Дар бораи ҷойи кор
Ищут опытного специалиста по безопасности продуктов, который будет развивать secure-by-design подходы, повышать зрелость SDLC и управлять кросс-командными инициативами по защите продуктов Aircall.
Responsibilities
- Drive and scale secure-by-design practices across product and engineering teams, integrating security into design, development, CI/CD, and release workflows.
- Lead security design and architecture reviews for major product initiatives; define security requirements, controls, and patterns that teams can adopt consistently.
- Own and evolve threat modeling practices, ensuring risks are systematically identified early and mitigations are validated.
- Perform deep technical assessments, including manual code review, targeted security testing, and validation of fixes, for high-impact findings and critical services.
- Identify and reduce classes of vulnerabilities across Aircall’s codebases and services, including auth/authz flaws, injection, logic issues, SSRF, API security, and cloud misconfigurations.
- Build and improve security tooling and automation that scales across engineering, including guardrails, CI checks, policy-as-code, and AI-assisted autonomous security-review processes.
- Triage and drive remediation of vulnerabilities discovered through internal testing, automated detection, and external reports, including coordinated disclosure where applicable.
- Investigate and respond to product security incidents, helping with containment, root cause analysis, and prevention. Participate in on-call/threat-response rotations and coordinate during high-severity events.
- Stay up to date on attacker techniques, MITRE ATT&CK, red team reports, and threat intelligence; propose new detection patterns or responses.
- Serve as a trusted advisor to engineering and product leadership, translating security risks into pragmatic, prioritized actions and tradeoffs.
- Own cross-team product security initiatives, including secure SDLC improvements, secure design frameworks, security champions, and organization-wide security patterns and standards.
- Mentor and up-level engineers across security and product teams through reviews, pairing, coaching, and security education.
Requirements
- 8+ years of relevant experience in Product Security, Application Security, Secure Software Engineering, or equivalent.
- Proven track record of leading product security work across multiple teams and influencing architecture and SDLC maturity at scale.
- Strong foundation in secure design, threat modeling, vulnerability discovery, and remediation strategies.
- Proficiency with one or more programming languages: Python, Java, or JavaScript, and ability to read code to identify security defects.
Conditions
- Location: San Francisco, Seattle.
- Salary: $215,000 - $265,000 a year.
- Hybrid format.
Employer
Aircall