B

Brevo

CRM and marketing automation for SMEs

Customer Experience Associate - Ecommerce

Full-Time
No salary listed
Junior
Noida, Uttar Pradesh, India
HybridHybrid schedule with two work-from-home days per week.

About the job

Requirements
  • At least 2 years of experience in customer service.
  • Excellent written and spoken French communication skills at C1 level or above.
  • Ability to build customer relationships and customer confidence.
  • Familiarity with email marketing.
  • Ability to work independently and collaboratively.
  • Ability to understand technical aspects of email marketing, including DNS record creation and modification, email-friendly HTML, and the Brevo API.
Responsibilities
  • Manage and resolve daily client tickets, ensuring that client questions and problems are resolved properly and quickly.
  • Direct clients to the appropriate solutions through incoming and outgoing phone calls.
  • Address challenging customers and problems requiring escalation outside the department.
  • Provide all customers with an outstanding customer experience.
  • Develop client relations and work closely with the technical team to identify bugs.
  • Master email-marketing best practices, the Brevo platform, and the tools offered to customers.
  • Develop familiarity with DNS records, email-friendly HTML, and the Brevo API.
Desired Qualifications
  • Experience using tools such as JIRA, Freshdesk, or Zendesk.

About the company

Brevo is a European leader in digital marketing software that helps businesses manage customer relationships and grow sustainably. It offers a CRM and marketing tools to build personalized connections, with features for email marketing, automation, and transactional messaging, all accessible through a platform available in six languages. A forever free plan makes the core tools accessible to small and medium-sized enterprises, while Brevo Academy provides digital marketing training and onboarding. Enterprise plans include dedicated success managers and guided onboarding, with premium service options that add features and support. The company differentiates itself by its multilingual, SMB-friendly platform, a no-cost entry tier, and emphasis on guided training and personalized assistance. Its goal is to empower clients with comprehensive marketing tools and tailored support to foster client growth and a positive social impact.

Company Size

501-1,000

Company Stage

Debt Financing

Total Funding

$954.5M

Headquarters

Paris, France

Founded

2012

Get referred to Brevo

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Brevo’s September 25, 2026 status updates show incident containment and cleanup completed.
  • General Atlantic and Oakley Capital backing funds product, security, and U.S. expansion.
  • Recent AI and automation investments strengthen upsell potential across its customer base.

What critics are saying

  • September 10 and 14, 2026 breaches exposed 138 accounts and 100,000 websites.
  • Hardcoded Cloudflare keys and SAML flaws prove Brevo’s security controls failed repeatedly.
  • Trust erosion can trigger enterprise churn after September 2026 incident disclosures.

What makes Brevo unique

  • Brevo’s 2025 €500 million round made it a unicorn with deep capital.
  • Brevo combines CRM, email, SMS, WhatsApp, and forms in one platform.
  • Brevo serves SMEs globally with multilingual product support and freemium distribution.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Parental Leave

401(k) Company Match

Flexible Work Hours

Hybrid Work Options

Professional Development Budget

Bi-Annual Global Team Building Trip

Growth & Insights and Company News

Headcount

6 month growth

↑ 2%

1 year growth

↑ 2%

2 year growth

↑ 1%
IBS Technology
Sep 24th, 2026
The attack on Brevo's supply chain highlights the risks of poorly managed Cloudflare API keys.

The attack on Brevo's supply chain highlights the risks of poorly managed Cloudflare API keys. September 24, 2026 · IBS_technology Brevo, the French email marketing platform, suffered a two-phase breach. On September 10, attackers exploited a vulnerability in its SAML SSO and gained access to 138 customer accounts. Four days later, they returned, this time using a Cloudflare API key with full permissions that had been forgotten and left embedded in the source code. Cloudflare How did they do it? Using that key, they deployed a malicious Cloudflare Worker that rewritten HTTP responses directly at the network perimeter, without touching a single source file (which made the attack very difficult to detect through traditional audits). They combined this with a hidden WordPress plugin that installed itself without requiring additional authentication in administrator sessions, and a fake "clickfix" that was only displayed to administrator accounts to evade detection systems. Scope. More than 100,000 websites served malicious code for several hours on September 14. Among those affected are companies such as eBay, Louis Vuitton, and Michelin, and Trezor (a cryptocurrency wallet manufacturer) confirmed that 347,000 contact addresses were compromised. Why does this matter for companies that use Cloudflare's infrastructure? The attack vector was not a vulnerability in Cloudflare's own infrastructure, but rather an API credential that was never rotated. This is a stark reminder that Workers - which operate at the edge and leave no trace in the source code - are a particularly attractive target when a key is exposed. It's time to review periodic token rotation, minimum permission scope (scoped API tokens), and audits of Worker deployments in its own accounts.

KINAMU Business Solutions GmbH
Sep 22nd, 2026
SugarAI and Brevo integration: sync contacts and target lists automatically.

SugarAI and Brevo integration: sync contacts and target lists automatically. September 22, 2026 12:01:01 KINAMU Business Solutions GmbH SugarAI is an AI-powered customer platform for all marketing and sales channels. Brevo (formerly Sendinblue) is a platform for email and SMS communication and marketing automation. The KINAMU Brevo Connector connects the two systems and automatically synchronizes relevant data. Connecting SugarAI and Brevo. The connector synchronizes contacts, prospects, email addresses, and target lists between SugarAI and Brevo. The connection is based on a webhook. New and changed data is transferred automatically, with synchronization usually taking up to around one minute. Create target lists in SugarAI and use them in Brevo. Contact selection can remain in SugarAI, where information from different parts of the CRM is available. In addition to contact details, this can include company information, products, contracts, customer status, or previous activities. Target lists can be created directly in SugarAI using SAI reporter module. The corresponding lists are then made available in Brevo automatically. Automatically synchronize contacts. New contacts and prospects can also be created in Brevo automatically as well as changes to existing records are transferred as well. The integration also works in the other direction. For example, Brevo landing pages can be used to collect new leads or contacts and create them in SugarAI. The connector also supports custom fields in both SugarAI and Brevo, so additional information can be included in the synchronization alongside the standard contact data. Double opt-in and blacklist status. The in Brevo implemented double opt-in process can be used for newly synchronized contacts and leads. Double opt-in status is synchronized back to SugarAI. The Brevo blacklist status of a contact is also transferred to a separate field in SugarAI. This information can be used in SugarBPM to trigger further processes. Conclusion. The KINAMU Brevo Connector connects the CRM data in SugarAI with the communication and marketing functions of Brevo. Contacts and target lists can be synchronized automatically, while processes such as newsletter subscriptions, double opt-in, blacklist handling, and lead creation can remain connected to the existing SugarAI processes.

IT Security News
Sep 18th, 2026
Brevo supply-chain attack infected over 100,000 websites.

Brevo supply-chain attack infected over 100,000 websites. 2026-09-19 00:09 A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin. The company was first compromised on September 10, when attackers exploited a vulnerability in its [...] Read the original article: Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. Hacking & Cracking September 18, 2026 A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile... September 18, 2026 In "Cyber Security News" Email marketing and customer relationship management platform Brevo, formerly known as Sendinblue, suffered a supply chain attack in which malicious code... September 18, 2026 In "CySecurity News - Latest Information Security and Hacking Incidents"

Canadian Cyber Security Journal
Sep 18th, 2026
A compromised API key turned brevo into a launchpad for a ClickFix attack on 100,000 websites.

A compromised API key turned brevo into a launchpad for a ClickFix attack on 100,000 websites. What happened. Customer-engagement platform Brevo, first breached on September 10 through a flaw in its SAML single sign-on handling, suffered a second intrusion on September 14 when attackers used a compromised, long-lived Cloudflare API key to deploy a malicious worker script. The worker injected code into brevo.com, sibforms.com, and three JavaScript files Brevo customers embed directly into their own websites, showing selected visitors a fake "verify you are human" page instructing them to paste and run a command on their computer, a technique known as ClickFix. On sites running WordPress with a Brevo widget, the script attempted to install a malicious plugin if the visitor was logged in as an administrator. Security firm Sansec estimates the malware served for roughly four hours and likely reached more than 100,000 websites before Brevo removed the worker and revoked the compromised credentials. Read the disclosure from.

We Fix PC
Sep 17th, 2026
Brevo supply-chain attack injected ClickFix scripts on customer sites.

Brevo supply-chain attack injected ClickFix scripts on customer sites. Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. The customer relationship management and digital marketing company says the attackers used the API key to create a malicious Cloudflare Worker that modified content at the CDN edge for approximately five and a half hours on September 14. The attack affected pages on brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, and sibforms.com. The Cloudflare worker also modified the Brevo forms script, Brevo Conversations widget, and the Brevo SDK loader scripts that customers embed on their websites. In a post-mortem published today, Brevo explained that attackers obtained a long-lived Cloudflare API key with full account permissions that had been hardcoded in application source code, which allowed them to create Cloudflare Workers, routes, and DNS records across Brevo's zones without triggering an alert. "Because the Worker rewrote responses at the edge and removed security headers such as Content-Security-Policy, our origin servers and files remained unmodified and standard integrity checks did not detect the change," explained Brevo. The company says the key may have been compromised as early as late August, but there's no evidence of prior malicious activity. Upon detecting the compromise, Brevo removed the Worker and its routes, defining the exposure window as between 16:07 and 20:30 UTC. In the hours that followed, the company revoked the compromised key and credentials created with it, removed the hardcoded credential from its source code, deleted attacker-controlled hostnames, and purged its edge caches. Brevo says app.brevo.com, its API, email delivery infrastructure, and customer account data were not affected. Used in ClickFix attacks. The incident was first reported by security firm Sansec, which reported that it may have impacted up to 100,000 websites that use the affected Brevo components. Sansec says the incident began on September 14, 2026, between 16:05 and 20:13 UTC, but has now confirmed that all malicious subdomains stopped resolving on September 15, and Brevo files are now clean. Visitors to these websites were shown a fake Cloudflare verification page, followed by ClickFix instructions urging them to run a command on Windows. On WordPress websites embedding an affected Brevo widget, the script also checked whether the visitor was logged in as an administrator and attempted to upload a malicious plugin from https://cdn10.sendibt1[.]com/p/wm.zip. While SanSec was not able to retrieve the archive, BleepingComputer found it uploaded to VirusTotal and can confirm it pretends to be a WordPress plugin named "Web Media Optimizer" but acts as a persistent backdoor and JavaScript loader. Other domains BleepingComputer saw distributing the malicious WordPress plugin and scripts include https://yelahaye[.]surf and https://boiseno[.]club. Once installed, it hides itself from the WordPress plugin list, copies itself into the must-use plugins directory for persistence, and periodically contacts the attacker-controlled 'https://glegchner.com/ads.php' server. That URL is currently returning a Base64-encoded URL pointing to JavaScript that the plugin then injects into visitors' pages. The current Base64-encoded URL decodes to https://corralos[.]beer/a412dkoq.js, which the site injects to fetch a ClickFix lure to display. The plugin also stores a backup copy of the last valid JavaScript URL so it can continue loading malicious code if the remote server becomes unavailable. Finally, the plugin contains a hardcoded authentication key that allows attackers to generate a valid login session for a WordPress administrator account without knowing the account password. On September 10, Brevo disclosed a different SSO-related incident where attackers hijacked customer accounts and launched phishing attacks targeting customers of companies using Brevo. One high-profile victim was cryptocurrency wallet vendor Trezor, which reported on September 11 that phishing attacks reached 347,000 user email addresses and successfully compromised at least 2,500. Brevo did not respond to BleepingComputer's questions as to whether the SSO incident and the Cloudflare compromise were connected. WordPress administrators who visited an affected site while logged in on September 14 should check for unusual plugins installed or activated that day and remove them. If found, they should also rotate administrator passwords. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.