Engineering Manager - Security Engineering

Aircall

Bellevue (WA)

On-site

USD 200,000 - 260,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive salary & benefits
Growth opportunities
Diverse, multinational team

Job summary

Aircall is seeking a Security Engineering Leader to own the SSDLC, drive threat modelling, and lead security initiatives across cloud security, detection, and governance. You will mentor a multi-disciplinary team of engineers and collaborate with cross-functional partners to secure our SaaS platform.

Ideal candidates bring 7+ years in security engineering, 3+ years in tech lead roles, and hands-on AWS + IaC experience, with a proven track record in SOC 2 and ISO 27001 compliance.

Qualifications

  • 7+ years of professional experience in security engineering.
  • 3+ years in an engineering management or technical lead role with direct reports.
  • Experience building and scaling security teams in a cloud-native SaaS environment.
  • Deep fluency in at least two security pillars (Product Security, Infrastructure Security, D&R, or GRC).
  • Hands-on experience with major cloud platforms (AWS strongly preferred).
  • Experience owning or contributing to SOC 2 Type II, ISO 27001, or equivalent programmes.
  • Ability to communicate security risk clearly to non-technical executives and board members.
  • Experience running security incident response — from detection through containment, eradication, and post-mortem.

Responsibilities

  • Own the Secure Software Development Lifecycle (SSDLC) from threat modelling through to production deployment and automation of security reviews.
  • Embed security reviews, static analysis (SAST), dependency scanning (SCA), and secrets detection into CI/CD pipelines.
  • Lead the Bug Bounty and Vulnerability Disclosure Program; triage and remediate reports with engineering teams.
  • Drive regular penetration testing cycles for web, mobile, and API surfaces; oversee remediation tracking.
  • Champion a developer-centric security culture with security champions, training, and tooling.
  • Define and maintain the security architecture of Aircall's cloud infrastructure (AWS).
  • Own security observability through CSPM, CNAPP and CWPP tools.
  • Enable agentic auto-remediations for security vulnerabilities.
  • Lead infrastructure hardening programs: CIS benchmarks, container security, Kubernetes policy enforcement (OPA).
  • Collaborate on shared security responsibilities and runbooks with other teams.
  • Build and mature Aircall's threat detection capability; incident response planning and drills.
  • Establish security metrics (MTTD, MTTR, alert-to-incident rates).
  • Ensure 24×7 detection coverage through tooling and on-call rotations.
  • Own and improve information security governance aligned to SOC 2 Type II and data protection regulations.

Skills

Security engineering
Engineering management
Cloud platforms (AWS)
Security incident response
Executive communication

Tools

Terraform
CDK

Job description

Aircall is a unicorn, AI-powered customer communications platform used by 22,000+ companies worldwide to drive revenue, resolve issues faster, and scale customer-facing teams. We’re redefining customer communications by bringing voice, SMS, WhatsApp, and AI together into one seamless workspace.

Our momentum comes from a simple idea: help teams work smarter, not harder. Aircall’s AI Voice Agent automates routine calls, AI Assist streamlines post-call work, and AI Assist Pro delivers real-time guidance so people can do their best work. The result is higher revenue, faster resolutions, and teams that scale with confidence.

Aircall is headquartered in Paris, our European HQ, with a strong North American presence anchored in Seattle, our North American HQ, and teams across Madrid, London, Berlin, San Francisco, New York City, Sydney, and Mexico City. We’ve built a product customers love and a business that’s scaling quickly, backed by world-class investors and driven by rapid AI innovation across multiple product lines.

At Aircall, you’ll join a company in motion. We’re ambitious, product-driven, and execution-focused, with visible impact, fast decisions, and real growth.

How we work at Aircall

We’re customer-obsessed, data-driven, and focused on delivering meaningful outcomes. We value ownership, continuous learning, and thoughtful speed. If you thrive in a collaborative, fast-moving environment where trust and impact matter, you’ll feel at home here.

Scope Of Responsibility
Product Security
  • Own the Secure Software Development Lifecycle (SSDLC) from threat modelling through to production deployment. Secure Agentic development practices by automating threat modeling, code reviews, internal pentesting and vulnerability remediation by building in-house security AI agents.
  • Partner with engineering to embed security reviews, static analysis (SAST), dependency scanning (SCA), and secrets detection into CI/CD pipelines.
  • Lead the Aircall Bug Bounty and Vulnerability Disclosure Program (VDP), triaging and remediating reports with engineering teams.
  • Drive regular penetration testing cycles for web, mobile, and API surfaces; oversee remediation tracking.
  • Champion a developer-centric security culture through security champions, training, and tooling that makes the secure path the easy path.
Infrastructure Security
  • Define and maintain the security architecture of Aircall's cloud infrastructure (AWS), with a strong emphasis on zero-trust, least privilege, and defence in depth.
  • Own, maintain and expand security observability through CSPM, CNAPP and CWPP tools like Wiz.
  • Enable agentic auto-remediations for security vulnerabilities.
  • Own network segmentation, secrets management, certificate lifecycle, identity & access management (IAM), and workload isolation, and secure hosting of internal AI applications
  • Lead infrastructure hardening programs: CIS benchmarks, container security, Kubernetes policy enforcement (OPA), and immutable infrastructure practices.
  • Manage the security posture of third-party SaaS tools and vendor risk assessments.
  • Collaborate with Infrastructure engineering and Product Engineering on shared security responsibilities and runbooks.
Detection & Response
  • Build and mature Aircall's threat detection capability — SIEM tuning, alert triage playbooks, and investigation workflows. Own incident response: develop and test the IR plan, lead tabletop exercises, and act as incident commander for significant security events.
  • Drive threat intelligence and threat hunting programs to stay ahead of adversaries targeting the cloud communications sector.
  • Establish and track key security metrics: MTTD, MTTR, alert-to-incident conversion rates, and coverage gaps.
  • Ensure 24×7 detection coverage through tooling, automation, and on-call rotations, balancing reliability and engineer wellbeing.
Governance, Risk & Compliance (GRC / Information Security)
  • Own and continuously improve Aircall's information security management program, aligned to SOC 2 Type II, and applicable data-protection regulations (GDPR, CCPA).
  • Lead audit preparation and evidence collection for external certifications and customer security questionnaires.
  • Maintain the corporate risk register for information security, presenting findings and remediation plans to senior leadership and the board as required.
  • Define and enforce security policies, standards, and exception processes across the organisation.
  • Act as the primary security liaison for enterprise customers, prospects, and partners conducting security due diligence.
People Leadership
  • Lead, mentor, and grow a multi-disciplinary security team of 6–10 engineers across the four pillars.
  • Run structured 1:1s, career-development conversations, and quarterly goal-setting aligned to company OKRs.
  • Hire and onboard exceptional security talent; contribute to employer-branding initiatives in the security community.
  • Create an environment where engineers feel psychologically safe to raise concerns, experiment, and learn from failures.
  • Balance hands-on technical involvement with delegation — staying close enough to the work to be credible, but trusting the team to execute.
  • Partner cross-functionally with Engineering leadership, Legal, People Ops, and Finance to align security initiatives with business priorities.
What We're Looking For
  • 7+ years of professional experience in security engineering.
  • 3+ years in an engineering management or technical lead role with direct reports.
  • Proven track record of building and scaling security teams in a cloud-native, SaaS environment.
  • Deep technical fluency across at least two of the four pillars (Product Security, Infrastructure Security, D&R, GRC).
  • Hands-on experience with major cloud platforms (AWS strongly preferred, GCP or Azure a plus) and infrastructure-as-code (Terraform, CDK, or equivalent).
  • Experience owning or contributing to SOC 2 Type II, ISO 27001, or equivalent compliance programmes.
  • Demonstrated ability to communicate security risk clearly to non-technical executives and board members.
  • Experience running security incident response — from detection through containment, eradication, and post-mortem.
Preferred / Nice To Have
  • Background in a high-growth B2B SaaS or cloud-communications company.
  • Familiarity with VoIP, real-time communications, or telephony security considerations.
  • Experience embedding Agentic AI practices into security engineering workflows and securing internal AI tooling and implementation.
  • Relevant certifications: CISSP, CISM, AWS Security Specialty, GIAC (GWAPT, GCIA, GCIH), or equivalent.
  • Experience running a Bug Bounty programme (HackerOne, Bugcrowd, or similar).
  • Contributions to the open-source security community, conference speaking, or published research.
  • Familiarity with DORA metrics and the relationship between deployment frequency and security posture.

Base salary range:: $200,000 USD - $260,000 USD

Why join us
  • Key moment to join Aircall in terms of growth and opportunities
  • Our people matter, work-life balance is important at Aircall
  • Fast-learning environment, entrepreneurial and strong team spirit
  • 45+ Nationalities: cosmopolite & multi-cultural mindset
  • Competitive salary package & benefits
DE&I Statement

At Aircall, we believe diversity, equity and inclusion – irrespective of origins, identity, background and orientations – are core to our journey.

We pride ourselves on promoting active inclusion within our business to foster a strong sense of belonging for all. We’re working to create a place filled with diverse people who can enrich and learn from one another. We’re committed to ensuring that everyone not only has a seat at the table but is valued and respected at it by providing equal opportunities to develop and thrive.

We will constantly challenge ourselves to make sure that we live up to our ambitions around diversity, equity and inclusion, and keep this conversation open. Above all else, we understand and acknowledge that we have work to do and much to learn.

Want to know more about candidate privacy? Find our Candidate Privacy Notice here.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Engineering Manager - Security Engineering
Engineering Manager - Security Engineering

Aircall • New York (NY)

On-site
USD 200,000 - 260,000
Engineering Manager - Security Engineering
Engineering Manager - Security Engineering

Aircall • Seattle (WA)

On-site
USD 200,000 - 260,000
Medical, dental, and vision insurance 100% covered
401k plan with company matching
Unlimited PTO
+2
Senior Security Engineer, Detection & Response
Senior Security Engineer, Detection & Response

Aircall • Seattle (WA)

On-site
USD 180,000 - 220,000
Competitive salary package
Senior GRC Engineer
Senior GRC Engineer

Aircall • New York (NY)

On-site
USD 180,000 - 200,000
Competitive salary package & equity
Medical, dental, and vision insurance 100% covered
Unlimited PTO
+2
Senior Security Engineer, Detection & Response
Senior Security Engineer, Detection & Response

Aircall • San Francisco (CA)

On-site
USD 180,000 - 220,000
Competitive salary & benefits
Principal Software Engineer, Programmable Comms
Principal Software Engineer, Programmable Comms

Aircall.io, Inc. • United States

On-site
USD 180,000 - 240,000
Competitive salary package
Diversity, equity and inclusion
Forward Deployed Engineer - AI Solutions Engineering
Forward Deployed Engineer - AI Solutions Engineering

Aircall • San Francisco (CA)

On-site
USD 90,000 - 136,000
Medical, dental, and vision insurance
401k plan with company matching
Unlimited PTO
Network Engineer
Network Engineer

Aircall • United States

On-site
USD 95,000 - 110,000
Manager, Customer Engineering
Manager, Customer Engineering

Aircall.io, Inc. • New York (NY), San Francisco (CA)

On-site
USD 134,000 - 185,000
Forward Deployed Engineering Lead
Forward Deployed Engineering Lead

Aircall • San Francisco (CA)

On-site
USD 185,000 - 256,000