Security Engineer - Product Security
Security Engineer - Product Security

Security Engineer - Product Security

Full-Time 36000 - 60000 £ / year (est.) No home office possible
Hard Yaka

At a Glance

  • Tasks: Help build secure products by collaborating with engineering teams and improving security practices.
  • Company: Join Aircall, a fast-growing AI-powered customer communications platform.
  • Benefits: Enjoy competitive salary, work-life balance, and a multicultural environment.
  • Other info: Be part of a diverse team with excellent growth opportunities.
  • Why this job: Make a real impact in product security while leveraging cutting-edge AI technologies.
  • Qualifications: 2-5 years in Product Security or software engineering with a strong security focus.

The predicted salary is between 36000 - 60000 £ per year.

Aircall is a unicorn, AI-powered customer communications platform used by 22,000+ companies worldwide to drive revenue, resolve issues faster, and scale customer-facing teams. We’re redefining customer communications by bringing voice, SMS, WhatsApp, and AI together into one seamless workspace.

As a Security Engineer, Product Security, you will help Aircall build and ship secure products by working closely with engineering teams and product managers to identify risk early, reduce vulnerabilities, and improve security quality across the software development lifecycle. You’ll support secure-by-design practices and help ensure security is integrated into how teams design, build, test, and release software. In this role, you’ll be hands-on across threat modelling, vulnerability detection and remediation, and security testing.

Key Responsibilities:

  • Partner with engineering teams to review designs and implementation plans, identifying security risks early and recommending mitigations.
  • Perform threat modelling for new features and major changes, helping teams document risks, assumptions, and security controls.
  • Identify and help remediate common vulnerability classes across services and APIs (e.g., auth/authz, injection, data exposure, logic flaws).
  • Triage and support remediation of vulnerabilities identified through SAST/DAST tools, internal testing, or third-party findings.
  • Conduct security testing and validation, including targeted manual testing for high-risk areas.
  • Help improve secure development practices by creating reusable guidance, checklists, and secure patterns for engineering teams.
  • Contribute to security tooling and automation that improves coverage, reduces false positives, and streamlines security reviews.
  • Assist with product security incidents by supporting investigation, impact analysis, and follow-up remediation.
  • Communicate security risks clearly and pragmatically, helping teams prioritize effectively and ship safely.
  • Document learnings and contribute to evolving product security processes and standards.

Requirements:

  • 2–5 years of experience in Product Security, Application Security, or software engineering with a strong security focus.
  • Strong understanding of web application and API security fundamentals and common vulnerability classes (OWASP Top 10).
  • Experience performing security reviews, threat modelling, or secure architecture assessments for software systems.
  • Familiarity with security testing tools and practices (SAST/DAST, dependency scanning, fuzzing, manual testing).
  • Comfort reading and reviewing production code in at least one language (e.g., Python, Go, Java, JavaScript/TypeScript).
  • Exposure to automated or AI-assisted security tools or workflows, and interest in applying them to improve developer experience and security outcomes.
  • Ability to work cross-functionally with engineering teams and communicate findings in a constructive, actionable way.
  • Proven ability to drive remediation efforts and follow through on risk reduction outcomes.

Nice-to-have:

  • Experience with cloud-native architectures (AWS/GCP/Azure), microservices, Kubernetes, service-to-service authentication, and secrets management.
  • Experience tuning security tools to reduce noise and improve signal (e.g., improving rules, baselines, or pipelines).
  • Familiarity with secure SDLC practices and security champions programs.
  • Exposure to bug bounty/vulnerability disclosure or working with external researchers.
  • Experience improving internal security automation or developer workflows (including using AI-assisted tooling).

Why join us?

  • Key moment to join Aircall in terms of growth and opportunities.
  • Our people matter, work-life balance is important at Aircall.
  • Fast-learning environment, entrepreneurial and strong team spirit.
  • 45+ Nationalities: cosmopolite & multi-cultural mindset.
  • Competitive salary package & benefits.

DE&I Statement: At Aircall, we believe diversity, equity and inclusion – irrespective of origins, identity, background and orientations – are core to our journey. We pride ourselves on promoting active inclusion within our business to foster a strong sense of belonging for all. We’re committed to ensuring that everyone not only has a seat at the table but is valued and respected at it by providing equal opportunities to develop and thrive. We are strongly committed to hiring a diverse and multicultural team and we encourage applications from traditionally underrepresented backgrounds.

Security Engineer - Product Security employer: Hard Yaka

Aircall is an exceptional employer that prioritises work-life balance and fosters a collaborative, fast-paced environment where innovation thrives. With a commitment to employee growth and a diverse, multicultural team, Aircall offers competitive salaries and benefits, making it an ideal place for those looking to make a meaningful impact in the field of product security. Join us in Paris, where you'll be part of a dynamic company at the forefront of AI-driven customer communications.
Hard Yaka

Contact Detail:

Hard Yaka Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Security Engineer - Product Security

✨Tip Number 1

Network like a pro! Reach out to current employees at Aircall on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for your application process. Personal connections can give you an edge!

✨Tip Number 2

Prepare for the interview by brushing up on your technical skills and understanding of security principles. Be ready to discuss real-world scenarios where you've identified and mitigated security risks. Show us how you think!

✨Tip Number 3

Don’t just focus on your technical skills; highlight your soft skills too! Communication is key in this role, so be prepared to demonstrate how you can effectively collaborate with engineering teams and convey complex security concepts.

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows your enthusiasm for joining Aircall and being part of our innovative team.

We think you need these skills to ace Security Engineer - Product Security

Product Security
Application Security
Web Application Security
API Security
Threat Modelling
Vulnerability Detection
Security Testing
SAST/DAST Tools
Manual Testing
Secure Development Practices
Cloud-native Architectures
Microservices
Kubernetes
Communication Skills
Cross-functional Collaboration

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Security Engineer role. Highlight relevant experience in product security and application security, and don’t forget to mention any hands-on work with threat modelling or vulnerability detection.

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about security and how your skills align with our mission at Aircall. Be sure to mention any experience with AI tools, as we love innovation!

Showcase Your Problem-Solving Skills: In your application, give examples of how you've tackled security challenges in the past. We want to see your thought process and how you approach risk management—this is key for us at Aircall!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our team!

How to prepare for a job interview at Hard Yaka

✨Know Your Stuff

Make sure you brush up on your knowledge of web application and API security fundamentals, especially the OWASP Top 10. Be ready to discuss how you've applied this knowledge in past roles, as it shows you're not just familiar with the concepts but can also implement them effectively.

✨Showcase Your Experience

Prepare specific examples from your previous work where you've performed security reviews or threat modelling. Highlight any hands-on experience with security testing tools like SAST/DAST, and be ready to explain how you’ve used them to identify and remediate vulnerabilities.

✨Communicate Clearly

Aircall values clear communication, so practice articulating complex security concepts in a straightforward manner. Think about how you would explain security risks and mitigation strategies to non-technical team members, as this will demonstrate your ability to work cross-functionally.

✨Embrace AI and Automation

Since Aircall is keen on leveraging AI for security, be prepared to discuss any experience you have with automated security tools or workflows. Share your thoughts on how AI can enhance security practices and improve developer experience, showing that you’re aligned with their innovative approach.

Security Engineer - Product Security
Hard Yaka

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>