Our Security and IT team keeps the 360Learning platform secure, compliant and auditable for the 1,500 organisations that learn on it every day. As a Senior DevSecOps Engineer, your mission is to make our infrastructure secure by design, detectable by default, and provable at audit time.
360Learning runs its learning platform on Azure and Kubernetes, certified ISO 27001:2022 and SOC 2 Type II. Over the past two years the technical security workload has grown on every front: a larger and more regulated customer base sending their own scans and security assessments, a wider detection and response scope, more infrastructure to keep hardened and auditable, and a growing backlog of security engineering projects that never reach the top of the queue.
We are creating this position to add real technical capacity on the infrastructure side of security, and to move part of our security posture from manual effort to automated guardrails. You will be the bridge between security and platform engineering: deep enough in infrastructure to fix things yourself, and close enough to security operations to know what to look for.
“Ours is a small, senior team with a broad scope: information security, compliance, infrastructure governance and internal tooling, with dual audit accountability on ISO 27001:2022 and SOC 2 Type II. That means direct impact and no layers between you and the decision. Roughly half of this role is greenfield build work you will own end to end.” Guillaume Seigneuret, CISO and Hiring Coach.
Within 1 month, you will:
Complete our onboarding and learn how we work through our own platform and our Convexity culture
Map our Azure and AKS environment, our detection and logging coverage, and our ISO 27001 and SOC 2 control scope with the CISO and the Security Engineer
Meet the DevOps, platform engineering and IT teams you will work with daily
Shadow alert triage and one customer security assessment end to end
Within 3 months, you will:
Be autonomous on our AKS and Azure environment and handle infrastructure related alerts end to end
Have shipped at least one concrete hardening or automation improvement in production
Own the infrastructure scope of vulnerability management, from triage to remediation follow up
Within 6 months, you will:
Have the honeypot live and producing high fidelity alerts
Have measurably widened SIEM connector coverage, with documented log sources and retention
Run infrastructure vulnerability remediation on a predictable cycle with SLA reporting
Within 12 months, you will:
Manage detection content as code, with reviewed and tested rules and documented runbooks
Have largely automated audit evidence on the infrastructure scope
Have eliminated long lived credentials on the critical paths, so engineering teams ship on secure defaults they did not have to think about
The Skill Set:
5+ years in infrastructure, cloud or platform engineering with a strong security focus, or in security engineering with hands on infrastructure practice
Production experience with Kubernetes: RBAC, network policies, admission controllers, secrets handling, workload identity, runtime security
Solid cloud experience, ideally Azure. Strong AWS or Google Cloud experience with a genuine interest in converting works too
Infrastructure as code: Terraform, GitOps workflows, CI/CD pipelines
Scripting and automation: Python or Go, plus shell. Comfortable reading and writing code, and opening pull requests on repositories owned by other teams
Log analysis and investigation: cloud audit logs, query languages, correlation across identity, network and application sources
Fluent English (US/UK) / B2 level or equivalent (FR).
Enthusiasm for our working environment explained here: https://bit.ly/Convexity360L
What we offer:
Compensation: Package includes base salary, a variable component and equity 📈
Benefits/Perks: Work From Home stipend, RTT, lunch vouchers, medical insurance, gym subscription, 1 month parental leave for the second parent.
Balance: Flexible hours, full remote work possible anywhere in France 🏠
Diversity, Equity, and Inclusion: We have 6 active ERGs including Mental Health, Environmental/Sustainability, Women, Parents, LGBTQIA2S+, and Ethnic Diversity. Each group has at least one executive team member serving as a member of the group, bringing greater awareness to each group’s activities and providing a quick path to impact 🤝
Corporate Social Responsibility: Review our CSR Charter: 360learning.com/blog/corporate-social-responsibility-charter 🌎🌏🌍
Culture: A framework that will help you make an impact - envision our way of working and our Convexity Culture: https://bit.ly/Convexity360L & find out more about the teams, product and processes https://bit.ly/42H1ggC 🚀👩🏻💻🏆
Interview Process:
- Phone Screen with our Talent Acquisition Manager
- Discovery Meeting with our Head of Security
- Live exercise with our Head of Security and our Head of Devops: investigation of an incident scenario, or review of an insecure infrastructure configuration
- Clarification Meeting with the Security Engineer and a DevOps engineer
- Culture Fit Meeting with our VP of Engineering
- Offer!
Skills Required
- 5+ years of experience in infrastructure, cloud, or platform engineering with a strong security focus, or security engineering with hands-on infrastructure experience
- Production Kubernetes experience, including RBAC, network policies, admission controllers, secrets handling, workload identity, and runtime security
- Solid cloud experience; Azure is preferred, with strong AWS or Google Cloud experience also considered
- Experience with infrastructure as code, Terraform, GitOps workflows, and CI/CD pipelines
- Scripting and automation experience with Python or Go and shell; ability to read and write code and contribute pull requests
- Experience with log analysis and investigation using cloud audit logs, query languages, and correlation across identity, network, and application sources
- Fluent English at US/UK level, or B2-level French or equivalent
- Enthusiasm for the company's working environment and Convexity culture
360Learning Compensation & Benefits Highlights
-
Fair & Transparent Compensation — Compensation is structured with transparent, market-benchmarked salary bands and a “compute, not negotiate” model, with predictable, formula-based annual reviews. Feedback suggests packages commonly combine base pay with performance incentives and equity for a competitive total-rewards mix.
-
Healthcare Strength — U.S. materials cite medical, dental, and vision coverage with about 84.7% paid for employees and dependents, plus mental-health support through platforms such as Teale. Coverage is described as comprehensive and includes core protections like life and disability insurance.
-
Parental & Family Support — Primary caregivers receive 12 weeks fully paid leave and secondary caregivers 4 weeks, with indications of structured return-to-work support. These policies sit alongside remote-friendly practices that help make family time more workable.
360Learning Insights
What We Do
Performance-driven learning & development teams achieve business impact with 360Learning. L&D teams leverage AI and collaborative learning to pinpoint skills gaps, capture knowledge from experts, and deliver it to learners when needed most. 360Learning’s learning platform is equipped with powerful LMS automation, collaborative learning Academies, tools to create a top-notch learner experience, and an AI-powered Skills ontology to activate skills-based learning. Employees upskill, customers learn, and partners are trained—all from one place. 360Learning partners with 2,500+ companies to deliver impactful learning. Founded in 2013, the company has raised $240 million and built a team of 400+ across New York, Paris, London, and Germany. 360Learning pioneered collaborative learning, launched the first AI certification for L&D, and founded the L&D Collective community to foster knowledge sharing and relationship building.
Why Work With Us
We are powered through our culture called Convexity (more info here: http://bit.ly/Convexity_360L). We focus a lot on making an impact, but also maintaining "Your Life, Your Way", where we believe you can be successful anywhere. We are strong-believers in documenting our process, sharing continuous feedback and having low authority.
Gallery
360Learning Teams
360Learning Offices
Remote Workspace
Employees work remotely.
360Learning is a remote-first employer. We have entities in France, the UK, Germany, Spain, the US, and Canada. We also offer a monthly allowance for our remote employees to create a productive workspace at home, or to rent a co-working space.


