{"id":1013269,"url":"https://alion.io/job/vibe-co-principal-security-engineer","title":"Principal Security Engineer","company":{"id":3937,"name":"Vibe.co","domain":"vibe.com","url":"https://alion.io/company/vibe","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"A","score":95,"open_postings":3,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":77,"computed_at":"2026-09-25T05:45:01Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Paris, France"],"countries":["FR"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":115000,"max":175000,"currency":"EUR","period":"year","gross":null,"usd_annual":200892},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"GCP","optional":false},{"name":"GitOps","optional":false},{"name":"HIPAA","optional":false},{"name":"ISO 27001","optional":false},{"name":"Kubernetes","optional":false},{"name":"SOC 2","optional":false}],"status":"live","first_seen_at":"2026-09-17T16:56:06Z","employer_posted_date":"2026-09-17","last_verified_at":"2026-09-26T02:14:53Z","board_verified":true,"closed_at":null,"days_open":8,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":8},"description":"Streaming TV is no longer just a brand awareness channel. It’s becoming a core part of the performance marketing mix, alongside search and social. Vibe.co is building the platform that makes TV work like the rest of the acquisition stack: targeted, measurable, and optimized for results.\nVibe.co is an Audience First Streaming TV Advertising platform that gives marketers the tools to reach the right audiences, optimize campaigns in real time, and understand what’s actually driving business outcomes. With hyper-targeted segmentation, AI-powered recommendations, real-time optimization, and incrementality measurement, Vibe brings the precision and accountability of digital advertising to the biggest screen in the house.\nToday, more than 12,000 brands use Vibe.co to reach 120 million+ households. And in August 2026, Vibe.co became a Walmart company, opening up a new chapter for the business and the industry. With Walmart’s first-party data and purchase signals now part of the Vibe platform, advertisers can connect TV advertising to real-world transactions and measure the impact of CTV with a level of precision previously associated with platforms like Google and Meta.\nThis is a unique moment to join Vibe. With Walmart’s scale, data, and reach behind us, we’re building the next generation of TV advertising and creating a more measurable, performance-driven future for the channel.\nAbout the Role\nYou'll be Vibe's founding security hire. Security has been part of how we build since day one and we're already SOC 2 Type 2 compliant, but nobody has owned it full-time. Ad spend and headcount have both roughly doubled every year since 2022, enterprise partnerships keep expanding, and the more visible Vibe becomes, the more scrutiny comes with it. Now it needs an owner.\nYou'll define the risk model, set the roadmap, decide what we harden and what we accept, and turn policies into running procedures in code on the paths engineers and AI already use. That work happens in a cloud native ecosystem across AWS and GCP, with most of our services running on Kubernetes, everything as code and a GitOps deployment model.\nReporting to our, Head of Infrastructure, and joining a lean six-person Infrastructure and IT team. You won't do it alone, but you'll be the main contributor, and the person every team turns to on security. Since we joined forces with Walmart, you'll also coordinate directly with their cloud security teams.\nWhat You'll Do\nRisk & Governance\nMap Vibe's risk model across every major system.\n\nSet the security roadmap with clear priorities.\n\nSecurity Engineering\nPave the road with guardrails and secure defaults enforced across the engineering tool set.\n\nShip the golden paths so the safe way is the easy one.\n\nHarden security across our cloud native ecosystem (AWS and GCP) and third-party providers.\n\nOwn access management from onboarding to offboarding, and get it to the point where it runs without you.\n\nDetection & Response\nPrioritize vulnerability findings by real exposure, assign them to the team that owns the code, and follow remediation through to closure.\n\nOwn security incident response from detection through resolution.\n\nTurn manual processes into pipelines that run on their own.\n\nLaunch and run Vibe's private bug bounty program.\n\nTrust & Compliance\nOwn SOC 2 compliance end to end and maintain current certification.\n\nDrive Vibe's future compliance initiatives and requirements.\n\nDefine Vibe's security posture and make it self-serve so enterprise deals clear security without routing through you.\n\nSecurity Culture\nSet clear, practical rules for safe AI use, built into the tools themselves, covering both the AI we ship in our products and the AI our teams work with every day.\n\nRun security awareness training and measure behavior changes so the whole company raises its bar.\n\nWhat You Need\nBuilt a security function as a company's first security hire.\n\nWrite code comfortably and bring deep cloud-native security experience.\n\nManaged a compliance framework at scale, such as SOC 2, ISO 27001 or HIPAA.\n\nManaged AI security risk hands on, both in what a company ships with AI and in how its employees use it day to day.\n\nNice to Haves\nRan a private bug bounty program.\n\nAd tech security background, including exposure to US privacy law (CCPA/CPRA, VPPA) in a data-heavy environment.\n\nNavigated security through a company acquisition.\n\nOur Values\nAt Vibe, we run on three values: Impact, Ambition, and Urgency. We tie every goal to a real business outcome, think 10x rather than settling for good enough, and move daily rather than waiting for perfect conditions.\nYou'll thrive here if you own outcomes without needing direction, default to action, and hold yourself to results, not effort.\nThis is a high-performance environment with high-performance rewards: you'll work alongside people who push you, with real ownership over hard problems in a market that's moving fast.\nIf that sounds like the best version of your career, we want to meet you.\nWhat We Offer\nFor candidates in France, the pay range for this role is €115,000-€175,000.\nAt Vibe, we want you to build something, own something, and grow fast. Here's how we back that up:\nVariable pay - Based on real Vibe business goals.\n\nHybrid flexibility - We're in the Heart of Paris and our team is in 3x a week!\n\nHealth insurance - Full coverage via Alan.\n\nMeal vouchers - Via Swile.\n\nAnnual offsite - The whole team, once a year, somewhere worth the trip.\n\nTech Syncs - Engineering and Product meet in person at least quarterly, worldwide.\n\nOur Interview Process\nWe respect your time. Here's exactly what to expect, no surprises, no ghosting.\nRecruiter Screen - 30 minutes. We’ll share more context on the role and team, and learn more about your background and what you’re looking for.\n\nHiring Manager Interview - 45 minutes. Meet with the person you’d work with directly and dive deeper into your experience, technical background, and approach to the role.\n\nTechnical Assessment - 90 minutes. A deeper technical conversation covering core engineering skills, problem-solving, and a technical use case relevant to the role.\n\nBar Raiser Interview - 30 minutes. Meet with a senior leader at Vibe for a final conversation and an opportunity to ask any remaining questions.\n\nOffer - We move quickly once we’ve made a decision. We don’t let good decisions sit.\n\nEqual Opportunity\nVibe is an equal opportunity employer. We evaluate all applicants without regard to race, color, religion, national origin, gender, gender identity or expression, sexual orientation, age, disability, veteran status, or any other characteristic protected by law.\nWe believe the best ideas come from teams with different backgrounds, perspectives, and experiences. If you need a reasonable accommodation during the application or interview process, please let us know.\nReferral Instructions\nBeing referred? Ask your contact to submit your application directly on your behalf.","description_format":"text","description_chars":6959,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Health insurance"],"hiring_locations":[{"name":"France","iso":"FR","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Advertising"],"lifecycle":[{"event":"open","at":"2026-09-17T21:21:17Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":7,"expected_fill_days":77,"reasons":["conf:0","velocity","win:early"],"computed_at":"2026-09-25T05:45:01Z"},"pay":{"stated_usd_annual":200892,"is_top_pay":true},"html_url":"https://alion.io/job/vibe-co-principal-security-engineer","json_url":"https://alion.io/job/vibe-co-principal-security-engineer.json","meta":{"generated_at":"2026-09-26T02:56:52Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3124,"day_limit":5000,"remaining_today":1876,"minute_limit":60,"resets_at":"2026-09-27T00:00:00Z"}}}