SlipstreamJobsFresh Startup & VC-Backed Jobs

Director of Cloud Infrastructure & Security

Vestiaire Collective - Paris, France - Hybrid - posted 2026-08-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Vestiaire Collective is a global marketplace for pre-loved fashion, operating across 70+ countries with offices in Paris, London, Berlin, New York, Singapore, and Ho Chi Minh City. The company runs a sophisticated technology platform on AWS and GCP, featuring Kubernetes, Kafka, Terraform, Vault, Cloudflare, and Datadog, alongside a large PHP application undergoing modernization and a growing suite of AI-powered services. As Director of Cloud Infrastructure & Security, you will own the entire technical foundation and lead two distinct teams: Cloud Infrastructure (DevOps/SRE) and Security. You will be accountable for the reliability, cost-efficiency, and security posture of all production systems. Key responsibilities include: **Leadership & Strategy:** Lead, hire, and retain two small, senior teams. Define a joint roadmap aligned to business priorities and risk appetite. Establish clear KPIs, SLOs, and risk metrics with regular reporting to leadership. Set the operating model for what product teams self-serve versus what your teams own centrally. Foster a culture where reliability and security are shared accountabilities, including establishing a Security Champions model across engineering. **Cloud Infrastructure & Reliability:** Own the AWS and GCP footprint end-to-end (EKS, networking, Vault, RDS/Aurora, MSK, ElastiCache, MongoDB Atlas, OpenSearch, Cloudflare). Establish real reliability engineering practice with SLOs, error budgets, capacity planning, and business continuity planning. Drive infrastructure-as-code maturity through Terraform automation, GitOps adoption (ArgoCD), and policy-as-code enforcement (Kyverno/OPA). Consolidate observability into a single source of truth. Improve developer experience and CI/CD throughput (Jenkins, GitHub Actions). Own FinOps with cost accountability per team and run-rate reduction. Support core platform modernization including tech migrations, runtime upgrades, and database/Kubernetes upgrades. Systematically attack toil through automation and safe self-service handoff. **Security:** Own security strategy and posture across cloud, application, identity, detection, and response. Strengthen cloud security posture management (CNAPP) and secure-by-default configurations. Embed security into the SDLC and CI/CD with static analysis and dependency scanning. Mature vulnerability management, penetration testing, and bug bounty programs. Advance identity and access management toward least privilege and zero trust. Mature logging, detection, and incident response. Set guardrails for safe AI adoption and defend against AI-enabled fraud. Ensure compliance with GDPR, PCI DSS v4, NIS2, and CIS v8 with maintained evidence libraries. Manage third-party and supply-chain risk. Own security-built services (back-office authentication, banning/fraud tooling, phone verification). Manage endpoint security and partner with Corporate IT. Keep security awareness training current. **Requirements:** - 8+ years in engineering, with 5+ years leading infrastructure, platform, or security teams (ideally in a fast-paced scaleup or marketplace environment) - Proven experience managing multiple teams or functions, including hiring and developing senior engineers - Deep, hands-on-credible expertise in public cloud (AWS strongly preferred), Kubernetes, and infrastructure-as-code (Terraform) - Track record establishing reliability practice at scale (SLOs, incident management, on-call, capacity planning, disaster recovery) - Demonstrable cloud cost optimization / FinOps results at meaningful scale - Strong grounding in cloud and application security fundamentals (IAM, network security, secrets management, CSPM, OWASP Top 10) - Working knowledge of compliance frameworks (GDPR, DORA, PCI DSS, NIS2) and ability to translate requirements into practical controls - Experience leading through incidents and security events under pressure - Excellent communication skills: able to make technical trade-offs legible to a CFO and risk decisions legible to engineers - Comfortable operating with a lean team—ruthless prioritization, automation over headcount, pragmatism over perfection The company offers purpose-driven work at scale, high-impact scope with global reach, a truly international environment (50+ nationalities), career acceleration in a fast-moving scaleup, dedicated learning and growth budget, hybrid flexibility (typically 2 days remote per week), 2 paid volunteer days per year, and competitive compensation including bonus, health coverage, lunch vouchers, gym pass, and location-dependent legal perks.

Similar roles