Skip to content

Open nowPosted 6 hours ago

Platform Security Engineer

Scality5 open roles

Where
Paris, France
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPlatform Security EngineerScality · Paris, France
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Scality's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted 6 hours ago

The posting

At Scality, we build software that stores and protects the world’s most critical data — running on Linux, inside some of the largest infrastructures on the planet, at exabyte scale, for organizations that cannot afford to fail.

We are looking for a Platform Security Engineer to join our platform and delivery team in Paris. This is a new seat, and it exists because security work needs dedicated capacity. Absorbed as background tasks between feature tickets, it never gets the focus it deserves. You would be that dedicated capacity.

This is a Linux-first, hands-on engineering role. You will not write policies for other people to implement — you will write the Python and Bash that hardens our OS, automates our vulnerability management, and proves to auditors and customers that our supply chain is sound.

About Scality

  • Gartner Magic Quadrant Leader for 9 consecutive years — the only 100% software-defined storage company to hold this position since the quadrant’s inception
  • #1 on the GigaOm Radar for Enterprise Object Storage (2024), ahead of 17 competing vendors
  • Gold Stevie Award 2025 — ARTESCA 3.0, Cloud Storage & Backup Solution category
  • Net Promoter Score of 85 across RING and ARTESCA

About the team

How We Build

How This Role Works

  • Security priorities are owned by our VP of Engineering. The agenda is set at that level, with dedicated resources committed across the teams. You will not have to invent it alone — and you will have a voice in it: the engineers closest to the code help decide what goes on the roadmap. We will be straight with you: today security work competes with delivery commitments and too often loses. Naming an owner and funding dedicated people is how we intend to change that. You would help build that capability, not inherit a finished one.
  • The team is accountable for the deliveries. Security items sit on the team’s plate alongside everything else it commits to, rather than in a separate function filing tickets from the outside.
  • You are the dedicated resource that makes them happen. While your teammates carry releases, OS compatibility, and platform features, your time is reserved for the security work. That focus is the whole reason the seat exists.
  • You share the team’s perimeter and its knowledge. Same repositories, same Jira projects, same code reviews, same sprint rituals. The engineers around you have rare, hard-earned Linux depth — OS integration, RPM packaging, boot and GRUB, CI/CD, monitoring — and you will learn the platform from them.
  • You will have peers. Security engineers embedded in the other development teams work the same problems on different perimeters. That network is where you compare notes, share tooling, and grow into the craft.

Your First Missions

  • A standing exposure record, per shipped component and per release: what the SBOM says is present, what the upstream vendor has decided (including “will not fix”, which is common on RHEL 8 and often the real answer), and whether the vulnerable code path is actually reachable in our configuration
  • Reachability over presence. A module shipped and loaded by a distribution default is not the same as a module configured on a live URL. That distinction is the difference between “vulnerable” and “no impact”, and it is where the engineering judgement lives
  • Continuous CVE detection across our repositories, vendored third-party modules, container images, and shipped RPMs
  • Wiring detection into our existing SBOM tooling and GitHub Actions pipelines, so exposure is computed when a release is built rather than when a customer asks
  • A defined interface with the security engineers and the customer-facing teams: who produces the technical assessment, who owns the wording that reaches the customer, and how both meet the response commitments in our customer security policy
  • Durable capture. An assessment that lives only in a ticket comment gets re-derived next release. Findings belong somewhere queryable
  • A remediation loop with clear ownership and response targets, integrated with how the team already works in Jira
  • AI-assisted remediation, where it fits: from advisory to proposed patch to a tested build, with a human deciding what ships
  • A hardened, defensible default configuration for the distribution
  • Advancing SELinux enforcement across RING and S3C (work already begun on the team, which you will help carry)
  • Supply-chain integrity: artifact provenance, signing, dependency currency, reproducible and verifiable builds
  • Secrets and credential handling across the delivery pipeline
  • Cryptographic posture — including FIPS 140-3 readiness, which matters concretely: FIPS 140-2 certificates move to NIST’s historical list on 22 September 2026, and RHEL 9’s validated OpenSSL, GnuTLS, and kernel crypto modules are the foundation we build on
  • Compliance-driven engineering work, notably the supply-chain security expectations of NIS2 (Article 21(2)(d)) and the EU Cyber Resilience Act — translated into automation and evidence, not spreadsheets

What We Are Looking For

  • Linux is your primary operating system — at work, at home, or both. You are comfortable in the terminal and you reach for a shell before a UI
  • Roughly 2–4 years of relevant experience, or a shorter track record with unusually strong evidence of the skills below
  • Solid working ability in Python and Bash — you will be writing and maintaining real code in a production codebase
  • A genuine, demonstrable interest in security. We care much more about this than about formal credentials. Show it however it is true for you: CTFs, a home lab, reading advisories and CVE writeups for fun, a hardening project, security-adjacent contributions, a blog, anything real
  • Comfortable using Git in a collaborative environment
  • Ability to read and understand existing code before modifying it
  • The judgement to tell a real risk from a scanner’s opinion — and the instinct to check whether vulnerable code is actually reachable before calling it exposed
  • The willingness to say plainly when you are not yet sure, rather than producing an answer you could not defend
  • French — the team works in French day to day
  • Written communication skills in English
  • CVE triage, CVSS scoring, or vulnerability management experience
  • Reading vendor advisories and understanding vendor triage — NVD, RHSA, Red Hat severity and will-not-fix calls
  • Supply-chain security tooling — SBOM formats (SPDX, CycloneDX), scanners (Trivy, Grype, Syft), artifact signing
  • RPM packaging or Linux distribution internals
  • SELinux policy work
  • CI/CD systems, especially GitHub Actions
  • RHEL / Rocky Linux (versions 8 and 9)
  • Containers (Docker, containerd, systemd units)
  • Ansible or Salt
  • Awareness of NIS2, the Cyber Resilience Act, or FIPS 140-3
  • Familiarity with S3 or object storage concepts
  • Serious use of AI coding tools in a real workflow — Claude Code or equivalent, beyond autocomplete

What We Offer

  • Dedicated focus. Security is your job here, not the thing you get to after the sprint work is done
  • Clear direction, and a say in it. Security priorities are owned by our VP of Engineering, and the team is accountable for delivering them. You would not be inventing the agenda on your own, you would help shape what goes on it, and you would be part of making it stick
  • A network of peers. Security engineers embedded in the other development teams, working the same problems on different perimeters
  • Work that compounds. Customer security questions are a permanent obligation, so every assessment you make reusable and every check you automate keeps paying back, release after release
  • Modern tooling, actually adopted. Claude Code in every engineer’s hands, and a real say in how AI reshapes our build and delivery chain
  • A rare combination: security work with the leverage of owning the whole stack, down to our own Linux distribution
  • Mentorship from senior engineers with deep expertise across Linux, storage, packaging, and distributed systems — you will not be the only person who understands your perimeter
  • A long-term growth path toward becoming your team’s security reference and a senior voice in the network
  • Work that ships to production and runs at exabyte scale, in banking, healthcare, and government
  • Standard French benefits: meal vouchers, Navigo subsidy, mutuelle
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Scality's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Scality's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Scality's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.