Security Engineer - Full Remote (France) or Hybrid

Voyage Privé
Aix-en-Provence, France
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English, French

Tech stack

Java (Programming Language) PHP (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Build Automation Microsoft Azure Cloud Computing Cloud Computing Security Code Review Continuous Integration Github Identity and Access Management
+19 more
Python (Programming Language) Key Management Node.Js Open Web Application Security PCI Data Security Standards Secure Coding Security Software Data Streaming Systems Integration Virtual Machines Software Vulnerability Management Google Cloud Software Security Gitlab Containerization Serverless Computing Jenkins Static Application Security Testing Golang

Job description

As a Security Engineer, you’ll play a key role in shaping the security and resilience of Voyage Privé’s technology platform. You’ll work closely with Engineering, Product, and Platform teams to embed security practices into every stage of product development, deliver measurable impact, and help us scale efficiently while maintaining a strong security posture.

You’ll have the opportunity to build many security foundations from scratch - from internal tooling to CI/CD guardrails - and influence key architectural and technical decisions as we redesign our platform for scale.

Your key responsibilities will include:

  • Strengthen the security posture across products, data and infrastructure: secure coding practices, code reviews, threat modeling, vulnerability remediation, cloud, and network hardening.
  • Develop automated security guardrails integrated into CI/CD pipelines (SAST, SCA, secrets scanning).
  • Design secure architectures for applications, APIs, data flows, and integrations in partnership with engineering teams.
  • Secure hybrid environments combining virtual machines, containerized workloads, and cloud-native services, ensuring consistent security standards across the entire platform.
  • Drive proactive risk identification through continuous scanning, threat modeling sessions, risk assessments, and architecture reviews.
  • Enable engineering teams to build secure-by-design practices by acting as a trusted advisor, developing internal tools, and leading security awareness sessions.
  • Operational security & incident readiness: participate in on-call rotations, investigate security events, and improve incident response workflows.
  • Lead security improvement projects: build automation, enhance tools, optimize processes, and foster a culture of security ownership., Our HQ in the South of France offers an exceptional environment - natural, cultural, and digital - on a modern and eco-responsible campus.

Prefer flexibility? We offer a hybrid model for all other positions with 3 mandatory on-site days per week plus 4 fully remote weeks per year.

Put meaning back into your work and join a unique ecosystem that connects worlds often far apart: business, sports, education, and social impact, through projects like Ecole des XV, Provence Rugby, VP Green, Les Tremplins, and Chez Pierre.

Requirements

  • 5-7 years of experience in software engineering, security engineering, DevSecOps, or equivalent technical security roles.
  • Strong development background (Python, Node.js, Java, Go, PhP or similar).
  • Hands-on experience with modern CI/CD systems (GitHub Actions, GitLab, Jenkins).
  • Solid understanding of cloud security principles (AWS, GCP, Azure).
  • Experience securing both virtualized systems (VMs) and containerized workloads.
  • Strong knowledge of secure coding, OWASP Top 10, and application security fundamentals.
  • Experience with SAST, SCA, container/IaC scanning, runtime security tools, IAM, and secrets management.
  • Pragmatic, engineering-first mindset: able to balance security with developer experience, velocity, and real-world constraints.
  • Excellent communication skills: able to translate complex security issues into actionable guidance for both technical and non-technical stakeholders.
  • Proactive, autonomous, critical thinker with a continuous improvement mindset.
  • Nice to have: previous experience or knowledge of compliance requirements (GDPR, PCI-DSS…)
  • Fluent in French and English.

About the company

About Voyage Privé

Born in France in 2006, Voyage Privé has grown from an ambitious startup into becoming the Europe’s leading travel tech platform. Operating across 9 markets with tens of millions of users, we’re not just another e-commerce success story - we’re a tech powerhouse revolutionizing online travel.

What makes us unique? A mission-driven culture where performance meets impact. Our innovative campus brings together tech talent, professional athletes, students, and artists, creating an ecosystem where digital innovation drives both business growth and positive change.

We’re now at an inflection point, upgrading our entire technical foundation with cloud architecture, AI, and real-time systems to become a reference and top-of-mind platform for luxury travel, known by travelers for its for excellent offer and customer experience, and by our providers as a high-performance business development partner.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.smartrecruiters.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · World Congress 2026 Europe

Videos

See all

Related articles

See all