SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Mistral is a leading AI company providing full-stack solutions from frontier models to developer tools and applications. As a Product Security Engineer within the Cybersecurity organization, you will be the dedicated security partner for one or more product organizations (such as Vibe, Studio, or Forge), working alongside engineers, researchers, and product managers to embed security throughout the entire product lifecycle.
Your mission is to enable engineering teams to build secure products without slowing velocity. Rather than acting as a gatekeeper, you will provide secure-by-design principles, pragmatic engineering guidance, and scalable security automation. You will own the Product Security strategy for your assigned product portfolio, influence architectural and engineering decisions, and help define secure software practices across a world-leading AI company.
Key responsibilities include: serving as the dedicated Product Security partner for product organizations; driving security from design and architecture reviews through production deployment and ongoing operations; leading threat modeling, security architecture reviews, and risk assessments for new features and major changes; defining pragmatic security requirements and secure-by-default patterns; reviewing critical designs and code focusing on authentication, authorization, tenant isolation, data protection, and cryptography; designing product-specific security validation strategies including targeted testing and agent-based assessments; partnering with engineering to prioritize and remediate vulnerabilities; collaborating with Security Engineering on reusable platforms and developer guardrails; championing secure software engineering through coaching and Security Champion programs; and defining Product Security metrics to continuously improve posture.
Required qualifications: 5+ years in Product Security, Application Security, or Software Engineering with strong security focus; deep understanding of modern software architecture, distributed systems, APIs, and cloud-native applications; demonstrated experience with threat modeling and secure design assessments; expertise in authentication, authorization, cryptography, secrets management, tenant isolation, and common vulnerability classes (OWASP Top 10, CWE); strong software engineering skills in Python, Go, TypeScript or similar languages with ability to review production code and build security automation; experience with application security testing (manual code review, penetration testing, bug bounty); experience designing product-specific security testing approaches; understanding of Secure SDLC principles; excellent communication and influencing skills; and pragmatic, engineering-first mindset with strong technical judgment.