Director of Cloud Infrastructure & Security
Quick Summary
Leadership across two teams Lead, grow and retain two teams — Cloud Infrastructure and Security — each small, senior and high-leverage. Hire well; we cannot afford mediocre hires at this size.
able to make a technical trade-off legible to a CFO and a risk decision legible to an engineer. Comfortable operating with a lean team — ruthless prioritisation, automation over headcount,
Through technology, expertise, and a highly engaged global community, we enable millions of people to buy and sell fashion in a more sustainable way.
About the Role
~1 min readVestiaire Collective runs a global marketplace on AWS and GCP — Kubernetes, Kafka, Terraform, Vault, Cloudflare, Datadog, a large PHP application under active modernisation, a series of microservices in different tech stacks (Goland, PHP, Node) and a fast-growing surface of AI-powered services.
As Director of Cloud Infrastructure and Security, you will own that entire foundation. You will lead two distinct teams — Cloud Infrastructure (DevOps/SRE) and Security — and be accountable, alongside product development teams for the reliability, cost-efficiency and security posture of everything we run in production.
Responsibilities
~1 min read-
Lead, grow and retain two teams — Cloud Infrastructure and Security — each small, senior and high-leverage. Hire well; we cannot afford mediocre hires at this size.
-
Define a joint roadmap for both teams, aligned to business priorities and risk appetite, and make explicit calls on what we will not do.
-
Establish clear KPIs, SLOs and risk metrics, and report regularly to leadership on reliability, cost and security posture.
-
Set the operating model: what product teams self-serve behind guardrails versus what your teams own centrally.
-
Foster a culture where reliability and security are shared accountabilities, not tickets thrown over a wall, including establishing a Security Champions model across engineering.
-
Own our AWS and GCP footprint end to end: EKS, networking, secrets (Vault), data stores (RDS/Aurora, MSK, ElastiCache, MongoDB Atlas, OpenSearch) and the edge (Cloudflare).
-
Establish real reliability engineering practice: SLOs and error budgets, capacity planning, and a business continuity plan.
-
Drive infrastructure-as-code maturity: Automating Terraform change application, advancing our move to GitOps (ArgoCD), and enforcing guardrails at creation time with policy-as-code (Kyverno/OPA) so provisioning is safe, self-serve and reviewable.
-
Consolidate observability into a single source of truth for metrics, logs and traces.
-
Improve developer experience and delivery throughput: CI/CD (Jenkins, GitHub Actions), paved roads, test environments on demand, and delivery metrics that hold up.
-
Own FinOps: infrastructure cost per unit of business value, cost accountability pushed back to each team, and continued run-rate reduction. Cost discipline is a first-class objective.
-
Support the modernisation of our core platform: Tech migrations, runtime and framework upgrades, and continuous database and Kubernetes upgrades.
-
Attack toil systematically: automate the recurring requests, and hand safe self-service back to product teams rather than absorbing the work.
-
Grow the foundations for AI-augmented engineering and operations
-
Own security strategy and posture across cloud, application, identity, detection and response, building and improving the governance: risk register, published roadmap, remediation SLAs, and a recurring reporting cadence for leadership.
-
Strengthen cloud security posture management (CNAPP) and secure-by-default configurations across all environments.
-
Improve Embedding security into the SDLC and CI/CD: establish full static-analysis and dependency-scanning coverage with clear criteria for when critical findings block a release.
-
Mature vulnerability management, penetration testing and our bug bounty program into one prioritised program with SLAs and aging reports that measurably reduce risk.
-
Advance identity and access management toward least privilege and zero trust: automated provisioning from groups, and periodic access reviews.
-
Mature logging, detection and incident response, closing SIEM coverage gaps
-
Set guardrails for safe AI adoption (shadow AI outside approved paths, data and prompt leakage, prompt injection, model abuse) and defend against AI-enabled fraud and phishing.
-
Ensure compliance with GDPR, PCI DSS v4, NIS2, and CIS v8, including a maintained, reusable evidence library rather than evidence gathered on request.
-
Collaboration with legal and finance teams on compliance and forensic investigation topics
-
Manage third-party and supply-chain risk with vendor tiering and a recurring review cadence.
-
Own the security-built services your team already runs (back-office authentication and ACL, banning/fraud tooling, phone verification) and decide what to keep, hand over or retire.
-
Own endpoint security and partner closely with Corporate IT on device and identity coverage.
-
Keep security awareness and training relevant to a threat landscape that now includes AI-enabled social engineering.
Requirements
~1 min readLocation & Eligibility
Listing Details
- Posted
- August 28, 2026
- First seen
- August 28, 2026
- Last seen
- August 30, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 62%
- Scored at
- August 28, 2026
Signal breakdown
Please let Vestiairecollective know you found this job on Jobera.
3 other jobs at Vestiairecollective
View all →Explore open roles at Vestiairecollective.
Similar Infrastructure jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.