Security Engineer - Purple Team specialist H/F

Veepee

Paris

Sur place

EUR 60 000 - 105 000

Plein temps

14 jours+
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Avantages offerts par ce poste

Health insurance
Flexible office with up to 2 days at‑h
Learning platform

Résumé du poste

Veepee, a pioneer of online flash sales, seeks a security professional to join its in‑house threat detection and incident response team in a hybrid setup. You will lead offensive engagements, simulate AD attack paths, and translate findings into automated detections and remediation plans.

With 3–5 years in offensive security or mixed red/blue roles, you will work across web/API assessments and risk scenarios, collaborating closely with product and infrastructure teams.

Qualifications

  • 3–5 years in offensive security, detection engineering or a mixed red/blue role.
  • Proficiency in French and professional English.
  • Solid offensive skills: web and API penetration testing (OWASP), Active Directory attack techniques, and business-logic abuse beyond the technical stack.
  • Scripting and automation (Python, Bash, PowerShell); interest in AI-assisted security tooling is a strong plus.

Responsabilités

  • Attack Veepee's perimeter like a real adversary: red team, pen tests, phishing campaigns and business web flows.
  • Qualify risks and emerging threats with working attack scenarios.
  • Convert attack paths into detection rules, hunting queries, or automated controls.
  • Automate tools and processes; build AI-assisted security tooling where applicable.
  • Remediate findings and communicate impact to product and infra teams.

Connaissances

Offensive security
Penetration testing (web/API)
Active Directory attacks
Threat hunting
Automation scripting
Python
Communication
French & English fluency

Outils

OWASP

Description du poste

Pioneer of online flash sales since 2001, Veepee is a key player in European e‑commerce, collaborating with over 7,000 brands to offer highly discounted products for a limited time. With a turnover of 3.3 billion euros incl. VAT in 2024 and about 5,000 staff across ten countries, our cybersecurity team brings together Red/Purple/Blue capabilities and risk & compliance experts to secure business operations.

The threat detection & incident response team runs fully in‑house—covering detection engineering, case management and response, threat intelligence, and the vulnerability lifecycle. Automation and AI lie at the core: agents triage alerts 24/7, an LLM pipeline audits our code, and every confirmed finding fuels a remediation loop with product teams.

Responsibilities and Qualifications
  • Attack Veepee's perimeter the way a real adversary would: red team, penetration tests (grey/black/white/AI box), Active Directory attack paths, phishing campaigns and the business web‑based processes themselves (member journeys, seller flows, payment chains), hunting for logic flaws no scanner will ever find.
  • Put our risk register and threat intelligence to the test: take a stated risk or an emerging threat and confirm it, or refute it, with a working attack scenario.
  • Qualify what comes in from the outside: Bug Bounty reports (public and authenticated programs) and alerts escalated by our RAG agents during the cyber‑watching rotation.
  • Convert every confirmed attack path into something that runs without you: a detection rule, a hunting query, an automated control. If a bot can do it, we automate it.
  • Build and improve the team's tooling: AI‑assisted code audit, password auditing, secret hunting, attack‑surface monitoring.
  • Carry your findings through to remediation: explain the impact to product and infra teams, propose the fix, track it through our vulnerability‑management lifecycle, and re‑attack to prove it's closed.
  • Share your discoveries with technical and business teams and spread security culture in accordance with day‑to‑day constraints.
  • The most important thing is motivation! Naturally curious profiles who enjoy proving or disproving that an attack works, and who don't consider the job done until it's fixed.
  • Solid offensive skills: web and API penetration testing (OWASP), Active Directory attack techniques, and a taste for business‑logic abuse beyond the technical stack.
  • Investigation fundamentals: comfortable digging through EDR, logs and network data to reach a verdict, and turning attacker behavior into detection logic or solid on the offensive side with a strong will to grow there.
  • Scripting and automation (Python, Bash, PowerShell); interest in AI‑assisted security tooling (LLM‑based code audit, agentic workflows) is a strong plus.
  • You document what you do and make it reproducible.
  • Strong communication skills: you can convince a product team to fix something they didn't want to hear about.
  • Experience: ~3–5 years in offensive security, detection engineering or a mixed red/blue role.
  • Language: French and professional English.
Benefits
  • Variable bonus
  • The dynamic and creative environment within international teams
  • Variety of self‑education courses on our learning platform
  • Participation in meetups and conferences locally and internationally
  • Flexible office with up to 2 days at home
  • Health insurance

Fortheserviceofdiversityandinclusion,Veepeeiscommittedtoreviewingallapplicationsreceived onanequalbasis.

The Veepee Group processes your data collected as part of the management of your recruitment in order to manage your application file for the position for which you have applied. To find out more about our personal data protection policy, we invite you to consult it on our career site.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Engineer - Purple Team specialist H/F
Security Engineer - Purple Team specialist H/F

Veepee • France

Hybride
EUR 65 000 - 95 000
Variable bonus
Health insurance
Formation et meetups
+1
Security Engineer - Purple Team specialist H/F
Security Engineer - Purple Team specialist H/F

Veepee • Paris

Hybride
EUR 60 000 - 85 000
Variable bonus
International teams
Self-education platform
+3
Alternance - Délégué.e Protection des données H/F/X
Alternance - Délégué.e Protection des données H/F/X

Veepee • Saint-Denis

Sur place
EUR 30 000 - 40 000
Prime variable
Participation & intéressement
Télétravail possible jusqu'à 2 jours par semaine
+3
Software Engineer Go, Rust or Scala (Infrastructure) - Foundation (H/F/X)
Software Engineer Go, Rust or Scala (Infrastructure) - Foundation (H/F/X)

Veepee • Paris

Sur place
EUR 90 000 - 130 000
Variable bonus
Flexible Office
International teams
+2
Fullstack Developer (F# / C#) - Brand Payment
Fullstack Developer (F# / C#) - Brand Payment

Veepee • Paris

Sur place
EUR 70 000 - 110 000
Variable bonus
International teams
Learning platform courses
+2
Data Scientist
Data Scientist

Veepee • Paris

Sur place
EUR 70 000 - 110 000
Be part of a dynamic and international team!
Flexible schedule
Team buildings & afterworks
Sales Analyst & Support - Beauty (F/H/X) - CDD
Sales Analyst & Support - Beauty (F/H/X) - CDD

Veepee • L'Île-Saint-Denis

Hybride
EUR 42 000 - 65 000
Prime variable
Participation aux bénéfices et plan d\
Responsable du Contrôle interne et de la conformité groupe - H/F/X
Responsable du Contrôle interne et de la conformité groupe - H/F/X

Veepee • Saint-Denis

Sur place
EUR 60 000 - 75 000
Prime variable
Participation & intéressement
Télétravail possible jusqu'à 2 jours/semaine
+3
Sales Analyst & Support - Kids (F/H/X) - CDD
Sales Analyst & Support - Kids (F/H/X) - CDD

Veepee • Saint-Denis

Hybride
EUR 42 000 - 62 000
Prime variable
Participation aux bénéfices
Télétravail 2 jours/semaine
+5
Sales Analyst & Support - Kids - CDD H/F
Sales Analyst & Support - Kids - CDD H/F

veepee_france • Saint-Denis

Hybride
EUR 42 000 - 52 000
Prime variable
Participation aux bénéfices et plan d"