CronJobs

security jobs

Engineering Manager - Security Engineering

Aircallioinc · Seattle Office

onsitesenior$200,000–$200,000Posted Sep 10, 2026AWSKubernetesOPACSPMCNAPPCWPPWiz

Apply on the employer site

About this role

**Aircall — Engineering Manager, Security Engineering** Aircall is an AI-powered customer communications platform used by 22,000+ companies worldwide. We bring voice, SMS, WhatsApp, and AI into one seamless workspace—helping teams work smarter and scale with confidence. We’re looking for a seasoned **Engineering Manager** to lead Aircall’s **Security Engineering** organization. This is a high-impact leadership role spanning four pillars: **Product Security**, **Infrastructure Security**, **Detection & Response**, and **Governance, Risk & Compliance (GRC)**. You’ll grow an established team, set the technical direction, and partner closely with Engineering, Product, Legal, IT, and Finance to embed security deeply across the company. --- ## Scope of Responsibility ### Product Security - Own the **Secure Software Development Lifecycle (SSDLC)** from threat modeling through production deployment. - Enable secure, agentic development practices by automating threat modeling, code reviews, internal pentesting, and vulnerability remediation using in-house security AI agents. - Partner with engineering to embed security reviews, **SAST**, **dependency scanning (SCA)**, and **secrets detection** into **CI/CD**. - Lead Aircall’s **Bug Bounty** and **Vulnerability Disclosure Program (VDP)**. - Drive regular **penetration testing** cycles for web, mobile, and API surfaces; oversee remediation tracking. - Champion a developer-centric security culture via security champions, training, and tooling. ### Infrastructure Security - Define and maintain security architecture for **AWS**, emphasizing **zero-trust**, **least privilege**, and **defense in depth**. - Own and expand security observability using **CSPM/CNAPP/CWPP** tools (e.g., **Wiz**). - Enable agentic auto-remediations for security vulnerabilities. - Own network segmentation, secrets management, certificate lifecycle, **IAM**, workload isolation, and secure hosting of internal AI applications. - Lead infrastructure hardening (CIS benchmarks, container security, Kubernetes policy enforcement via **OPA**, immutable infrastructure). - Manage security posture of third-party SaaS tools and vendor risk assessments. - Collaborate with Infrastructure and Product Engineering on shared security responsibilities and runbooks. ### Detection & Response - Build and mature threat detection (SIEM tuning, alert triage playbooks, investigation workflows). - Own incident response: develop/test the IR plan, lead tabletop exercises, and act as incident commander for significant events. - Drive threat intelligence and threat hunting programs for the cloud communications sector. - Track key security metrics (e.g., **MTTD**, **MTTR**, alert-to-incident conversion, coverage gaps). - Ensure **24×7** detection coverage through tooling, automation, and on-call rotations (balancing reliability and wellbeing). ### Governance, Risk & Compliance (GRC / Information Security) - Own and continuously improve the information security management program aligned to **SOC 2 Type II** and applicable data protection regulations (**GDPR**, **CCPA**). - Lead audit preparation and evidence collection for external certifications and customer security questionnaires. - Maintain the corporate information security risk register and present findings/remediation plans to senior leadership and the board as required. - Define and enforce security policies, standards, and exception processes. - Act as the primary security liaison for enterp

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord