Senior DevSecOps Engineer
360Learning · 🌍 Paris, Remote · Remote
Sponsorship verdict
No sponsorship evidence yet
No government record and no wording either way. Not a refusal — ask the recruiter.
- No government sponsor record hereThis employer posted directly and does not match a government sponsor register.
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- Can’t check pay against the visa rulesWe don’t have visa salary rules for this country yet.
- Confirmed live todayWhen a source last listed this job as open.
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Why not apply?
No register record and no sponsorship wording in the posting. Worth asking the employer before investing significant time.
SponsorApply flags time-wasters so your applications go where they can land. These come from the posting's own wording — read the original listing to confirm. See better-fit alternatives →
Sponsor Radar — 360Learning
This employer posted directly and does not match a government sponsor register.
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for 360Learning →
About the role
Our Security and IT team keeps the 360Learning platform secure, compliant and auditable for the 1,500 organisations that learn on it every day. As a Senior DevSecOps Engineer, your mission is to make our infrastructure secure by design, detectable by default, and provable at audit time. 360Learning runs its learning platform on Azure and Kubernetes, certified ISO 27001:2022 and SOC 2 Type II. Over the past two years the technical security workload has grown on every front: a larger and more regulated customer base sending their own scans and security assessments, a wider detection and response scope, more infrastructure to keep hardened and auditable, and a growing backlog of security engineering projects that never reach the top of the queue. We are creating this position to add real technical capacity on the infrastructure side of security, and to move part of our security posture from manual effort to automated guardrails. You will be the bridge between security and platform engineering: deep enough in infrastructure to fix things yourself, and close enough to security operations to know what to look for. “Ours is a small, senior team with a broad scope: information security, compliance, infrastructure governance and internal tooling, with dual audit accountability on ISO 27001:2022 and SOC 2 Type II. That means direct impact and no layers between you and the decision. Roughly half of this role is greenfield build work you will own end to end.” Guillaume Seigneuret, CISO and Hiring Coach. Within 1 month, you will: • Complete our onboarding and learn how we work through our own platform and our Convexity culture • Map our Azure and AKS environment, our detection and logging coverage, and our ISO 27001 and SOC 2 control scope with the CISO and the Security Engineer • Meet the DevOps, platform engineering and IT teams you will work with daily • Shadow alert triage and one customer security assessment end to end Within 3 months, you will: • Be autonomous on our AKS and Azure environment and handle infrastructure related alerts end to end • Have shipped at least one concrete hardening or automation improvement in production • Own the infrastructure scope of vulnerability management, from triage to remediation follow up Within 6 months, you will: • Have the honeypot live and producing high fidelity alerts • Have measurably widened SIEM connector coverage, with documented log sources and retention • Run infrastructure vulnerability remediation on a predictable cycle with SLA reporting Within 12 months, you will: • Manage detection content as code, with reviewed and tested rules and documented runbooks • Have largely automated audit evidence on the infrastructure scope • Have eliminated long lived credentials on the critical paths, so engineering teams ship on secure defaults they did not have to think about The Skill Set: • 5+ years in infrastructure, cloud or platform engineering with a strong security focus, or in security engineering with hands on infrastructure practice • Production experience with Kubernetes: RBAC, network policies, admission controllers, secrets handling, workload identity, runtime security • Solid cloud experience, ideally Azure. Strong AWS or Google Cloud experience with a genuine interest in converting works too • Infrastructure as code: Terraform, GitOps workflows, CI/CD pipelines • Scripting and automation: Python or Go, plus shell. Comfortable reading and writing code, and opening pull requests on repositories owned by other teams • Log analysis and investigation: cloud audit logs, query languages, correlation across identity, network and application sources • Fluent English (US/UK) / B2 level or equivalent (FR). • Enthusiasm for our working environment explained here: https://