Live opening · Posted 8 hours ago

Bug Bounty Hunter (M/F)

Septeo · Full remote, , France
Smartrecruiters Yes Full-time
JobBeeper subscribers received an alert for this role.

At a glance

The key details from the original listing.

Posted 8 hours ago
CompanySepteo
LocationFull remote, , France
Job typeFull-time
Work modeYes
SourceSmartrecruiters
ListedPosted 8 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
13 min from Smartrecruiters publishing this role to us finding it
12 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
62,820 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

We are looking for a permanent Bug Bounty Hunter (M/F), based in Montpellier, Valbonne, or working fully remotely.
What we can achieve together:
Septeo's Red Team has transformed the way it operates. Vulnerability research no longer relies on occasional, manually executed campaigns, but on agentic offensive workflows: chains of agents that continuously explore the exposed attack surface, test applications, analyse code and verify fixes.
This shift changes where the value lies: what matters today is no longer the number of testing hours, but the quality of the tools and capabilities designed, together with the judgement used to steer them.
Reporting to the Head of Offensive Security R&D, your role will cover two core areas: building, stabilising and maintaining vulnerability detection tools and processes; and working closely with the Group’s Product Owners, DTOs, developers and CISOs to share findings, support remediation and strengthen security practices.
Your work will be built around three systems that currently structure our offensive security capabilities:
An AI-powered internal EASM platform: continuous discovery of the exposed attack surface, asset qualification and ownership mapping, and identification of attack chains.
Agentic SAST: continuous code analysis and repository-specific remediation proposals, rather than generic recommendations.
A vulnerability lifecycle management platform: from initial finding to automated retesting and management-level reporting.
You will operate, strengthen and continuously improve these systems. From day one, you will also identify and design what is missing: you will not simply execute a roadmap, but help shape it.
Your day-to-day responsibilities:
Design, develop and enhance offensive tools and workflows, including their architecture, scope, guardrails and stop conditions.
Deploy, stabilise and maintain them with a Dev/DevOps mindset, covering pipelines, CI/CD, monitoring and continuous reliability improvements.
Operate them on a daily basis: schedule, launch and monitor workflows; diagnose agent drift; triage false positives; and restore systems after incidents.
Prototype quickly, measure tangible value and decide what should be industrialised or discontinued.
Work regularly with the Group’s Product Owners, DTOs, developers and CISOs to qualify vulnerabilities, turn findings into actionable information and track remediation.
Document design decisions, including guardrails that were considered but not retained and the reasons behind those choices.
Propose and design the next capabilities that will help strengthen the Group’s security posture.
Could this be you?
First and foremost, you have a background as a Hunter, Bug Bounty Hunter or security researcher. You know how to explore an attack surface, identify non-obvious exploitation paths and distinguish a genuinely exploitable vulnerability from scanner noise. A strong bug bounty track record or freelance security experience will be highly valued.
You have hands-on experience applying AI to security, including agents, automation, tool development and advanced use of AI models. Rather than limiting yourself to manual testing, you can define what needs to be built, guide a coding agent, review its output and assess whether it is robust. Here, sound judgement and the ability to improve the toolset matter more than expertise in any particular programming language.
You are experienced in orchestrating agentic workflows: chaining and monitoring agents, understanding why a workflow is drifting and correcting it. You are also comfortable with production deployment and product stabilisation, including pipelines, CI/CD, monitoring and continuous improvement. Concrete achievements will matter more than a list of tools.
You are highly autonomous, able to move forward without constant guidance, quickly understand an objective even when it is not perfectly defined, and turn an idea into an operational solution.
You can also communicate effectively with a wide range of stakeholders, including Product Owners, DTOs, developers and CISOs, to help drive remediation and improve practices. You share the Red Team mindset: technical curiosity, a talent for finding unconventional paths and the persistence to keep going when a system resists.

Employment type
Full-time

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App