Security Engineer, Product Security – Seattle Office

last updated January 24, 2026 6:12 UTC

Aircall

HQ: Hybrid

more jobs in this category:

  • -> Mentor - Cyber Security Career Track (Part-time/Remote) @ Springboard
  • -> Microsoft SQL Server Database Administrator DBA @ red9.com
  • -> MSSQL Database Administrator @ Paymentology
  • -> Senior Developer - Integrations Team (C#/.NET) @ Deel
  • -> Technical web manager (Remote, Europe or Asia Pacific) @ Creative Force
As a Security Engineer, Product Security, you will help Aircall build and ship secure products by working closely with engineering teams and product managers to identify risk early, reduce vulnerabilities, and improve security quality across the software development lifecycle. You’ll support secure-by-design practices and help ensure security is integrated into how teams design, build, test, and release software.
In this role, you’ll be hands-on across threat modeling, vulnerability detection and remediation, and security testing. You will partner with engineers to make security practical and actionable — helping teams move quickly while raising the security bar.
Responsibilities:

    • Partner with engineering teams to review designs and implementation plans, identifying security risks early and recommending mitigations.
    • Perform threat modeling for new features and major changes, helping teams document risks, assumptions, and security controls.
    • Identify and help remediate common vulnerability classes across services and APIs (e.g., auth/authz, injection, data exposure, logic flaws).
    • Triage and support remediation of vulnerabilities identified through SAST/DAST tools, internal testing, or third-party findings.
    • Conduct security testing and validation, including targeted manual testing for high-risk areas.
    • Help improve secure development practices by creating reusable guidance, checklists, and secure patterns for engineering teams.
    • Contribute to security tooling and automation that improves coverage, reduces false positives, and streamlines security reviews.
    • Assist with product security incidents by supporting investigation, impact analysis, and follow-up remediation.
    • Communicate security risks clearly and pragmatically, helping teams prioritize effectively and ship safely.
    • Document learnings and contribute to evolving product security processes and standards.
Should have:

    • 2–5 years of experience in Product Security, Application Security, or software engineering with a strong security focus.
    • Strong understanding of web application and API security fundamentals and common vulnerability classes (OWASP Top 10).
    • Experience performing security reviews, threat modeling, or secure architecture assessments for software systems.
    • Familiarity with security testing tools and practices (SAST/DAST, dependency scanning, fuzzing, manual testing).
    • Comfort reading and reviewing production code in at least one language (e.g., Python, Go, Java, JavaScript/TypeScript).
    • Exposure to automated or AI-assisted security tools or workflows, and interest in applying them to improve developer experience and security outcomes.
    • Ability to work cross-functionally with engineering teams and communicate findings in a constructive, actionable way.
    • Proven ability to drive remediation efforts and follow through on risk reduction outcomes.
Bonus / Nice-to-have:

    • Experience with cloud-native architectures (AWS/GCP/Azure), microservices, Kubernetes, service-to-service authentication, and secrets management.
    • Experience tuning security tools to reduce noise and improve signal (e.g., improving rules, baselines, or pipelines).
    • Familiarity with secure SDLC practices and security champions programs.
    • Exposure to bug bounty / vulnerability disclosure or working with external researchers.
    • Experience improving internal security automation or developer workflows (including using AI-assisted tooling).
$140,000 – $165,000 a year
This is not including equity and other benefits. The actual salary offered will carefully consider a wide range of factors, including your skills, qualifications, and experience.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Apply info ->

To apply for this job, please visit jobs.lever.co

Shopping Cart
There are no products in the cart!
Total
 0.00
0