NS

Senior Infrastructure & Security Engineer

Salary
€75K–€95K
EUR per year
Hiring from
France
Work type
Remote
Posted
Oct 4, 2026
Is this job info correct?

Senior Infrastructure & Security Engineer | GCP, SOC 2, ISO 27001 | Remote (France)


Be the first infrastructure and security engineer at a startup that sells to France's largest companies. You'll build a platform that stays up and a security posture that passes audits, with a deliberate path to the CISO seat.


The company

A Paris-based B2B SaaS startup, less than a year old, that helps large shippers cut both their freight costs and their CO₂ emissions. It was founded by five partners: tech entrepreneurs and experts who have advised the transport departments of large corporations for more than twenty years. Two CAC 40 groups are already customers, the seed round is closed, and the tech team is deliberately small and very senior.


The role

Every enterprise deal goes through procurement, security questionnaires and external audit. You'll own the infrastructure and security foundations that make those deals possible. The platform runs on GCP (Cloud Run, Cloud SQL, GCS), with isolated environments designed in from day one: nothing to retrofit, everything to build. The SOC 2 and ISO 27001 program kicked off in September 2026 with an external specialist, on Vanta, so you'll shape the controls rather than inherit them.

Time split: roughly 50% platform and SRE, 25% security engineering, 25% compliance.


What you'll build

  • The full GCP footprint under Terraform or Pulumi: projects, IAM, networking, services, databases, storage, secrets.
  • CI/CD pipelines on GitHub Actions, with progressive rollout and rollback.
  • SLOs that reflect what enterprise clients care about, a complete observability stack, and incident management that follows through.
  • Network and IAM security, security in the development lifecycle, the threat model and vulnerability management.
  • The technical side of SOC 2 and ISO 27001: controls, evidence automation, technical policies, and answers to client security teams.


What we're looking for

Must-haves

  • 5+ years in SRE, platform, infrastructure or DevOps roles, with real production ownership.
  • Deep, hands-on GCP experience (IAM, VPC, Cloud Run, Cloud SQL, GCS, Secret Manager, Cloud Armor). AWS or Azure on top is a plus, not a substitute.
  • Production-grade Terraform or Pulumi: module design, state management, drift handling, plan reviews.
  • A language beyond YAML: TypeScript, Python or Go.
  • Solid Linux, networking, TLS and PKI fundamentals, and a good grasp of database operations.
  • Hands-on SOC 2 and/or ISO 27001 experience: controls implemented, evidence produced or an audit cycle completed.
  • The ability to hold a credible conversation with an auditor or a client's security team.


Nice-to-haves

  • Multi-tenant SaaS with strict data isolation.
  • The Bun / TypeScript ecosystem or serverless container platforms.
  • Securing LLM-based systems.
  • Certifications (ISO 27001 Lead Implementer, CISSP, CCSP, GCP Professional Cloud Security Engineer), on top of hands-on work.
  • French.


What you'll find here

  • A first-hire role, with real decisions to make.
  • A path to the CISO / Head of Security seat: owning the security management system, the security roadmap and eventually a team, as certifications land and the company grows.
  • No 24/7 on-call: production support during business hours, with the CTO as backup.
  • Compliance that matters: controls with real engineering value, not checkbox theatre.


Compensation and conditions

  • €75,000 to €95,000 gross annual base salary, plus BSPCE (French employee stock options).
  • Permanent contract (CDI); freelance also possible.
  • Remote from anywhere in France; Paris-based candidates welcome.
  • Health insurance, meal vouchers, public transport reimbursement.


Hiring process

  1. Phone call with the recruitment firm.
  2. Technical interview with the CTO: infrastructure, cloud architecture and your approach to the SOC 2 / ISO 27001 program.
  3. Practical exercise: threat modelling or infrastructure-as-code review on a realistic scenario (2 hours max).
  4. Interview with the founders.


Similar jobs

Apply on LinkedIn