> Markdown version of [/jobs/ext/1416362-cybersecurity-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/1416362-cybersecurity-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CyberSecurity, Product Security Engineer - **Company:** Mistral AI - **Location:** Paris, France - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Code Review, Cyber Security, Data Security, Software Design Patterns, Distributed Systems, Python (Programming Language), Key Management, Open Web Application Security, Software Architecture, Systems Development Life Cycle, Software Deployment, Software Engineering, TypeScript, Spring Cloud, Software Security, Production Code, Security Orchestration, Automation & Response, Golang - **Published:** July 24, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=e9a26882c624a3a2 ## About the Role * 5+ years of experience in Product Security, Application Security or Software Engineering with a strong security focus. * Strong understanding of modern software architecture, distributed systems, APIs and cloud-native applications. * Demonstrated experience performing threat modeling, architecture reviews and secure design assessments. * Deep understanding of modern software security, including authentication, authorization, cryptography, secrets management, tenant isolation, secure data flows and common vulnerability classes (OWASP Top 10, CWE). * Strong software engineering skills in Python, Go, TypeScript or similar languages, with the ability to review production code and build security automation. * Experience with application security testing techniques, including manual code review, penetration testing, bug bounty programs. * Experience designing product-specific security testing approaches, including security automation or agent-based testing, is highly valued. * Strong understanding of Secure SDLC principles from product design through production deployment and long-term maintenance. * Excellent communication and influencing skills, with the ability to earn trust across engineering organizations and balance security, product delivery and developer experience. * A pragmatic, engineering-first mindset with strong technical judgment and a focus on solving meaningful security problems. ## Description As a Product Security Engineer within the Cybersecurity organization, you will be the dedicated security partner for one or more product organizations (such as Vibe, Studio or Forge). You will work alongside engineers, researchers and product managers to ensure security is built into every stage of the product lifecycle-from early design and architecture decisions through implementation, production deployment and continuous evolution. Your mission is to help engineering teams build secure products without slowing them down. Rather than acting as a gatekeeper, you will enable teams to make sound security decisions through secure-by-design principles, pragmatic engineering guidance and scalable security automation. You will own the Product Security strategy for your product portfolio, influence engineering decisions, and help define how secure software is built across one of the world's leading AI companies. What you will do * Serve as the dedicated Product Security partner for one or more product organizations. * Drive security throughout the entire product lifecycle, from design and architecture reviews to production deployment and ongoing operation. * Lead threat modeling, security architecture reviews and risk assessments for new features, APIs and major architectural changes. * Define pragmatic security requirements and secure-by-default patterns that enable engineering teams to ship safely at high velocity for a specific product. * Review critical designs and code, focusing on authentication, authorization, tenant isolation, data protection, cryptography and other high-impact security controls. * Design product-specific security validation strategies, including targeted testing, abuse-case development and guided agent-based security assessments tailored to each product's architecture and workflows. * Partner with engineering teams to prioritize and remediate vulnerabilities identified through code reviews, penetration testing, bug bounty programs and automated security testing. * Collaborate with Security Engineering to improve reusable security platforms, developer guardrails and security capabilities integrated into the SDLC. * Champion secure software engineering through coaching, technical leadership, reusable design patterns and Security Champion programs. * Define Product Security metrics, continuously improve the security posture of your products and help shape Product Security practices across the company. ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)