Aircall · 4 hours ago
Security Engineer, Product Security
Aircall is seeking a Security Engineer focused on Product Security to enhance the security of their products. The role involves collaborating with engineering teams to identify risks, improve security practices, and ensure secure product development throughout the software lifecycle.
AnalyticsCall CenterCloud Data ServicesCRMEnterprise ApplicationsSaaSSoftwareTelecommunicationsVoIP
Responsibilities
Partner with engineering teams to review designs and implementation plans, identifying security risks early and recommending mitigations
Perform threat modeling for new features and major changes, helping teams document risks, assumptions, and security controls
Identify and help remediate common vulnerability classes across services and APIs (e.g., auth/authz, injection, data exposure, logic flaws)
Triage and support remediation of vulnerabilities identified through SAST/DAST tools, internal testing, or third-party findings
Conduct security testing and validation, including targeted manual testing for high-risk areas
Help improve secure development practices by creating reusable guidance, checklists, and secure patterns for engineering teams
Contribute to security tooling and automation that improves coverage, reduces false positives, and streamlines security reviews
Assist with product security incidents by supporting investigation, impact analysis, and follow-up remediation
Communicate security risks clearly and pragmatically, helping teams prioritize effectively and ship safely
Document learnings and contribute to evolving product security processes and standards
Qualification
Required
2–5 years of experience in Product Security, Application Security, or software engineering with a strong security focus
Strong understanding of web application and API security fundamentals and common vulnerability classes (OWASP Top 10)
Experience performing security reviews, threat modeling, or secure architecture assessments for software systems
Familiarity with security testing tools and practices (SAST/DAST, dependency scanning, fuzzing, manual testing)
Comfort reading and reviewing production code in at least one language (e.g., Python, Go, Java, JavaScript/TypeScript)
Exposure to automated or AI-assisted security tools or workflows, and interest in applying them to improve developer experience and security outcomes
Ability to work cross-functionally with engineering teams and communicate findings in a constructive, actionable way
Proven ability to drive remediation efforts and follow through on risk reduction outcomes
Preferred
Experience with cloud-native architectures (AWS/GCP/Azure), microservices, Kubernetes, service-to-service authentication, and secrets management
Experience tuning security tools to reduce noise and improve signal (e.g., improving rules, baselines, or pipelines)
Familiarity with secure SDLC practices and security champions programs
Exposure to bug bounty / vulnerability disclosure or working with external researchers
Experience improving internal security automation or developer workflows (including using AI-assisted tooling)
Benefits
This is not including equity and other benefits.
Company
Aircall
Aircall is a cloud-based call center software that integrates with CRM, productivity, and helpdesk tools.
H1B Sponsorship
Aircall has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (9)
2024 (3)
2023 (1)
2020 (4)
Funding
Current Stage
Late StageTotal Funding
$225.55MKey Investors
HubSpot VenturesGoldman Sachs Asset ManagementDTCP
2022-02-23Series Unknown
2021-06-23Series D· $120M
2020-05-27Series C· $65M
Leadership Team
Recent News
2025-12-05
2025-12-04
Company data provided by crunchbase