Bug Bounty Hunter (M/F)

SEPTEO

Montpellier, Valbonne

Hybrid

EUR 70,000 - 120,000

Full time

45 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Septeo is seeking a permanent Bug Bounty Hunter (M/F) for roles based in Montpellier, Valbonne, or remote. You will build and maintain offensive security tools, guide AI-enabled processes and collaborate with product teams to strengthen remediation and security practices.

You will lead the design and deployment of agentic workflows, ensuring robust tooling, continuous improvement, and effective stakeholder communication across the Group.

Qualifications

  • Background as Hunter, Bug Bounty Hunter or security researcher.
  • Hands-on experience applying AI to security, including agents, automation, tool development and AI model usage.
  • Experience orchestrating agentic workflows and production deployment.
  • Highly autonomous with strong problem-solving and initiative.
  • Ability to communicate with Product Owners, DTOs, developers and CISOs.

Responsibilities

  • Design, develop and enhance offensive tools and workflows, including architecture and guardrails.
  • Deploy, stabilize and maintain tools with a Dev/DevOps mindset (pipelines, CI/CD, monitoring).
  • Operate workflows daily: schedule launches, monitor, diagnose drift, triage false positives, restore systems after incidents.
  • Prototype quickly and decide what to industrialize or discontinue.
  • Collaborate with Product Owners, DTOs, developers and CISOs to qualify vulnerabilities and track remediation.
  • Document design decisions and guardrails with rationale.
  • Propose next capabilities to strengthen security posture.

Skills

Bug bounty hunter
Security researcher
AI for security
Agentic workflows
Autonomy

Job description

Job Description

Weare looking for a permanent Bug Bounty Hunter (M/F), based in Montpellier, Valbonne, or working fully remotely.

What we can achieve together:

Septeo'sRed Team has transformed the way it operates. Vulnerability research no longer relies on occasional, manually executed campaigns, but on agentic offensive workflows: chains of agents that continuously explore the exposed attack surface, test applications, analyse code and verify fixes.

Thisshift changes where the value lies: what matters today is no longer the number of testing hours, but the quality of the tools and capabilities designed, together with the judgement used to steer them.

Reportingto the Head of Offensive Security R&D, your role will cover two core areas: building, stabilising and maintaining vulnerability detection tools and processes; and working closely with the Group’s Product Owners, DTOs, developers and CISOs to share findings, support remediation and strengthen security practices.

Yourwork will be built around three systems that currently structure our offensive security capabilities:

  • An AI-powered internal EASM platform: continuous discovery of the exposed attack surface, asset qualification and ownership mapping, and identification of attack chains.
  • Agentic SAST: continuous code analysis and repository-specific remediation proposals, rather than generic recommendations.
  • A vulnerability lifecycle management platform: from initial finding to automated retesting and management-level reporting.

Youwill operate, strengthen and continuously improve these systems. From day one, you will also identify and design what is missing: you will not simply execute a roadmap, but help shape it.

Yourday-to-day responsibilities:
  • Design, develop and enhance offensive tools and workflows, including their architecture, scope, guardrails and stop conditions.
  • Deploy, stabilise and maintain them with a Dev/DevOps mindset, covering pipelines, CI/CD, monitoring and continuous reliability improvements.
  • Operate them on a daily basis: schedule, launch and monitor workflows; diagnose agent drift; triage false positives; and restore systems after incidents.
  • Prototype quickly, measure tangible value and decide what should be industrialised or discontinued.
  • Work regularly with the Group’s Product Owners, DTOs, developers and CISOs to qualify vulnerabilities, turn findings into actionable information and track remediation.
  • Document design decisions, including guardrails that were considered but not retained and the reasons behind those choices.
  • Propose and design the next capabilities that will help strengthen the Group’s security posture.
Company Description

Septeois a leading software company in Europe, with an international presence, and is ranked among the top five vertical software publishers in France. Experiencing strong growth and continuous transformation, the Group has established itself as a key player in the software industry through the strength of its people: determined, bold and committed teams.

At Septeo, artificial intelligence is at the heart of our evolution. We see AI as a driver of sustainable performance, collaboration and innovation, responsibly embedded in everyday practices and made accessible across all our professions. Our ambition is clear: “make intelligent software for Europe”.

Our culture is built on strong values: being, acting and transforming together. It is not set in stone; it comes to life every day through our actions and decisions, striking a balance between performance, responsibility and enjoyment.

This ambition is reflected in what we do every day: designing software that supports life’s essential moments for millions of citizens. Being behind these key moments comes with great responsibility. It is ours. And perhaps, soon, yours.

JoiningSepteo means becoming part of an international collective journey, helping drive the Group’s transformation in a fast-moving environment, and turning AI into a tangible source of value creation, today and tomorrow.

Qualifications

Could this be you?

  • First and foremost, you have a background as a Hunter, Bug Bounty Hunter or security researcher. You know how to explore an attack surface, identify non-obvious exploitation paths and distinguish a genuinely exploitable vulnerability from scanner noise. A strong bug bounty track record or freelance security experience will be highly valued.
  • You have hands‑on experience applying AI to security, including agents, automation, tool development and advanced use of AI models. Rather than limiting yourself to manual testing, you can define what needs to be built, guide a coding agent, review its output and assess whether it is robust. Here, sound judgement and the ability to improve the toolset matter more than expertise in any particular programming language.
  • You are experienced in orchestrating agentic workflows: chaining and monitoring agents, understanding why a workflow is drifting and correcting it. You are also comfortable with production deployment and product stabilisation, including pipelines, CI/CD, monitoring and continuous improvement. Concrete achievements will matter more than a list of tools.
  • You are highly autonomous, able to move forward without constant guidance, quickly understand an objective even when it is not perfectly defined, and turn an idea into an operational solution.
  • You can also communicate effectively with a wide range of stakeholders, including Product Owners, DTOs, developers and CISOs, to help drive remediation and improve practices. You share the Red Team mindset: technical curiosity, a talent for finding unconventional paths and the persistence to keep going when a system resists.
Additional Information
  • Being part of Septeo’s AI-First journey and discovering new ways of working through artificial intelligence.
  • Growing and thriving through a personalized learning path and internal mobility opportunities.
  • Enjoying a meaningful human experience by connecting and sharing through themed events (afterworks, sports activities, CSR initiatives, seminars, etc.)
  • Joining a community that cares about people and is committed to equal opportunities, diversity, and inclusion.
Our3-step recruitment process:
  1. An initial phone conversation with a Talent Acquisition Specialist to introduce the role and its responsibilities, while getting to know you better.
  2. A second interview with a dual objective: presenting our Group and its values, while exploring your motivations and how your career aspirations align with the position.
  3. A final interview with your future manager, giving you the opportunity to dive deeper into the role and validate your skills and experience.
What are you doing on Monday?
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Bug Bounty Hunter (M/F)
Bug Bounty Hunter (M/F)

SmartRecruiters, Inc. • France

Remote
EUR 70,000 - 110,000
Bug Bounty Hunter H/F
Bug Bounty Hunter H/F

SEPTEO • Montpellier, Valbonne

Hybrid
EUR 70,000 - 110,000
Bug Bounty Hunter H/F
Bug Bounty Hunter H/F

SmartRecruiters, Inc. • France

Remote
EUR 85,000 - 110,000
Senior Offensive Security Engineer H/F
Senior Offensive Security Engineer H/F

SEPTEO • France

On-site
EUR 65,000 - 90,000
Responsable Support Client H/F
Responsable Support Client H/F

SEPTEO • Valbonne

Remote
EUR 70,000 - 110,000
Formation personnalisée
Mobilité interne
Afterworks et séminaires
+1
Backend & Data Engineer IA H/F
Backend & Data Engineer IA H/F

SEPTEO • Valbonne

Remote
EUR 65,000 - 90,000
Backend & Data Engineer IA H/F
Backend & Data Engineer IA H/F

SEPTEO • Paris

Hybrid
EUR 75,000 - 110,000
Chef de projet technico fonctionnel H/F
Chef de projet technico fonctionnel H/F

Septeo • Montpellier

On-site
EUR 45,000 - 65,000
Backend & Data Engineer IA H/F
Backend & Data Engineer IA H/F

SEPTEO • Toulouse

Hybrid
EUR 90,000 - 110,000
Commercial Terrain Digital Immobilier H/F
Commercial Terrain Digital Immobilier H/F

SEPTEO • Lyon

Hybrid
EUR 42,000 - 65,000