Expert
Devoteam is a technology consulting company specializing in cloud, cyber, AI, and sustainable development. With over 11,000 employees in more than 25 countries, we have been guiding our clients for nearly 30 years in the technological transformation of their activities. In France, we are 4500 Digital Architects spread across more than 50 expertise tribes and coached by more than 400 expert managers. Joining us means: working on innovative and sustainable projects to put Technology at the service of humanity, continuously getting certified on new market technologies, and sharing unique moments with colleagues!
To learn more about Devoteam, click here.
Devoteam Cyber Trust is the team dedicated to Cybersecurity expertise. Composed of over 800 passionate experts worldwide, including 450 in France, we advise our clients on complex topics: cyber, risks, resilience, network security, Cloud security, encryption, audit, and security around our 5 partners AWS, Google, Microsoft, Salesforce, and ServiceNow.
As part of a mission with a client in the energy sector, you will join the AppSec VOC as a Vulnerability Expert, providing RUN support for the management and monitoring of application vulnerabilities.
Main Missions
Qualify reported vulnerabilities (true/false positive) and challenge project Security Champions on their analysis
Provide N3 AppSec expertise to project teams on complex technical analyses and the choice of fixes (OWASP categories: SQL injection, XSS, hardcoded secrets, etc.)
Ensure expertise on the follow-up of the AppSec VOC RUN, covering SAST, IaC, Secrets, and SCA scanners
Contribute to continuous process improvement (feedback from Security Champions, adjustment of scan and exclusion rules)
Coordinate different stakeholders and facilitate meetings between analysts, project managers, and management
Supervise SAST scans (Checkmarx) orchestrated via a vulnerability orchestrator across all GitLab repositories of the application park
Innovation & AI applied to VOC
Design and develop new AI-based solutions to automate and ensure the reliability of vulnerability qualification (automatic true/false positive sorting, intelligent prioritization of fixes)
Explore the use of LLMs to simplify technical analyses for development teams (generation of contextualized remediation recommendations)
Identify use cases for generative AI or automation to accelerate the processing of SAST/SCA/IaC/Secrets scans and reduce the workload of N3 analysts
Prototype and industrialize internal tools (scripts, agents, integrations) aimed at enriching or complementing the SOLANUM system
Actively monitor market AppSec/AI innovations and propose their integration into the VOC system
Drive a continuous improvement approach focused on innovation, in conjunction with technical teams and management
Good project management skills
Solid expertise in technical vulnerability management
Solid overall Cyber culture
Good AppSec culture (OWASP, SAST/SCA)
Understanding of AppSec scanners
Proficiency in Checkmarx or an equivalent tool
Ability to communicate complex technical concepts to development teams
A taste for RUN and continuous service improvement
Appetite for AI applied to cybersecurity and product/process innovation
Why join us?
Career monitoring carried out by a tech manager with regular exchanges;
Technical and soft skills certifications freely accessible with a goal of at least 2 certifications per year, provided vouchers, and expert coaching;
Strategic technology partners: Google, AWS, Microsoft, ServiceNow, Snowflake, MuleSoft, Outsystems, SAP, Databricks, Gitlab, …;
A career path with varied possibilities via geographical, functional, and inter-entity/tribe or squad internal mobility.
Internal roles to build your career within the Group: manager, internal trainer, tech leader, digital champion, squad leader, …
Internal contributions to broaden your skills such as school relations, recruitment, sales, article writing, animating meet-ups or communities, …
A strong community spirit, through internal events and sports and cultural activities thanks to more than 30 Happiness@Devoteam clubs, allowing you to meet your colleagues regularly and share your passions;
A Tech for People vision embodied in our values, our responsible practices, our sustainable development program recognized by the Ecovadis label, and our strong commitments, notably with the Devoteam Foundation.
How does the recruitment process at Devoteam unfold?
It includes 2 to 3 interviews:
Talent Acquisition Interview: the objective is to review your skills, your English level, and validate your motivations
Tech & Business Interview: this interview aims to deepen your technical skills and verify their suitability with our needs during an exchange with a business expert
Leadership Interview: it allows us to evaluate your potential, your ambitions, and to envision your evolution within Devoteam.
We prioritize at least one in-person interview. A reference check is requested and, depending on your profile, tests (technical, English, personality...) may be sent to you. If your application is accepted, we will send you an offer detailing the terms of employment. Upon acceptance, the employment contract is formalized.
If you share our passion for technology and want to build the responsible digital world of tomorrow, then you might be the enthusiast we are looking for at Devoteam.
The Devoteam Group works for equal opportunities, for the promotion of its employees based on merit, and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism, and excellence of our organization. All our positions are open to people with disabilities.
Registriere dich, um dich zu bewerben — und erfahre sofort, ob du passt.
Dein Agent sagt es dir — in wenigen Sekunden.
Registriere dich und ich sage dir sofort, wie gut Devoteam zu dir passt: was du schon mitbringst und was du noch stärken kannst. Danach bleibe ich dran und schreibe dir, sobald ich eine Chance finde, die sich wirklich lohnt.