Full-Time

DevOps Engineer

CortAIx Factory

Updated on 8/26/2026

Thales

Thales

10,001+ employees

Global defense and aerospace electronics

No salary listed

Issy-les-Moulineaux, France

Hybrid

Master's

Category
DevOps & Infrastructure (1)
Required Skills
Bash
Kubernetes
MLOps
Microsoft Azure
Python
Grafana
Puppet
OpenShift
Git
Threat modeling
Computer Networking
MLflow
Infrastructure as Code (IaC)
Docker
Role-based Access Control
Go
Cryptography
Prometheus
Jenkins
Terraform
Ansible
DevOps
Linux/Unix
Helm
Google Cloud Platform

Get referred to Thales

See people who can refer or advise you

Requirements
  • A Master 2 (Bac+5) degree from an engineering school or university is required.
  • At least five years of experience in DevOps, platform engineering, or site reliability engineering, including deployments in highly secured on-premises environments, is required.
  • Strong knowledge of Linux systems, networking, security, containers, and orchestration with Kubernetes or OpenShift is required.
  • Confirmed experience with continuous integration and continuous delivery, GitOps, and DevSecOps using a security-by-design approach is required, including cloud build chains and on-premises deployments in constrained or air-gapped contexts.
  • Experience with Infrastructure as Code and configuration automation using Terraform, Ansible, and Puppet is required.
  • Scripting experience with Bash and Python is required; Go is desirable.
  • Knowledge of public cloud environments, preferably Azure and Google Cloud Platform, and/or private cloud is required.
  • Knowledge of data sovereignty and classification constraints, network segmentation, proxies or demilitarized zones, and bastion hosts is required.
  • Experience with Docker, Kubernetes, Helm, Kustomize, and NVIDIA device plugin-based GPU management is required.
  • Experience with GitLab CI or Jenkins, ephemeral cloud runners, multistage pipelines, artifact promotion, and registries such as Harbor, Artifactory, or Nexus is required.
  • Knowledge of DevSecOps and software supply-chain practices, including static application security testing, dynamic application security testing, software composition analysis, container and Infrastructure as Code scanning, software bills of materials, image signing, provenance, compliance policies, CIS hardening, vulnerability management, and threat modeling is required.
  • Knowledge of PKI, mutual TLS, secrets management, rotation and segmentation, role-based access control, network policies, Zero Trust, security monitoring, hardware security modules, and encryption in transit and at rest is required.
  • Knowledge of observability and reliability practices using Prometheus, Grafana, EFK or ELK, SLOs, SLIs, runbooks, resilience testing, disaster recovery, and business continuity is required.
  • Knowledge of Git, trunk-based development or GitFlow, code review, dependency management, artifact and license management, and ITIL change management is required.
  • Ability to work collaboratively with data, artificial intelligence, cybersecurity, network, infrastructure, architecture, and client teams is required.
  • The position may require access to information covered by French national defense secrecy and therefore requires completion of the applicable security-clearance procedure.
Responsibilities
  • Contribute to reusable patterns and golden standards for secure landing zones and hybrid continuous integration and continuous delivery pipelines, covering compilation, testing, cloud scanning, signed artifact promotion, on-premises quality-assurance deployments, production release, and end-to-end observability.
  • Support Data and AI teams in implementing reusable patterns for their use cases while maximizing reliability and security.
  • Optimize cloud build performance and costs through ephemeral execution, caching, parallelization, retention policies, and FinOps practices.
  • Deploy, configure, and maintain DevSecOps capabilities, including security-by-design development controls, static application security testing, dynamic application security testing, software composition analysis, software bills of materials, machine-learning bills of materials, image signing, and secrets management.
  • Manage interactions with customer on-premises infrastructure architects and DevOps teams throughout the integration and maintenance of AI solutions.
  • Design secure continuous integration and continuous delivery, data, and AI-stack architectures for deployment in critical environments.
  • Participate in agile team rituals, architecture reviews, and security reviews.
Desired Qualifications
  • Knowledge of Go is desirable.
  • Knowledge of MLOps and integration of AI pipelines with MLflow is appreciated.
  • Experience with sensitive or classified environments, operating-system and container hardening, and regulatory compliance such as ISO 27001, NIS2, or sovereign requirements is an asset.
  • Experience industrializing AI workloads on Kubernetes, including GPU scheduling, drivers, and hardened base images, is an asset.

Thales designs and delivers critical technology for aerospace, defense, and digital security, including electronics, software, and data-security systems used in air travel, credit cards, and modern military platforms. It combines hardware and software to create avionics, radar, cybersecurity, and secure communications systems that collect sensor data, run specialized software, and protect networks. It distinguishes itself through end-to-end solutions across defense, aerospace, and cybersecurity, ongoing deep-tech research in AI and quantum, and strategic acquisitions such as Gemalto and Imperva, plus its partial state ownership. Its goal is to provide reliable, secure, and connected technologies that support national security, public safety, and everyday life by solving complex security and connectivity challenges.

Company Size

10,001+

Company Stage

IPO

Headquarters

Meudon, France

Founded

1893

Get referred to Thales

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • H1 2026 order intake rose 21% to €12.5 billion, led by defense.
  • Thales signed Exail at €134 a share, targeting underwater warfare and synergies above €90 million.
  • New launches in Luna 8, TopSky-America, and Denmark air defense expand addressable markets.

What critics are saying

  • Exail closing needs antitrust approvals through Q3 2027; integration drags until early 2028.
  • Thales Cybersecurity Products faced 2026 vulnerability reviews and external data-leak allegations, damaging trust.
  • FAA modernization and defense procurement face political reversal; one major program loss hits growth fast.

What makes Thales unique

  • Thales spans defense, aerospace, and cyber security with tightly integrated critical systems.
  • Its installed base in air traffic control and encryption creates sticky, long-duration customer relationships.
  • French state backing and global industrial partnerships strengthen sovereign-market access in Europe and India.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Paid Parental Leave

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

-4%

1 year growth

-4%

2 year growth

3%
WebWire
Aug 24th, 2026
Thales issues $1.1B bond to finance Exail acquisition

Thales has issued a €1 billion bond in two tranches to finance its acquisition of Exail, announced on 6 July 2026. The bond consists of a €500 million tranche with a four-year term at a 3.50% fixed rate, and another €500 million tranche with an eight-year term at a 3.75% fixed rate. The issuance attracted strong investor demand and was oversubscribed by a diversified investor base. The offering reflects market confidence in Thales's credit quality, rated A2 by Moody's and A- by S&P Global Ratings, both with stable outlooks. Crédit Agricole Corporate & Investment Bank served as global coordinator, with BNP Paribas, Deutsche Bank, J.P. Morgan, and others acting as bookrunners.

Wilsons Media
Aug 21st, 2026
Massive supply-chain attack sees terabytes of data belonging to some of the world's biggest and most sensitive organizations leaked online.

Massive supply-chain attack sees terabytes of data belonging to some of the world's biggest and most sensitive organizations leaked online. * More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM * LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of an open-source security scanner * Some of the credentials still work, nearly five months after the original breach, indicating that there is still a persistent security risk until they are changed Security firms CloudSEK and Hudson Rock have claimed more than 2,500 organizations have had credentials harvested in a supply-chain attack on LiteLLM. LiteLLM, an open source gateway which translates API calls for over 100 large language models into a single OpenAI-compatible format, was not directly compromised in the attack, as hackers targeted a known vulnerability in Aqua Security's Trivy. The list included many large and critical service providers, including but not limited to Cisco, Samsung, Salesforce, and Amazon Web Services, as well as Airbus U.S. Space & Defense, Thales Group, Deutsche Bahn, Munich Re, and the London Stock Exchange Group. Latest Videos FromTechRadar An attack that is still a concern nearly five months later. The original attack occurred on March 24 2026 and was spearheaded by a financially motivated hacking group called TeamPCP, which compromised Trivy, an open source security tool that scans for vulnerabilities. The modified package, which was subsequently downloaded and 'invited' in by LiteLLM without checking its ID- an automated process that essentially allowed a poisoned version of the trusted tool in- gained server administrator privileges and then installed a stealer. The stealer compromised credentials and secrets far more valuable than corporate data, including Cloud keys, SSH keys, Kubernetes tokens, environment variables, repository and package-publishing tokens, and AI provider keys. These are arguably worse from a security standpoint than a singular breach because of both the scale of the attack and the fact that hackers now had a 'key' to many security doors rather than having to run exploits to get there. The victim-scale research done by CloudSEK was further corroborated the following day by Hudson Rock, and it painted a grim picture of what was still an outstanding issue nearly 5 months after the original attack. The irony is that some of the credentials still work: Independent researcher Kevin Beaumont said some of the compromised keys were still valid after he tested them, even as the impacted organization insisted it had 'rotated' those keys to new ones. CloudSEK's figures indicate 2,500-plus companies and 434,000 CI/CD pipelines were compromised, while Hudson Rock has released a 153 GB archive of the exfiltrated material after examining a 195 TB file it had obtained. Both firms are running domain-lookup tools so organizations can check their own exposure online. Whether these revelations lead organizations to double-check their use of AI tools in multiple mission-critical instances that could compromise not only customer data but their own trade secrets down the line remains to be seen. Follow TechRadar on Google News and add Wilson’s Media LLC as a preferred source to get its expert news, reviews, and opinion in your feeds. More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of...

The Defense Post
Aug 20th, 2026
Thales, Systematic join Forces to modernize Denmark's air defense.

Thales, Systematic join Forces to modernize Denmark's air defense. Thales and Systematic have formed a strategic partnership to develop integrated air defense capabilities for the Danish Armed Forces. The collaboration combines Systematic's command-and-control software with Thales' air defense technologies, including the SAMP/T NG missile defense system, to support Denmark's modernization of its air and surface-based air missile defense architecture. Rather than developing a new weapon system, the deal focuses on improving how different air defense assets communicate and operate together. The companies said the goal is to deliver interoperable capabilities that can integrate with Denmark's existing defense architecture and NATO operations. The alliance will also support the Danish Acquisition and Logistics Organisation, which oversees defense procurement, while strengthening Denmark's domestic defense industry through local industrial participation and potential export opportunities. "This partnership is an important step to strengthen Denmark's air defense capabilities with trusted European technology, while building on the strong industrial capabilities we have developed here in Denmark," Systematic vice president for business development Klaus Qvist said. Denmark expands defense partnerships. The Thales-Systematic agreement follows a series of partnerships aimed at strengthening Denmark's defense capabilities and industrial base. In May, Australia's DroneShield and Denmark's Terma signed an agreement to develop interoperable counter-drone capabilities, creating a framework for joint testing and future deployment. In March, Spain's Navantia proposed a long-term partnership to support Denmark's next generation of naval programs, offering local industrial participation, training, and lifecycle support with deliveries beginning in 2030. This follows a December 2025 agreement between Heckler & Koch and Rheinmetall Nordic to jointly deliver integrated small arms, fire control, and weapon accessory solutions for European military and law enforcement customers.

Defence Nordic
Aug 19th, 2026
Systematic and French giant join forces on Danish air defence.

Systematic and French giant join forces on Danish air defence. The companies will integrate their technologies to help Denmark counter growing drone and ballistic-missile threats By Rasmus Schaal Linneberg, Kevin Landor Laursen August 19, 2026 2:40 PM Danish software company Systematic and major air defence manufacturer Thales announced a new partnership to deliver air defence solutions aimed at strengthening the Danish Armed Forces. The partnership was announced at the Danish defence expo DALO Industry Days, hosted by the Danish Ministry of Defence Acquisition and Logistics Organisation.

VIPress
Aug 17th, 2026
Thales formalises $150 Exail Technologies acquisition, targeting Q1 2028 completion

Thales has formalised its acquisition of Exail Technologies, signing a binding agreement on 30 July for €134 per share. The deal involves purchasing the Gorgé family's 35.51% stake by Q3 2027, followed by a mandatory public offer for remaining shares expected in early 2028, subject to regulatory approvals. The acquisition will strengthen Thales's portfolio in submarine warfare, naval robotics, and inertial navigation systems, whilst expanding capabilities in photonics, quantum technologies, and aerospace. Exail Technologies, a leading European dual-use technology company, generated €479 million revenue in 2025 and employs over 2,200 people. The company specialises in inertial navigation systems, maritime and submarine drones, autonomous mine-countermeasure systems, and photonic and quantum components. Exail's board unanimously supports the transaction, pending an independent expert's fairness opinion.