Security Engineer - Purple Team specialist H/F
Overview
Pioneer of online flash sales since 2001 and key player in European e-commerce, Veepee collaborates with over 7,000 brands to offer highly discounted products available for a limited time. Operating across sectors including fashion, home, wine, travel and beauty, Veepee achieved a turnover of 3.3 billion euros incl. VAT in 2024 and employs 5,000 staff across 10 countries.
Organization and team
The cybersecurity team includes Red, Purple and Blue teamers, plus risk and compliance oriented profiles, all working together to fix security weaknesses with innovative solutions adapted to business needs. A Bug Bounty program, an authenticated program on partner-facing platforms, an annual external Red Team engagement and recurring compliance assessments keep us honest and focused on risk management.
Our threat detection and incident response runs fully in-house: you can touch everything, from detection engineering, case management and response, threat intelligence and the vulnerability lifecycle to the AI agents orchestrated on top of it. Automation and AI are at the core of everything, with agents triaging alerts 24/7 so humans focus on what matters, an LLM pipeline auditing our code, and a remediation loop feeding product teams with every confirmed finding.
Responsibilities
- Attack Veepee’s perimeter the way a real adversary would: red team, penetration tests (grey/black/white/AI box), Active Directory attack paths, phishing campaigns and the business web-based processes themselves (member journeys, seller flows, payment chains), hunting for logic flaws that scanners might miss.
- Put our risk register and threat intelligence to the test: confirm or refute a stated risk or emerging threat with a working attack scenario.
- Qualify external inputs: Bug Bounty reports (public and authenticated programs) and alerts escalated by our intelligent agents during cyber-watching rotations.
- Convert confirmed attack paths into automated defenses: a detection rule, a hunting query, or an automated control. If a bot can do it, we automate it.
- Build and improve the team’s tooling: AI-assisted code audit, password auditing, secret hunting, attack-surface monitoring.
- Carry findings through remediation: explain impact to product and infra teams, propose fixes, track them in the vulnerability-management lifecycle, and re-attack to verify closure.
- Share discoveries with technical and business teams and promote security culture within day-to-day constraints.
Qualifications
- The most important attribute is motivation: naturally curious profiles who enjoy proving or disproving that an attack works and who don’t consider the job done until it’s fixed.
- Solid offensive skills: web and API penetration testing (OWASP), Active Directory attack techniques, and a taste for business-logic abuse beyond the technical stack.
- Investigation fundamentals: comfortable digging through EDR, logs and network data to reach a verdict, and turning attacker behavior into detection logic or advancing offensive capabilities with a strong growth mindset.
- Scripting and automation (Python, Bash, PowerShell); interest in AI-assisted security tooling (LLM-based code audit, agentic workflows) is a strong plus.
- Documentation practices: you document what you do and make it reproducible.
- Strong communication skills: you can convince a product team to fix something they didn’t want to hear about.
- Experience: approximately 3–5 years in offensive security, detection engineering or a mixed red/blue role.
- Languages: French and professional English.
Benefits
- Variable bonus
- Dynamic and creative environment within international teams
- Variety of self-education courses on our learning platform
- Participation in meetups and conferences locally and internationally
- Flexible office with up to 2 days at home
- Health insurance
Recruitment process
- 30-minute HR screen with a Veepee Recruiter
- Technical and operational discussion with the team
- Final interview with Head of Cybersecurity
We believe it is up to you to define how you work, develop yourself, and progress. At Veepee we guarantee that you can just be yourself. For diversity and inclusion, Veepee reviews all applications on an equal basis. For more information about our system, see the company page and our personal data protection policy on the career site.
#J-18808-Ljbffr