Senior SRE Engineer
Job description
About the role
As a Gorgias Platform Security Engineer focused on the platform security and SRE intersection, you will own the design and execution of security controls that protect our global infrastructure. You will partner closely with SRE and engineering leadership to embed security into the platform rather than treating it as an afterthought. This role owns the implementation of proactive threat detection, resilient architecture, and robust incident response capabilities across our production environments. You will be responsible for ensuring that security and reliability practices are consistent, automated, and scalable across all services. The work you do will directly influence our ability to meet enterprise-grade security requirements and support high-assurance customers. You will translate complex security requirements into operational practices that our engineering teams can adopt without friction. Your contributions will shape how Gorgias hardens its cloud and Kubernetes environments against evolving threats while maintaining velocity.
Key facts
What you'll do
Platform & cloud security
- Own cloud and Kubernetes security across identity, access, network controls, and workload protection for more than ten global clusters.
- Design secure-by-default platform guardrails using policy-as-code tools so that secure configurations become the default and the easy path.
- Harden continuous integration and infrastructure pipelines from source to deployment, including GitHub Actions, ArgoCD, and Terraform workflows.
- Design and operate a decoupled secrets architecture that prevents credentials from appearing in repositories or deployment artifacts.
- Strengthen network foundations through deliberate VPC design, secure peering strategies, and zero-trust segmentation between services.
Detection & response
- Construct security-focused logging and monitoring pipelines that emphasize actionable signals over raw data volume.
- Implement runtime detection capabilities such as intrusion detection and file integrity monitoring for GKE workloads.
- Develop and maintain incident response playbooks that are practical, tested, and followed during real incidents.
- Operate and refine the SIEM to improve signal-to-noise ratios and enable automated mitigation for high-risk scenarios.
Auth & identity
- Design and enforce strong authentication and authorization standards for internal tools, APIs, and customer surfaces.
- Audit and advance privileged access management to confirm that least privilege is practiced and verifiable.
Compliance & enterprise enablement
- Own the ongoing health of SOC 2 Type II controls so that compliance is maintained continuously, not just around audit cycles.
- Drive readiness for ISO 27001 and data protection obligations related to PII and GDPR as the business expands globally.
- Partner with enterprise customers to understand security requirements and ensure our platform supports their expectations.
- Collaborate with product and security teams to align roadmaps, risk assessments, and remediation plans.
- Mentor engineers on secure coding, deployment hygiene, and incident response practices.
- Contribute to architectural decisions that balance security, scalability, and developer experience.
Requirements
- Bring more than five years of experience in infrastructure security, cloud security, or security engineering within fast-paced, high-growth software organizations.
- Demonstrate deep expertise with GCP and Kubernetes, including GKE, workload identity, network policies, and RBAC implementations.
- Show mastery of networking fundamentals such as VPC design, peering strategies, firewall architectures, and zero-trust networking models.
- Exhibit hands-on experience hardening CI/CD and infrastructure as code pipelines, especially GitHub Actions, ArgoCD, and Terraform.
- Prove competence in authentication and identity protocols, including OAuth 2.0, OIDC, and SAML, along with the ability to design and audit identity flows.
- Have practical experience with policy-as-code frameworks like OPA or Kyverno for defining and enforcing guardrails at the platform level.
- Offer a background in detection, response, SIEM, and runtime security, including writing and maintaining incident response runbooks.
- Hold experience with compliance regimes such as SOC 2 Type II, ISO 27001, and GDPR/PII protection in enterprise contexts.
- Show fluency with scripting and automation using languages such as Python, Go, and Bash to build tooling and respond to incidents.
Nice to have
- Experience contributing to open source projects relevant to cloud infrastructure, security, or observability.
- Familiarity with modern e-commerce platforms and the specific security and reliability challenges they face.
Practical notes
- Location is Paris.
- This is a full-time position.
- Compensation is aligned with level and market, with equity offered at the 90th percentile worldwide.
- Details regarding salary and equity can be verified through our public salary calculator at https://docs.google.com/spreadsheets/d/1GZOLCKCLVTZrLvhKN_QFNE9QpBniFXtxvNITXuL5jz4/edit?gid=4.
- The role reports to the SRE and security leadership team and works across product, security, and infrastructure initiatives.
- We expect this role to engage fully with on-call responsibilities and incident response duties as part of platform ownership.
- The successful candidate will collaborate across time zones and functions in a fast-moving, high-growth environment.