Product Security Engineer

Fortinet

CDI Sophia Antipolis, Alpes-Maritimes, France IT / Digital
Publiée le
17/04/2026
Contrat
CDI
Localisation
Sophia Antipolis, Alpes-Maritimes, France
Taille équipe
Missions clés Gérer les incidents liés à la sécurité des produits Fortinet. · Effectuer des recherches sur les vulnérabilités des produits Fortinet. · Contribuer à l'élaboration et à l'exécution de la stratégie d'automatisation et d'outillage. · Triage des incidents et tests pour les vulnérabilités signalées. · Escalader les incidents aux analystes seniors si nécessaire.
Profil recherché Bac +3 (Licence, Bachelor), Bac +5 (Master 2, Diplôme d'ingénieur) · communication · fiabilité · intégrité éthique · détail orienté
Outils & compétences Fortinet, asymmetric cryptography, C, Dynamic Application Security Testing, Nessus, Retina, Nexpose, Burp, Qualys, CoreImpact, pentesting methodologies, fuzzing tools

Le poste en détail

The Product Security Incident Response Team is looking for a Product Security Engineer, to handle Product Security related incidents, and to perform vulnerability research on Fortinet products.

 

Duties:

  • Find and report unknown vulnerabilities in Fortinet products via black box analysis, fuzzing, and source code auditing, both manual and via appropriate tooling.
  • Contribute to the elaboration and execution of the automation and tooling strategy of Fortinet Product Security and QA, in order to prevent and detect vulnerabilities early in the source code.
  • Triage incidents, answer questions they may raise, test for vulnerabilities they may signal, investigate source code and create (then follow up on) Incidents on the Incident Management System when necessary. Escalate to senior analyst when incident falls out of the field of competence/knowledge.

     

     

Skills:

  • Good understanding of Fortinet products line-up, solid security background, in-depth understanding of asymmetric cryptography, scripting knowledge, high proficiency in C language, must be detail oriented and able to follow processes thoroughly.
  • Good understanding of vulnerabilities at source-code level required. Experience in Dynamic Application Security Testing tools e.g. Nessus, Retina, Nexpose, Burp, Qualys, CoreImpact is a plus, as well as experience in pentesting methodologies and/or fuzzing tools.
  • Clear and respectful communication, strong reliability, and consistent demonstration of ethical integrity across all aspects of the work.

     

Education:

  • BS in Computer Science or equivalent.
  • MS in Computer science preferred