Director of Cloud Infrastructure & Security

Vestiaire Collective · Paris

  • Senior
  • Contract
  • Posted 2026-08-28
  • Confirmed live on 25 September 2026

Apply at Vestiaire Collective

Job description

Vestiaire Collective is the leading global platform for desirable pre-loved fashion and a pioneer in transforming how people consume fashion.
 
Our mission is simple: make circular fashion the norm, not the exception.
Through technology, expertise, and a highly engaged global community, we enable millions of people to buy and sell fashion in a more sustainable way.
 
Founded in Paris in 2009, Vestiaire Collective is now a globally scaled marketplace with offices in Paris, London, Berlin, New York, Singapore, and Ho Chi Minh City, and logistics hubs across Europe, Asia, and the US.
Today, we are a team of around 600 people from over 50 nationalities, united by a shared ambition: to drive meaningful change in the fashion industry.
 
Our values, Activism, Transparency, Dedication, Greatness, and Collective, shape how we build, collaborate, and grow every day.

About the Role:
Vestiaire Collective runs a global marketplace on AWS and GCP — Kubernetes, Kafka, Terraform, Vault, Cloudflare, Datadog, a large PHP application under active modernisation, a series of microservices in different tech stacks (Goland, PHP, Node) and a fast-growing surface of AI-powered services. 
 
As Director of Cloud Infrastructure and Security, you will lead a small team of six senior individual contributors across Cloud Infrastructure (DevOps/SRE) and Security. This is a hands-on Director role: alongside setting the strategy and roadmap, you will work directly with the team on architecture, technical decisions, incidents and delivery. You will be accountable, alongside Product Development teams, for the reliability, cost-efficiency and security posture of everything we run in production.
What you will do:
Leadership across two teams
Directly lead, develop and retain a small team of six (6) experienced engineers across Cloud Infrastructure and Security. This is a player-coach role without multiple management layers, so you will remain close to the team’s technical work and day-to-day priorities.
Define a joint roadmap for both teams, aligned to business priorities and risk appetite, and make explicit calls on what we will not do.
Establish clear KPIs, SLOs and risk metrics, and report regularly to leadership on reliability, cost and security posture.
Set the operating model: what product teams self-serve behind guardrails versus what your teams own centrally. 
Foster a culture where reliability and security are shared accountabilities, not tickets thrown over a wall, including establishing a Security Champions model across engineering.

Cloud infrastructure, reliability and platform
Own our AWS and GCP footprint end to end: EKS, networking, secrets (Vault), data stores (RDS/Aurora, MSK, ElastiCache, MongoDB Atlas, OpenSearch) and the edge (Cloudflare).
Establish real reliability engineering practice: SLOs and error budgets, capacity planning, and a business continuity plan.
Drive infrastructure-as-code maturity: Automating Terraform change application, advancing our move to GitOps (ArgoCD), and enforcing guardrails at creation time with policy-as-code (Kyverno/OPA) so provisioning is safe, self-serve and reviewable.
Consolidate observability into a single source of truth for metrics, logs and traces.
Improve developer experience and delivery throughput: CI/CD (Jenkins, GitHub Actions), paved roads, test environments on demand, and delivery metrics that hold up.
Own FinOps: infrastructure cost per unit of business value, cost accountability pushed back to each team, and continued run-rate reduction. Cost discipline is a first-class objective.
Support the modernisation of our core platform: Tech migrations, runtime and framework upgrades, and continuous database and Kubernetes upgrades.
Attack toil systematically: automate the recurring requests, and hand safe self-service back to product teams rather than absorbing the work.
Grow the foundations for AI-augmented engineering and operations

Security
Own security strategy and posture across cloud, application, identity, detection and response, building and improving the governance: risk register, published roadmap, remediation SLAs, and a recurring reporting cadence for leadership.
Strengthen cloud security posture management (CNAPP) and secure-by-default configurations across all environments.
Improve Embedding security into the SDLC and CI/CD: establish full static-analysis and dependency-scanning coverage with clear criteria for when critical findings block a release.
Mature vulnerability management, penetration testing and our bug bounty program into one prioritised program with SLAs and aging reports that measurably reduce risk.
Advance identity and access management toward least privilege and zero trust: automated provisioning from groups, and periodic access reviews.
Mature logging, detection and incident response, closing SIEM coverage gaps
Set guardrails for safe AI adoption (shadow AI outside approved paths, data and prompt leakage, prompt injection, model abuse) and defend agai

Prepare for the interview

Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.

More at Vestiaire Collective

All open software jobs