Назад
Company hidden
7 дней назад

Security Engineer (Purple Team)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle/senior
Английский
b2
Страна
France
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Security Engineer (Purple Team): Conducting offensive security assessments and threat validation to identify and remediate vulnerabilities within complex e-commerce business logic and infrastructure. Focus on automating detection rules, leveraging AI-assisted security tooling, and collaborating with product teams to ensure robust security posture.

Location: Paris (Hybrid)

Company

hirify.global is a leading e-commerce company specializing in flash sales and digital retail experiences.

What you will do

  • Execute red team engagements, penetration tests, and phishing campaigns to identify logic flaws and security weaknesses.
  • Validate emerging threats and risk register items through practical attack scenarios.
  • Triage and qualify incoming Bug Bounty reports and security alerts.
  • Convert confirmed attack paths into automated detection rules and hunting queries.
  • Develop and improve internal security tooling, including AI-assisted code auditing and secret hunting.
  • Drive remediation efforts by communicating findings to product and infrastructure teams and verifying fixes.

Requirements

  • 3–5 years of experience in offensive security, detection engineering, or a mixed red/blue team role.
  • Solid offensive skills including web/API penetration testing (OWASP) and Active Directory attack techniques.
  • Proficiency in scripting and automation using Python, Bash, or PowerShell.
  • French and professional English proficiency required.
  • Strong communication skills to influence product teams and spread security culture.
  • Ability to document findings in a clear and reproducible manner.

Nice to have

  • Interest in AI-assisted security tooling such as LLM-based code audits and agentic workflows.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →