SlipstreamJobsFresh Startup & VC-Backed Jobs

Principal Security Engineer

Vibe.co - Paris, Île-de-France, France - Hybrid - posted 2026-09-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: EUR 115,000 - 175,000 / annual

Vibe.co is an Audience-First Streaming TV Advertising platform that enables marketers to reach targeted audiences, optimize campaigns in real time, and measure business outcomes. The company recently became part of Walmart, combining Walmart's first-party data with Vibe's precision advertising capabilities. With 12,000+ brands using the platform to reach 120+ million households, Vibe is scaling rapidly. You will be Vibe's founding full-time security hire, taking ownership of security across the organization as it scales. While security practices have been embedded since inception (SOC 2 Type 2 compliant), the company now needs dedicated leadership as ad spend and headcount have doubled annually since 2022, enterprise partnerships expand, and visibility increases. Reporting to the Head of Infrastructure, you'll join a lean six-person Infrastructure and IT team and serve as the primary security owner across the company. You'll define Vibe's risk model, set the security roadmap, and decide what to harden versus accept. Your work spans a cloud-native ecosystem across AWS and GCP, with services running on Kubernetes, infrastructure-as-code, and GitOps deployment. You'll also coordinate directly with Walmart's cloud security teams. Key responsibilities include: mapping risk across major systems and setting security priorities; building guardrails and secure defaults across the engineering toolset; hardening cloud infrastructure and third-party integrations; owning access management from onboarding to offboarding; prioritizing vulnerability findings and managing incident response; maintaining SOC 2 compliance and driving future compliance initiatives; defining security posture for enterprise deals; establishing practical AI security rules for both shipped products and internal tool use; and running security awareness training. You'll transform manual security processes into automated pipelines, launch and operate a private bug bounty program, and build a security culture where the safe path is the easy path. REQUIREMENTS: - Experience as a company's first security hire, building a security function from the ground up - Comfortable writing code with deep cloud-native security expertise - Hands-on experience managing compliance frameworks at scale (SOC 2, ISO 27001, or HIPAA) - Direct experience managing AI security risk, both in shipped products and employee tool usage NICE TO HAVES: - Private bug bounty program experience - Ad tech security background with exposure to US privacy law (CCPA/CPRA, VPPA) in data-heavy environments - Experience navigating security through company acquisition

Similar roles