About this job
<h3>About Kestra</h3><p style="min-height:1.5em">Kestra is the <strong>universal orchestration platform</strong>: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.</p><p style="min-height:1.5em">Trusted by <strong>over 10,000 organizations worldwide</strong>, including <strong>JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole</strong>, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to <strong>30,000 GitHub stars</strong>, hundreds of contributors, and a fast-growing global community.</p><h3>About the role</h3><p style="min-height:1.5em">Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise.<br /><strong>You would be our first dedicated security hire.</strong> We're looking for a <strong>Senior Security Engineer</strong> to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.<br />This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.<br /><strong>This is a hands-on engineering role, not a GRC or compliance one.</strong></p><h3>What you would do</h3><p style="min-height:1.5em">Your first six months would focus on the first three points below. The rest is where the role grows.</p><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Conduct hands-on penetration testing</strong> and threat modeling across our web application, APIs, control plane, and cloud environments.</p></li><li><p style="min-height:1.5em"><strong>Manage end-to-end vulnerability tracking</strong> across our codebases, software dependencies (SCA), container images, and cloud infrastructure.</p></li><li><p style="min-height:1.5em"><strong>Proactively fix security flaws</strong> by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.</p></li><li><p style="min-height:1.5em"><strong>Audit and harden our cloud infrastructure</strong> (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.</p></li><li><p style="min-height:1.5em"><strong>Automate security tooling</strong> into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.</p></li><li><p style="min-height:1.5em"><strong>Perform security code reviews</strong> and evaluate third-party dependencies, open-source integrations, and supply-chain risks.</p></li><li><p style="min-height:1.5em"><strong>Lead incident response</strong> efforts and establish continuous monitoring, detection, and mitigation strategies.</p></li><li><p style="min-height:1.5em"><strong>Own our public security posture </strong>as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem.</p></li></ul><h3>Our Tech Stack</h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Security & Vulnerability Tools</strong>: Trivy, GitHub Security / Dependabot, Elastic Security </p></li><li><p style="min-height:1.5em"><strong>Infrastructure</strong>: Docker, Kubernetes, Terraform</p></li><li><p style="min-height:1.5em"><strong>Cloud</strong>: GCP</p></li><li><p style="min-height:1.5em"><strong>Programming language</strong>: Java, Typescript, Javascript</p></li><li><p style="min-height:1.5em"><strong>Datastore</strong>: PostgreSQL, Elasticsearch</p></li><li><p style="min-height:1.5em"><strong>Queuing</strong>: Redis, Kafka, AMQP</p></li><li><p style="min-height:1.5em"><strong>Monitoring & Logs</strong>: ELK, Prometheus, Grafana</p></li><li><p style="min-height:1.5em"><strong>Deployment & Repository</strong>: GitHub Actions, ArgoCD</p></li></ul><h3>What we are looking for</h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>5+ years of experience</strong> in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.</p></li><li><p style="min-height:1.5em"><strong>Strong hands-on penetration testing background</strong>, with proven ability to discover application, API, and network-level vulnerabilities.</p></li><li><p style="min-height:1.5em"><strong>A builder/fixer mindset</strong>: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.</p></li><li><p style="min-height:1.5em"><strong>Deep familiarity with cloud security</strong> (AWS or GCP) and containerized environments (<strong>Kubernetes</strong>, Docker).</p></li><li><p style="min-height:1.5em">Experience with <strong>dependency and supply-chain security</strong> (CVE management, open-source licensing, SCA tools).</p></li><li><p style="min-height:1.5em">Fluent in English and comfortable working autonomously in a fully remote environment.</p></li><li><p style="min-height:1.5em">Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.</p></li></ul><h3>Perks & Benefits</h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Work from anywhere</strong>: We’re a remote-first company, so you can work from wherever feels like home. Plus, you’ll have access to coworking spaces worldwide if you ever need a change of scenery.</p></li><li><p style="min-height:1.5em"><strong>Health coverage</strong>: From medical support, dental, and vision, we've got you covered.</p></li><li><p style="min-height:1.5em"><strong>Home office setup on us</strong>: We’ll provide all the equipment you need to work comfortably.</p><div style="min-height:1.2em;margin-top:0;margin-bottom:0"> </div></li></ul><h3>Our Hiring Process</h3><p style="min-height:1.5em">We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.</p><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Intro call</strong> with the hiring manager (30 min)</p></li><li><p style="min-height:1.5em"><strong>Technical scenario / Practical assessment</strong> (2 hours, asynchronous homework focusing on threat assessment and remediation)</p></li><li><p style="min-height:1.5em"><strong>Team chat</strong> with one of your future colleagues (30 min)</p></li><li><p style="min-height:1.5em"><strong>Final discussion</strong> with one of our co-founders (30 min)</p></li></ul><p>Find more <a href="https://www.arbeitnow.fr/english-speaking-jobs">English Speaking Jobs in France</a> on Arbeitnow</a>