Назад
Company hidden
11 дней назад

Product Security Team Leader

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Israel
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Team Leader (Application Security): Leading a product security team and developing security practices for web, mobile, API, microservices, Kubernetes, and cloud-native products with an accent on SSDLC, threat modeling, vulnerability management, and secure architecture. Focus on assessing exploitability and business impact, automating security tooling and attack-surface monitoring, and guiding engineering teams through complex product-security risks.

Location: Herzliya, Israel

Company

hirify.global develops mobile games used by millions of players worldwide and combines the scale of a public company with the speed of a startup.

What you will do

  • Lead and develop a product security team, setting priorities, standards, measurable goals, and the team roadmap.
  • Partner with R&D, architecture, security champions, and business stakeholders on secure product development.
  • Drive SSDLC practices including threat modeling, secure design and architecture reviews, code reviews, penetration testing, and vulnerability remediation.
  • Assess and advise on the security of web, mobile, API, microservices, Kubernetes, container, and cloud-native products.
  • Oversee vulnerability management, SAST/DAST, WAF and runtime protection, bug-bounty programs, external research, and security-finding triage.
  • Develop security tooling, automation, attack-surface monitoring, training, and enablement programs, and coordinate with incident response teams during product-security incidents.

Requirements

  • 5+ years of hands-on experience in application security, product security, or a related security engineering discipline.
  • Strong expertise in web application, API, mobile application, and service-to-service security.
  • Knowledge of authentication and authorization flaws, injection, SSRF, business-logic abuse, secrets exposure, supply-chain risks, and cloud misconfigurations.
  • Strong understanding of Kubernetes, containers, microservices, cloud environments, and CI/CD pipelines.
  • Strong communication, stakeholder-management, analytical, problem-solving, ownership, and people-leadership skills.

Nice to have

  • Experience leading or managing an application or product security team or function.
  • Experience with SSDLC, threat modeling, secure design reviews, security architecture, vulnerability remediation, and risk prioritization.
  • Experience with penetration testing, vulnerability management, SAST, DAST, software composition analysis, and API security testing.
  • Experience with external attack-surface management, runtime application protection, WAF, API gateways, service-mesh security, or cloud security.

Culture & Benefits

  • Work in a global mobile-gaming company with an innovation, data, and creativity-focused environment.
  • Collaborate across global studios and product, engineering, architecture, and security functions.
  • Support technical compliance efforts related to GDPR, CCPA, and other applicable requirements.
  • Equal-opportunity workplace that values diversity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →