Postuler à ce poste

*

indique un champ obligatoire

CV

Types de fichiers acceptés : pdf, doc, docx, txt, rtf

Lettre de motivation

Types de fichiers acceptés : pdf, doc, docx, txt, rtf

Select...

RGPD : Lorsque vous postulez à une offre d'emploi sur ce site, les données personnelles concernant votre candidature seront collectées par Decathlon SE, (" Responsable du traitement "), qui est situé au 4 Boulevard de Mons 59650 Villeneuve d'Ascq. Vos données personnelles seront traitées aux fins de la gestion des activités de recrutement du Responsable du traitement. Vos données personnelles seront conservées par Decathlon SE pendant la durée nécessaire à l'évaluation de votre candidature à un emploi sans que cette durée n'excède 2 ans. 

 

  • Vous disposez du droit d'accéder à vos données personnelles, de demander qu'elles soient rectifiées, effacées, et de demander que leur traitement soit limité.
  • Vous disposez également du droit de demander leur portabilité.
  • Vous pouvez accéder à ces droits en cliquant ici.
  • Par ailleurs, vous pouvez également consulter notre politique de confidentialité pour plus d'informations sur les traitements effectués.

 

GDPR : When you apply to a job on this site, the personal data contained in your application will be collected by Decathlon SE, (“Controller”), which is located at 4 Boulevard de Mons 59650 Villeneuve d'Ascq.  Your personal data will be processed for the purposes of managing Controller’s recruitment related activities. Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment but for no longer than 2 years. 

 

  • You have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted.
  • You also have the right to data portability. You can request these rights by clicking here. 
  • In addition, you can also visit our privacy policy for more information on the processing carried out.

Diversity & non discrimination policy / Politique de diversité et de non discrimination

As part of our diversity and non-discrimination policy, Decathlon Digital wants to ensure that gender, disability, or age of our candidates are not a factor in our decision. If you wish, we suggest that you provide us with this information. This data will be anonymized and used in the macro analysis of the diversity of applications received. This information will be kept separate from your application and will have no effect on its processing.

___________________

Dans le cadre de sa politique de diversité et de non discrimination, Decathlon Digital souhaite s'assurer que le genre, le handicap, ou l'âge de nos candidat·e·s ne sont pas des facteurs de décision. Si tu le souhaites, nous te proposons de nous indiquer ces informations. Ces données seront anonymisées et utilisées dans l'analyse macro de la diversité des candidatures reçues. Ces informations seront séparées de ta candidature et n'auront donc aucun effet sur le traitement de celle-ci.

Select...
Select...
Select...