ログインアプリを入手

求人 › Paris › 求人詳細

Security Engineer - Purple Team specialist H/F

Veepee · Paris

フルタイム出社英語

仕事内容

企業の求人情報より · Veepee · 2026年7月15日掲載

Pioneer of online flash sales since 2001 and key player in European e-commerce, Veepee collaborates with over 7,000 brands to offer highly discounted products available for a limited time. Operating across various sectors, including fashion, home, wine, travel or beauty... Veepee achieved a turnover of 3.3 billion euros incl. VAT in 2024 and employs 5,000 staff members across 10 countries.

Organization and team

The cybersecurity team includes Red/Purple/Blue teamers and risk & compliance oriented profiles, all working together to fix security weaknesses with innovative solutions, adapted to business needs. A Bug Bounty program, an authenticated program on our partner-facing platforms, an annual external Red Team engagement and recurring compliance assessments keep us honest, and our radar sharp. Our threat detection & incident response runs fully in-house, nothing is outsourced: you can touch everything, from detection engineering, case management and response, threat intelligence and the vulnerability lifecycle to the AI agents orchestrated on top of it all. Automation and AI are at the core of everything (who doesn't?): agents triage our alerts 24/7 so humans focus on what matters, an LLM pipeline audits our code, and every confirmed finding feeds a remediation loop with product teams.

Responsibilities: Attack Veepee's perimeter the way a real adversary would: red team, penetration tests (grey/black/white/AI box), Active Directory attack paths, phishing campaigns and the business web based processes themselves (member journeys, seller flows, payment chains), hunting for logic flaws no scanner will ever find. Put our risk register and threat intelligence to the test: take a stated risk or an emerging threat and confirm it, or refute it, with a working attack scenario. Qualify what comes in from the outside: Bug Bounty reports (public and authenticated programs) and alerts escalated by our RAG agents during the cyber-watching rotation. Convert every confirmed attack path into something that runs without you: a detection rule, a hunting query, an automated control. If a bot can do it, we automate it. Build and improve the team's tooling: AI-assisted code audit, password auditing, secret hunting, attack-surface monitoring. Carry your findings through to remediation: explain the impact to product and infra teams, propose the fix, track it through our vulnerability-management lifecycle, and re-attack to prove it's closed. Share your discoveries with technical and business teams and spread security culture in accordance with day-to-day constraints.

Required skills: The most important thing is motivation! Naturally curious profiles who enjoy proving or disproving that an attack works, and who don't consider the job done until it's fixed. Solid offensive skills: web and API penetration testing (OWASP), Active Directory attack techniques, and a taste for business-logic abuse beyond the technical stack. Investigation fundamentals: comfortable diggi

記載されているスキル

Control & RiskCybersecurity

すべての求人であなたのマッチスコアを確認

BabZitunaは、すべての求人をあなたのプロフィールと照らし合わせて6つの実際の指標でスコア化し、なぜそのスコアになったのかを示します。公平性は監査済みです(公開バイアス監査を読む)。

アプリを入手 → ✓ 求職者は100%無料
ある求人のスコア内訳 例
スキル96経験90勤務地84働き方74雇用形態61給与データなし

例示の数字で、実在の候補者ではありません。各指標はあなた自身のプロフィールから100点満点で採点され、測定できない指標は推測せずにそう表示します。