Engineering Manager - Security Engineering
AircallAbout the role
We are looking for a seasoned Engineering Manager to lead Aircall's Security Engineering organisation. This is a high-impact leadership role spanning four pillars: Product Security, Infrastructure Security, Detection & Response, and Governance, Risk & Compliance (GRC). You will grow an established team of security engineers, set the technical direction, and partner closely with Engineering, Product, Legal, IT and Finance to embed security deeply across the company. You’ll scale the team through high impact AI engineering across all 4 pillars.
You will be both a skilled people manager and a credible technical leader — someone who can roll up their sleeves when needed but who ultimately scales their impact through their team. You bring empathy, clear communication, and a bias for pragmatic security outcomes over security theatre.
Scope of Responsibility
- Own the Secure Software Development Lifecycle (SSDLC) from threat modelling through to production deployment.
Secure Agentic development practices by automating threat modeling, code reviews, internal pentesting and vulnerability remediation by building in-house security AI agents. - Partner with engineering to embed security reviews, static analysis (SAST), dependency scanning (SCA), and secrets detection into CI/CD pipelines.
- Lead the Aircall Bug Bounty and Vulnerability Disclosure Program (VDP), triaging and remediating reports with engineering teams.
- Drive regular penetration testing cycles for web, mobile, and API surfaces; oversee remediation tracking.
- Champion a developer-centric security culture through security champions, training, and tooling that makes the secure path the easy path.
- Define and maintain the security architecture of Aircall's cloud infrastructure (AWS), with a strong emphasis on zero-trust, least privilege, and defence in depth.
- Own, maintain and expand security observability through CSPM, CNAPP and CWPP tools like Wiz.
- Enable agentic auto-remediations for security vulnerabilities.
- Own network segmentation, secrets management, certificate lifecycle, identity & access management (IAM), and workload isolation, and secure hosting of internal AI applications
- Lead infrastructure hardening programs: CIS benchmarks, container security, Kubernetes policy enforcement (OPA), and immutable infrastructure practices.
- Manage the security posture of third-party SaaS tools and vendor risk assessments.
- Collaborate with Infrastructure engineering and Product Engineering on shared security responsibilities and runbooks.
- Build and mature Aircall's threat detection capability — SIEM tuning, alert triage playbooks, and investigation workflows.
Own incident response: develop and test the IR plan, lead tabletop exercises, and act as incident commander for significant security events. - Drive threat intelligence and threat hunting programs to stay ahead of adversaries targeting the cloud communications sector.
- Establish and track key security metrics: MTTD, MTTR, alert-to-incident conversion
Infrastructure Security
Detection & Response
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s