Director of Cloud Infrastructure & Security
vestiairecollective
Paris
Posted Aug 28, 2026
- Contract
- Tech
Job description
Vestiaire Collective is the leading global platform for desirable pre-loved fashion and a pioneer in transforming how people consume fashion. Our mission is simple: make circular fashion the norm, not the exception. Through technology, expertise, and a highly engaged global community, we enable millions of people to buy and sell fashion in a more sustainable way. Founded in Paris in 2009, Vestiaire Collective is now a globally scaled marketplace with offices in Paris, London, Berlin, New York, Singapore, and Ho Chi Minh City, and logistics hubs across Europe, Asia, and the US. Today, we are a team of around 600 people from over 50 nationalities, united by a shared ambition: to drive meaningful change in the fashion industry. Our values, Activism, Transparency, Dedication, Greatness, and Collective, shape how we build, collaborate, and grow every day. ## About the Role: Vestiaire Collective runs a global marketplace on AWS and GCP — Kubernetes, Kafka, Terraform, Vault, Cloudflare, Datadog, a large PHP application under active modernisation, a series of microservices in different tech stacks (Goland, PHP, Node) and a fast-growing surface of AI-powered services. As **Director of Cloud Infrastructure and Security**, you will own that entire foundation. You will lead **two distinct teams** — **Cloud Infrastructure (DevOps/SRE)** and **Security** — and be accountable, alongside product development teams for the reliability, cost-efficiency and security posture of everything we run in production. ## What you will do: ### Leadership across two teams - Lead, grow and retain two teams — Cloud Infrastructure and Security — each small, senior and high-leverage. Hire well; we cannot afford mediocre hires at this size. - Define a joint roadmap for both teams, aligned to business priorities and risk appetite, and make explicit calls on what we will *not* do. - Establish clear KPIs, SLOs and risk metrics, and report regularly to leadership on reliability, cost and security posture. - Set the operating model: what product teams self-serve behind guardrails versus what your teams own centrally. - Foster a culture where reliability and security are shared accountabilities, not tickets thrown over a wall, including establishing a Security Champions model across engineering. ### Cloud infrastructure, reliability and platform - Own our AWS and GCP footprint end to end: EKS, networking, secrets (Vault), data stores (RDS/Aurora, MSK, ElastiCache, MongoDB Atlas, OpenSearch) and the edge (Cloudflare). - Establish real reliability engineering practice: SLOs and error budgets, capacity planning, and a business continuity plan. - Drive infrastructure-as-code maturity: Automating Terraform change application, advancing our move to GitOps (ArgoCD), and enforcing guardrails at creation time with policy-as-code (Kyverno/OPA) so provisioning is safe, self-serve and reviewable. - Consolidate observability into a single source of truth for metrics, logs and traces. - Improve developer experience and delivery throughput: CI/CD (Jenkins, GitHub Actions), paved roads, test environments on demand, and delivery metrics that hold up. - Own **FinOps**: infrastructure cost per unit of business value, cost accountability pushed back to each team, and continued run-rate reduction. Cost discipline is a first-class objective. - Support the modernisation of our core platform: Tech migrations, runtime and framework upgrades, and continuous database and Kubernetes upgrades. - Attack toil systematically: automate the recurring requests, and hand safe self-service back to product teams rather than absorbing the work. - Grow the foundations for AI-augmented engineering and operations ### Security - Own security strategy and posture across cloud, application, identity, detection and response, building and improving the governance: risk register, published roadmap, remediation SLAs, and a recurring reporting cadence for leadership. - Strengthen cloud security posture management (CNAPP) and secure-by-default configurations across all environments. - Improve Embedding security into the SDLC and CI/CD: establish full static-analysis and dependency-scanning coverage with clear criteria for when critical findings block a release. - Mature vulnerability management, penetration testing and our bug bounty program into one prioritised program with SLAs and aging reports that measurably reduce risk. - Advance identity and access management toward least privilege and zero trust: automated provisioning from groups, and periodic access reviews. - Mature logging, detection and incident response, closing SIEM coverage gaps - Set guardrails for safe AI adoption (shadow AI outside approved paths, data and prompt leakage, prompt injection, model abuse) and defend against AI-enabled fraud and phishing. - Ensure compliance with GDPR, PCI DSS v4, NIS2, and CIS v8, including a maintained, reusable evidence library rather than evidence gathered on request. - Collaboration with legal and finance teams on compliance and forensic investigation topics - Manage third-party and supply-chain risk with vendor tiering and a recurring review cadence. - Own the security-built services your team already runs (back-office authentication and ACL, banning/fraud tooling, phone verification) and decide what to keep, hand over or retire. - Own endpoint security and partner closely with Corporate IT on device and identity coverage. - Keep security awareness and training relevant to a threat landscape that now includes AI-enabled social engineering. ## Who you are: - **8+ years** in engineering, with **5+ years leading infrastructure, platform, or security teams** : ideally in a fast-paced scaleup or marketplace environment. - Proven experience managing **multiple teams or functions**, including hiring and developing senior engineers. - Deep, hands-on-credible expertise in **public cloud (AWS strongly preferred)**, **Kubernetes**, and **infrastructure-as-code (Terraform)**. - Track record establishing **reliability practice at scale** — SLOs, incident management, on-call, capacity planning, disaster recovery. - Demonstrable **cloud cost optimisation / FinOps** results at meaningful scale. - Strong grounding in **cloud and application security fundamentals** — IAM, network security, secrets management, CSPM, OWASP Top 10 — and the judgement to know when to hire the depth you don't have. - Working knowledge of **compliance frameworks** (GDPR, DORA, PCI DSS, NIS2) and how to turn requirements into practical controls. - Experience leading through **incidents and security events** under pressure. - Excellent communication skills: able to make a technical trade-off legible to a CFO and a risk decision legible to an engineer. - Comfortable operating with a **lean team** — ruthless prioritisation, automation over headcount, pragmatism over perfection. ## Our Tech Stack includes: - AWS cloud (primary), GCP, Kubernetes, Vault, Cloudflare, Datadog, ArgoCD, Okta. Applications are built on top of PHP 8, Golang and [Node.js](http://node.js), using MariaDB, MongoDB and Kafka.