Security Engineer
Company: Voyage Privé
Location: Aix en Provence or Remote, France
Contract Type: Full-time / Permanent
About Voyage Privé
Born in France in 2006, Voyage Privé has grown from an ambitious startup into Europe's leading travel tech platform. Operating across 9 markets with tens of millions of users, we're not just another e-commerce success story - we're a tech powerhouse revolutionizing online travel. Our mission-driven culture combines performance with impact. We are currently upgrading our entire technical foundation with cloud architecture, AI, and real-time systems to become a reference platform for luxury travel.
Your Mission
As a Security Engineer, you’ll play a key role in shaping the security and resilience of Voyage Privé’s technology platform. You’ll work closely with Engineering, Product, and Platform teams to embed security practices into every stage of product development, deliver measurable impact, and help us scale efficiently while maintaining a strong security posture. You’ll have the opportunity to build many security foundations from scratch — from internal tooling to CI/CD guardrails — and influence key architectural and technical decisions as we redesign our platform for scale.
Key Responsibilities
- Strengthen the security posture across products, data, and infrastructure: secure coding practices, code reviews, threat modeling, vulnerability remediation, cloud, and network hardening.
- Develop automated security guardrails integrated into CI/CD pipelines (SAST, SCA, secrets scanning).
- Design secure architectures for applications, APIs, data flows, and integrations in partnership with engineering teams.
- Secure hybrid environments combining virtual machines, containerized workloads, and cloud-native services, ensuring consistent security standards across the entire platform.
- Drive proactive risk identification through continuous scanning, threat modeling sessions, risk assessments, and architecture reviews.
- Enable engineering teams to build secure-by-design practices by acting as a trusted advisor, developing internal tools, and leading security awareness sessions.
- Operational security & incident readiness: participate in on-call rotations, investigate security events, and improve incident response workflows.
- Lead security improvement projects: build automation, enhance tools, optimize processes, and foster a culture of security ownership.
What We’re Looking For
We’re looking for builders who move fast, think big, and care deeply about creating impact that lasts.
Your Profile:
- 5–7 years of experience in software engineering, security engineering, DevSecOps, or equivalent technical security roles.
- Strong development background (Python, Node.js, Java, Go, PhP or similar).
- Hands-on experience with modern CI/CD systems (GitHub Actions, GitLab, Jenkins).
- Solid understanding of cloud security principles (AWS, GCP, Azure).
- Experience securing both virtualized systems (VMs) and containerized workloads.
- Strong knowledge of secure coding, OWASP Top 10, and application security fundamentals.
- Experience with SAST, SCA, container/IaC scanning, runtime security tools, IAM, and secrets management.
- Pragmatic, engineering-first mindset: able to balance security with developer experience, velocity, and real-world constraints.
- Excellent communication skills: able to translate complex security issues into actionable guidance for both technical and non-technical stakeholders.
- Proactive, autonomous, critical thinker with a continuous improvement mindset.
- Fluent in French and English.
Nice to have:
- Previous experience or knowledge of compliance requirements (GDPR, PCI-DSS...)
Recruitment Process
We believe in a fast, transparent, and human recruitment process:
- Intro Call with a Talent Acquisition Partner (30–45 min)
- Manager Interview (60 min)
- Take-Home Task
- Task Debrief (60 min)
- On-Site Interview (60 min)
Start Date: The sooner, the better
Location: Aix en Provence or remote, France