Cybersecurity Engineer, Devsecops

Mistral AI Mistral AI · AI Frontier · Paris, France · Engineering & Infra

Mistral AI is seeking a DevSecOps Engineer to secure its AI infrastructure and application lifecycle. The role involves driving threat modeling, vulnerability management, securing Kubernetes and IaC, defining security tooling strategy, and building foundational security automation. The ideal candidate has 5+ years of experience in DevSecOps or Cloud Security, with strong skills in Kubernetes, Terraform, and scripting languages like Python or Go.

What you'd actually do

  1. Drive threat modeling and risk prioritization exercises, serving as the security counterpart to system-design reviews for our core infrastructure and new products.
  2. Own end-to-end vulnerability management across CI/CD pipelines and runtime environments, covering both underlying infrastructure and applications.
  3. Secure our Kubernetes deployments and containerized workloads, implementing advanced pod and node hardening to prevent lateral movement across distributed systems.
  4. Define and enforce Infrastructure-as-Code security by building robust Terraform guardrails and integrating policy-as-code directly into deployment pipelines.
  5. Design and execute a comprehensive security tooling strategy, managing solutions for CNAPP, CSPM, SAST, SCA, secrets management, and SBOM-CVE tracking.

Skills

Required

  • DevSecOps
  • Security Engineering
  • Cloud Security
  • Kubernetes security
  • Container security
  • Infrastructure-as-Code (Terraform)
  • Python
  • Go
  • Threat modeling
  • Vulnerability management
  • CNAPP
  • CSPM
  • SAST
  • SCA
  • Secrets management
  • SBOM-CVE tracking

Nice to have

  • early security hire experience
  • partnering with developers and researchers

What the JD emphasized

  • 5+ years of experience in DevSecOps, Security Engineering, or Cloud Security
  • early security hire in a fast-paced or hyper-scale environment
  • Deep understanding of Kubernetes and container security
  • strong experience securing Infrastructure-as-Code (Terraform)
  • Strong programming and scripting skills (Python, Go, or similar)
  • Extensive experience deploying and tuning modern security tooling
  • proven track record of partnering with developers and researchers