About this role
<h4>About Qevlar AI</h4><p>Qevlar is a B2B SaaS startup that strives to massively increase the productivity of cybersecurity teams. We develop AI Cybersecurity Analysts that augment Security Operations Centers (SOCs). Since our creation 2 years ago, we have:</p><ul><li><p>Raised €14 million in seed funding led by EQT Ventures and Forgepoint Capital</p></li><li><p>Been incubated both by Microsoft (genAI studio) and Meta (AI program)</p></li><li><p>Deployed our solution to Global 500 companies and leading MSSPs in EMEA and NA (Equans, Nomios, Globalconnect, Almond)</p></li></ul><p><span><strong>We're looking for our first Director of IT & Information Security to build and own our entire internal security and IT function from scratch.</strong></span></p><h4>What will you do</h4><ul><li><p><strong>Own our security posture end-to-end:</strong> maintain SOC 2 Type II compliance, manage audits, run pentests, and define our security policies and incident response processes</p></li><li><p><strong>Be the face of security with our clients:</strong> answer security questionnaires, join customer calls, and build the trust that closes enterprise deals</p></li><li><p><strong>Build our IT foundation:</strong> manage devices and MDM, streamline onboarding/offboarding, administer our SaaS stack (Google Workspace, Slack, etc.), and own IAM/SSO/MFA</p></li><li><p><strong>Structure the chaos:</strong> we're scaling fast and everything needs to be formalised, you'll create the processes, documentation, and governance we need</p></li><li><p><strong>Grow with us:</strong> start as an individual contributor, then build your team as we scale</p></li></ul><h3>Who you are </h3><p><strong>You have:</strong></p><ul><li><p>7-10 years of experience in information security and/or IT, with at least one role in a B2B SaaS startup or scale-up</p></li><li><p>Hands-on experience with SOC 2 or ISO 27001 (you've been through audits, not just read about them)</p></li><li><p>Strong knowledge of IAM, SSO, and endpoint management (Okta, Google Workspace, Jamf, or similar)</p></li><li><p>Familiarity with cloud environments (AWS, GCP, or Azure)</p></li><li><p>The ability to talk security with enterprise clients and build credibility</p></li><li><p>Full autonomy, you don't need hand-holding to figure out what needs to be done</p></li></ul><p><strong>Bonus points for:</strong></p><ul><li><p>Experience with product security or secure SDLC</p></li><li><p>A DevOps or infrastructure background</p></li><li><p>Certifications like CISSP, CISM, or CISA</p></li><li><p>Familiarity with LLM-based systems and their security implications</p></li></ul><h4>Why join us</h4><ul><li><p><strong>Build from scratch:</strong> you're not inheriting a mess — you're creating the function, the processes, and eventually the team</p></li><li><p><strong>Security for security people:</strong> we build AI that helps SOC analysts. If you care about cybersecurity, our mission will resonate</p></li><li><p><strong>Ownership:</strong> BSPCE package included</p></li><li><p><strong>Flexibility:</strong> Paris-based, remote-friendly</p></li></ul><h4>Hiring process</h4><ol><li><p><strong>Intro Call</strong></p></li><li><p><strong>Case Study</strong></p></li><li><p><strong>Meet the Team </strong></p></li></ol>