Mirakl, founded in 2012, builds the marketplace platform that sits between enterprise retail and B2B operators and the thousands of third-party sellers transacting on their sites. The core product - a hosted platform handling catalog ingestion, seller onboarding, payments orchestration, and order routing - is what 450+ clients like large retailers and industrial distributors depend on to run multi-vendor commerce at scale. That means the attack surface is wide: third-party seller APIs, marketplace admin portals, and the data pipelines that move product, pricing, and order data between Mirakl's platform and a client's own commerce stack. A breach in a seller integration doesn't just expose one merchant; it can cascade across the entire marketplace.
The security challenge is architectural. Mirakl's platform connects to enterprise clients' ERP, OMS, and PIM systems while simultaneously onboarding and managing over 100,000 third-party seller accounts globally. Sellers are untrusted parties by design - they upload product data, set pricing, and manage fulfillment through APIs that must be authenticated and rate-limited without degrading marketplace performance. Payment flows add another layer: the platform mediates financial transactions between end customers, marketplace operators, and sellers, making PCI DSS scope and fraud detection engineering non-negotiable. Teams working here are operating in an environment where the trust model is fundamentally adversarial at the edges.
Mirakl operates globally with a distributed team. The technical stack centers on enterprise-scale SaaS - high-throughput APIs, cloud infrastructure, and integration layers that must maintain uptime and data integrity across hundreds of concurrent marketplace instances. The company's verticals (retail, B2B) mean security engineers face different threat profiles: retail marketplaces deal with credential stuffing, card testing, and bot-driven inventory manipulation, while B2B marketplaces face procurement fraud and supply-chain data exfiltration. If you're looking for a role where the security work maps directly to money moving and data flowing between untrusted parties at scale, the stakes here are concrete and measurable.






