Job Description
About the Role
As a Product Security Engineer at Mistral AI, you will be the dedicated security partner for one or more product organizations, embedding application security expertise across the product lifecycle. You will collaborate with engineers, researchers, and product managers to ensure secure-by-design principles guide development from architecture through production, enabling teams to ship safely without sacrificing velocity.
Responsibilities
- Serve as the primary Product Security partner for assigned product organizations, owning security strategy and execution.
- Drive threat modeling, security architecture reviews, and risk assessments for new features, APIs, and major architectural changes.
- Conduct code reviews and architecture assessments focused on authentication, authorization, tenant isolation, data protection, and cryptographic controls.
- Define pragmatic security requirements and secure-by-default patterns that balance engineering velocity with risk management.
- Design and implement product-specific security validation strategies, including targeted testing, abuse-case analysis, and agent-based security assessments.
- Partner with engineering teams to prioritize and remediate vulnerabilities identified through code review, penetration testing, bug bounty programs, and automated security testing.
- Collaborate with Security Engineering to enhance reusable security platforms, developer guardrails, and SDLC-integrated security capabilities.
- Coach engineering teams on secure software practices, establish Security Champion programs, and develop reusable design patterns.
- Define Product Security metrics, continuously improve product security posture, and shape AppSec practices company-wide.
Requirements
- 5+ years of experience in Product Security, Application Security, or Software Engineering with demonstrated security focus.
- Strong knowledge of modern software architecture, distributed systems, APIs, and cloud-native applications.
- Hands-on experience with threat modeling, architecture reviews, and secure design assessments.
- Deep expertise in software security fundamentals: authentication, authorization, cryptography, secrets management, tenant isolation, secure data flows, OWASP Top 10, and CWE.
- Proficiency in code review across Python, Go, TypeScript, or similar languages; ability to build security automation.
- Demonstrated experience with application security testing: manual code review, penetration testing, and bug bounty program management.
- Experience designing security testing approaches, including security automation or agent-based testing, is highly valued.
- Strong understanding of Secure SDLC principles from design through production deployment and maintenance.
- Excellent communication and influence skills; ability to earn trust across engineering teams and balance security with product delivery.
- Pragmatic, engineering-first approach with strong technical judgment and focus on solving meaningful security problems.
Benefits
Mistral AI offers a comprehensive benefits package including healthcare coverage, parental leave, retirement plans, relocation support, wellness programs, meal and transportation allowances, and location-specific perks. Benefits vary by country; refer to the company's Benefits page for details specific to Paris.
Mistral AI on Oh My Job
8 open positions right now, including 1 in Texas.