Careers
Principal Architect – Application Security and DevSecOps
About Quantum Beyond
Quantum Beyond advises companies and organizations on their strategic decisions relating to technology, artificial intelligence, cybersecurity, digital sovereignty, and organizational transformation. The company also develops advanced products and infrastructure in the fields of security, digital trust, AI, and communications.
Your mission
You will embed security throughout the entire design, development, testing, and deployment lifecycle of Quantum Beyond's products and solutions. You will also contribute to client engagements requiring advanced expertise in application security and DevSecOps.
Key responsibilities
- Define secure application architectures.
- Take part in threat modeling.
- Design secure development standards and practices.
- Integrate controls into development pipelines.
- Deploy static, dynamic, and software composition analysis.
- Govern the security of APIs and inter-system exchanges.
- Ensure the secure management of secrets and certificates.
- Evaluate software libraries and dependencies.
- Take part in critical code reviews.
- Define component signing and integrity mechanisms.
- Harden build and deployment environments.
- Design security controls for containers and infrastructure.
- Oversee application security testing.
- Support the remediation of vulnerabilities.
- Produce the necessary documentation and evidence.
- Train and support development teams.
Profile sought
- A minimum of 8 years of experience in application security, development, or DevSecOps.
- Solid experience in secure software architecture.
- A command of the risks related to web, mobile, and API applications.
- Experience with continuous integration and deployment pipelines.
- The ability to write code, review code, and automate controls.
- An understanding of cloud and containerized environments.
- The ability to work with architects, developers, and researchers.
- Excellent technical and documentation rigor.
- Professional French and English.
Assets
- CSSLP, CISSP, OSWE, GIAC, or equivalent certification.
- Experience in applied cryptography.
- Knowledge of software bills of materials and supply chain risks.
- Experience in mobile development or embedded systems.
- Involvement in high-assurance security projects.
- Contributions to open source projects.
Conditions
Location (on site and remote), compensation based on experience, benefits, and working arrangements: to be discussed or determined...
Submit your application
Send us your résumé along with a short introductory note.
