SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Mistral is a full-stack AI company providing frontier models, developer tools, applications, and compute infrastructure. They partner with enterprises across finance, manufacturing, defense, healthcare, and the public sector to build customized AI systems.
As a Platform Security Engineer on the Security team, you will architect and maintain the security posture of Mistral's rapidly scaling AI infrastructure and application lifecycle. Your mission is to embed robust security controls into CI/CD pipelines, infrastructure environments, and developer workflows while enabling teams to move fast without sacrificing security.
Key responsibilities include:
- Drive threat modeling and risk prioritization in system-design reviews for core infrastructure and new products
- Own end-to-end vulnerability management across CI/CD pipelines and runtime environments
- Secure container orchestration deployments and containerized workloads with advanced hardening
- Define and enforce Infrastructure-as-Code security through policy-as-code integration
- Design and execute a comprehensive security tooling strategy covering cloud-native protection, CSPM, SAST, dependency scanning, secrets management, and vulnerability tracking
- Champion developer enablement by building secure defaults and streamlining remediation workflows
- Build security automation to scale with hyper-growth while establishing pragmatic security culture
You bring 5+ years of Platform Security, Security Engineering, or Cloud Security experience, ideally as an early security hire in a fast-scaling environment. You have deep expertise in container orchestration, container security, and securing Infrastructure-as-Code across major cloud providers. Strong programming skills in Python or Go are essential for building security automation. You're experienced deploying modern security tooling with pragmatic vulnerability management and threat modeling approaches. Most importantly, you excel at partnering with developers and researchers to embed secure defaults without creating friction.