Security Engineer - Purple Team specialist H/F
Job description
About the role
You will design and execute sophisticated adversary emulation scenarios that rigorously test the resilience of Veepee's dynamic e-commerce environment across its multi-cloud and on-premises landscape. This role places you at the intersection of offensive security and detection engineering, where your work will directly validate the efficacy of our security monitoring and response capabilities. You will collaborate intimately with our blue team defenders to refine detection rules, tune alert fidelity, and ensure our security tooling keeps pace with an evolving threat landscape. Your contributions will focus on automating complex attack chains, measuring detection gaps, and quantifying risk in business-impact terms for executive stakeholders. You will own the purple team methodology end-to-end, from initial threat modeling and attack planning through to comprehensive reporting and actionable remediation guidance. This position demands a high degree of autonomy as you pioneer new techniques to simulate realistic threats against our customer-facing platforms and internal infrastructure. You will act as a force multiplier for the security organization, translating offensive insights into defensive improvements that protect brand reputation and customer trust. The role requires a deep understanding of how attackers operate in the cloud and how to leverage AI-driven security operations to stay one step ahead.
Key facts
What you'll do
Orchestrate continuous adversary emulation programs that challenge Veepee's detection and response capabilities across hybrid cloud infrastructures.
Architect, develop, and maintain an expanding library of reusable attack playbooks that simulate the tactics, techniques, and procedures of advanced threat actors.
Leverage offensive automation to conduct large-scale security validation exercises, measuring the effectiveness of security controls and identifying latent vulnerabilities.
Collaborate with detection engineers to build high-fidelity telemetry, ensuring that security information and event management systems accurately capture malicious behaviors.
Conduct in-depth compromise assessments to understand how attackers might move laterally within our complex, multi-tier application environments.
Perform threat hunting guided by intelligence, proactively searching for indicators of compromise and anomalous activity across endpoints, networks, and cloud services.
Translate complex offensive findings into clear, actionable reports that communicate risk severity and recommended mitigations to technical and non-technical audiences.
Work closely with application and infrastructure owners to ensure that remediation efforts are practical, prioritized, and aligned with business objectives.
Integrate red team insights into the security engineering workflow, helping to validate the efficacy of new detections before they are deployed to production.
Champion the adoption of security automation and artificial intelligence, leveraging large language models to enhance analysis, reporting, and threat intelligence processing.
Participate in the end-to-end vulnerability lifecycle, from initial discovery and validation through to tracking remediation and verifying closure.
Support the continuous improvement of incident response playbooks by injecting realistic scenarios uncovered during purple teaming activities.
Engage with the AI agent orchestration layer to test how autonomous security agents detect, respond to, and remediate simulated attacks.
Contribute to the success of the Bug Bounty program by identifying valid attack paths that can be transitioned into controlled testing scenarios.
Requirements
You have a Bachelor's degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
You possess proven experience as a Purple Team specialist, Red Team operator, or Detection Engineer with a strong track record in security operations.
You are highly proficient with the core technologies of security operation centers, including but not limited to SIEM, EDR, and network security monitoring tools.
You demonstrate mastery of offensive security techniques, with hands-on experience in areas such as lateral movement, credential access, and payload execution.
You have a deep understanding of cloud security architectures, containerization, and modern infrastructure-as-code practices.
You are fluent in scripting and programming, using languages such as Python, Go, or PowerShell to automate complex security tasks and workflows.
You hold a security certification such as OSCP, OSEP, GPEN, or similar, which validates your practical offensive security capabilities.
You communicate effectively with both technical teams and business stakeholders, translating complex security concepts into clear and concise narratives.
Nice to have
Experience contributing to a Bug Bounty program and understanding the nuances of responsible disclosure.
Familiarity with LLM pipelines and AI-driven security operations, including the integration of large language models into detection and analysis workflows.
Hands-on experience with agentic security automation and orchestration platforms that manage AI-driven security tasks.
Practical notes
Permanent contract.
Based in Paris.
Veepee is an equal opportunity employer, committed to fostering a diverse and inclusive workplace where all individuals have the opportunity to thrive. We welcome applications from qualified professionals regardless of background, gender, identity, religion, disability, age, sexual orientation, or any other protected characteristic.