- Assess the current DevSecOps maturity and define a clear roadmap in coordination with the Architecture Committee.
- Prioritize actions using a global risk-based approach — not only security risk — adapted to Wakam’s context.
- Define performance and reliability metrics for security processes.
- Support development and operations teams on day-to-day security topics.
- Put business and technical risks into perspective to help teams make informed decisions.
- Train and raise awareness among teams on security best practices, including secure coding, threat modeling, and related practices.
- Help build a sustainable DevSecOps culture across the organization.
- Integrate SAST, DAST, and SCA tests directly into CI/CD pipelines with optimized response times.
- Design and deploy fast, reliable, parallelized security test suites with immediate feedback for developers.
- Document data flows and model attack surfaces from the design phase.
- Deploy and configure static and dynamic analysis tools such as SonarQube, Trivy, Snyk, OWASP ZAP, and similar solutions.
- Orchestrate secure deployments through CI/CD pipelines, including automatic rollback mechanisms and multi-level validation.
- Develop custom automation tools when market solutions do not fully meet Wakam’s needs.
- Implement Infrastructure as Code (IaC) with embedded security controls using tools such as Terraform and Ansible.
- Ensure full versioning of code, infrastructure, configurations, and security policies.
- Manage secrets and certificates through dedicated solutions such as HashiCorp Vault or equivalent tools.
- Deploy and maintain security monitoring tools, including SIEM, alerting, and monitoring solutions.
- Automate anomaly detection and incident response through SOAR and automated runbooks.
- Actively contribute to the management and resolution of security incidents.
- Provide technical support to the team managing the workplace environment, including Microsoft 365, Exchange Online, and SharePoint, on security and monitoring topics.
- Contribute to integrating collaborative tools into global security policies, including authentication, conditional access, DLP, and SIEM alerts.
- Help automate recurring administration tasks and implement alerts for abnormal behaviours.
- Maintain active monitoring of DevSecOps trends, new threats, and emerging practices.
- Evaluate and integrate relevant technologies for Wakam’s environment.
- Share best practices and lessons learned internally and within the DevSecOps community.
- 7+ years of experience in software engineering and/or operations.
- A solid development background, either as a Developer or DevOps profile.
- Strong hands-on experience in application security and infrastructure security.
- A good understanding of cloud-based production environments.
- Experience with Security Operations / SOC is a plus.
- DevOps & Automation: CI/CD, Azure DevOps, GitHub Actions
- Containers: Docker, Kubernetes
- Infrastructure as Code: Terraform, Ansible
- Cloud Platforms: Azure, AWS
- Scripting: Python, Bash, PowerShell
- Application Security: OWASP, secure coding practices
- Security Tools: SAST, DAST, SCA, vulnerability scanning
- Knowledge of security protocols and cryptography.
- Familiarity with compliance frameworks and standards.
- Experience using vulnerability scanning and mitigation tools.
- Strong infrastructure security practices.
- Strong mentoring, influence, and support skills.
- Excellent communication skills, with the ability to explain technical risks and concepts clearly.
- Proven technical leadership and change management capabilities.
- High autonomy and a proactive, solution-focused mindset.
- A 360° vision, with the ability to balance security, business, and technology needs.
- Adaptability and comfort working in a transforming environment.
- Being at the heart of tech-led transformation.
- Collaborating with passionate experts across disciplines.
- Joining a culture that promotes ownership, agility, and innovation.
- Benefiting from flexible working arrangements — hybrid or fully remote within the UK.
- Interview with our Talent Acquisition Partner
- Manager interview with our Head of Information Security
- Case study with the Digital Team
- HRBP interview
AI-Assisted Interview Process Policy | Notion
Skills Required
- 7+ years in software engineering and/or operations
- Solid development background (Dev or DevOps profile)
- Strong hands-on experience in application and infrastructure security
- Understanding of Cloud-based production environments
- Experience with Security Operations (SOC) is a plus
What We Do
Wakam is a B2B2C insurance company that creates white-label insurance solutions via its Play&Plug® technology platform for more than 150 distribution partners and over 8 million policyholders. With a foothold in 32 countries and a 2021 turnover of €455 million, the majority of which was generated outside France, Wakam is the European leader in digital and embedded insurance. The company has been growing rapidly for more than seven years. Led by Olivier Jaillon, Wakam is a Mission-driven company since 2021, its corporate purpose is "enabling transparent and impactful insurance". We have a strong corporate culture built around 11 cultural markers that promote collaboration, curiosity, learning, open-mindedness and innovation

.jpg)

.png)





.png)