- Contract
- Permanent
- Location
- Paris
- Remote
- Hybrid remote
- Salary
- €90,000 – €120,000 per year
Translated from the French original, which prevails.
The role
Cyber-GRC, for Governance, Risk and Compliance, is how a large company steers its cybersecurity: which risks it carries, which controls it has put in place and whether they work, what its regulators and customers require, what its suppliers do with its data. Today that work happens in spreadsheets, questionnaires sent by email and screenshots standing in for evidence, reviewed once a year, while systems change every day and NIS2, DORA, the AI Act and the CRA keep stacking requirements nobody can meet by hand.
Mindlapse is the platform that overturns that paradigm: a single space where the CISO, compliance, business teams, subsidiaries and suppliers work on the same objects (controls, risks, policies, third parties, security by design), with AI as a design primitive, not an option. What we sell a CISO is the move from declarative, periodic compliance to continuous assurance measured on their real systems: GRC Engineering. Our first CAC 40 and SBF 120 groups are deployed.
We apply the same conviction to the way we build. Software development is changing in nature: code is no longer what a developer writes line by line, it is what agents produce from a specification, a context and rules, under the control of engineers who frame, supervise and arbitrate. Here, an ADE (Agentic Development Environment) has already replaced the IDE as the standard working environment, with autonomous development agents, automated quality and security checks, a continuous deployment chain and full observability. What is missing is the operating model that turns it into a system, and the person who runs it every day. And that shift is not decreed: it is steered, with people, a framework, a cadence and high standards. That is why this is first and foremost a management role.
Until now, this role has been held by Christophe, CPTO and co-founder. We are looking for his right hand: the person to entrust engineering and the team to (a dozen people, three squads), with real autonomy, so that he can focus on product and vision, and to pair with him on everything that connects the two: the roadmap, effort estimates, execution difficulties, process improvement.
We are not looking for an engineering manager who just keeps sprints running, nor an architect who draws diagrams and no longer ships, nor an AI evangelist who gives demos. We are looking for all three at once, in one head, and hands-on: someone with a view of what the developer's craft is becoming, who works in the ADE every day themselves, who makes the agentic SDLC work day to day, who answers for what goes to production, and who grows the team until that way of working is its norm. Three years in, you will have made Mindlapse an engineering team cited as an example for the way it builds with agents, and laid the engineering foundations of a software company that intends to redefine tomorrow's cybersecurity.
Your scope: three squads, each with a lead you manage directly.
Full Stack: the platform customers use every day, UI/UX design, the application modules.
AI: the product's AI capabilities (assistant, analyses, recommendations, agents), model access, RAG, guardrails, LLM-as-a-judge, cost and latency.
Infra: multi-environment cloud platform, continuous deployment, observability, reliability, security and compliance of production.
On that scope, you decide: organisation, standards, tooling, prioritisation with product, hiring. You answer for results, not means.
What you will do day to day:
Delivery leadership (~30%): design and run the agentic SDLC end to end, from ideation to deployment (what goes through agents, human checks, the definition of « done »); own the ADE, its standards and its evolution; run the rituals (daily standups, sprint planning, sprint reviews, retrospectives, demos) so that they produce decisions; hold the velocity, robustness, quality and responsiveness indicators, and answer for what goes to production (SLOs, incidents, post-mortems); carry engineering's commitments to customers (CISOs, CIOs, audits, due diligence, security questionnaires).
Hands-on delivery (~25%): get your hands in: take real tickets and ship them to production, especially on structuring topics (architecture, tooling, security); support the squads on the CI/CD chain, code review and security review, hard technical points and incidents; support the leads and developers technically through pairing. The standards you set, you apply to yourself first.
Management (~25%): manage the three leads directly and, through them, the whole team (objectives, feedback, reviews, progression); hire the key profiles and handle difficult situations properly; grow a mostly junior team until the leads decide without you; keep a culture where things get said and where kindness is not confused with complacency.
Product support (~20%): pairing with the CPTO, build the roadmap and its trade-offs; estimate effort and difficulty, batch, sequence; measure the landing (gap between estimated and actual, causes, corrections); steer customer feedback and change requests with Customer Success (qualify, prioritise, commit, close the loop); continuously improve the whole process, from functional specification to acceptance.
What we expect from you at 6 months:
The steering indicators are in place and shared with the founders every week: velocity (lead time, delivered throughput), robustness (availability, incidents, recovery time), code quality (coverage, rejection rate at checks, defects in production), support responsiveness (time to acknowledge and resolve customer feedback), cost per change. They make what the team produces objective, instead of the founders' and customers' perception of it.
The agentic SDLC operating model is written and applied, and the ADE is the whole team's working environment.
You have shipped several real changes to production yourself, through the ADE, and you have paired with each lead on their scope.
The process from ideation to deployment is formalised with the CPTO, with estimated effort and systematic technical framing.
The three leads are in place with written objectives and a feedback cadence that holds; Christophe is no longer on the front line, neither for day-to-day management nor for execution trade-offs.
What we expect from you at 12 months:
Operational excellence is demonstrated by the indicators, not narrated: service commitments met at every customer, incidents down, support responsiveness at the level large accounts expect, and no churn attributable to engineering quality, reliability or responsiveness.
Most product changes go through the agentic pipeline; throughput, quality and cost per change are clearly better than in the first six months.
The team has grown under your responsibility: successful hires, juniors levelled up, autonomous leads, turnover under control.
The roadmap holds and is credible, and customer feedback is steered end to end: qualified, prioritised, delivered, shown to the customer.
You represent engineering alone in front of the founders and customers; the CPTO no longer needs to re-read your decisions.
A right-hand role with real autonomy: you decide on your scope, you answer for results, and your scope will grow with the team.
Direct management of the three leads and full responsibility for the technical team, with a co-founder CPTO as your pair and direct access to the two other founders.
A product deployed at our first large-account customers, an infrastructure and a delivery chain already industrialised, agentic tooling taken seriously, the mandate to evolve it, and a role where you keep building yourself.
A supportive team that values autonomy, initiative and a diversity of backgrounds.
Who we are looking for
You have 8 or more years of experience in software engineering, several of them leading multiple teams or leads at a B2B SaaS vendor, in a start-up or scale-up.
You have already managed a technical team of ten people or more, directly and through leads: hiring, feedback, reviews, progression, difficult situations.
You have already been the right hand of a technical or product executive: you can decide without them, keep them informed without soliciting them, and carry their decisions in front of the team as your own.
You have yourself put agentic development in place at the scale of a team, ideally around an ADE, with autonomous coding agents and automated review. You know where it breaks, and not only in demos.
You still have your hands in the code, with agents: you can take a real ticket, run it through an ADE and ship it to production yourself, and you want to. This role does not suit someone who has let go of the keyboard.
You have real product seniority (roadmap, specification, estimation, acceptance) and a solid culture of delivery and running production.
You have a view of how the developer's craft is evolving, and you can make it concrete for a team.
You have the security and compliance reflex, because our users are CISOs and our customers audit what we deliver. Time spent in cybersecurity or a regulated sector (NIS2, DORA, AI Act) is a plus.
You know how to commit: say yes and keep it, say no with arguments, to a founder as to a customer, and stay human in tense moments.
You speak French and English fluently.
If you are looking for a VP Engineering role that consists of protecting a team from change, keeping sprints running, having every decision validated and no longer touching code, this is not the place. If you want to take charge of engineering at an AI-native software company, with a team to grow, a founder who trusts you and the autonomy that goes with it, we will get along.
Hiring process
Three weeks at most, a single point of contact, feedback within 72 hours after each step, a reasoned answer in every case.
Interview with Christophe (CPTO), 60 min by video: what you have concretely put in place to run an agentic SDLC, how you manage and grow a team, your view of the craft, what you expect from pairing with a founder.
Interviews with Hervé (CEO) and Julien (COO), 2 x 45 min: soft skills, background, motivations and view of the role; delivery, incidents and customer communication, how you see yourself in cybersecurity.
3 hours in Paris, in person: an organisational case, meeting the leads, challenging our operational practices, lunch with the founders.
Systematic reference checks before any offer, with former managers and former direct reports, in parallel with the last step.
What you get
- Work time flexibility
- Flexible working hours
- Remote work policy
- Between 3-4 days at home
- Culture
- Team buildingAfterworks, Team lunches
- Vacation & time off
- Reduction of working time (RTT)
- Financial benefits
- Remote work allowance
- Professional development
- Professional development planPaid industry certificationsFunded educational training
Skills
- Cybersecurity knowledge
- Presentation skills
- Negotiation skills
- Technical specifications
- Cloud infrastructure management
- Team management
The workplace
Other open positions
Customer Success Manager
- Permanent
- Paris
- Hybrid remote
- €50,000 – €75,000 per year
GRC Engineer
- Permanent
- Paris
- Hybrid remote
- €45,000 – €60,000 per year