11 дней назад
Product Security Team Leader
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Product Security Team Leader (Application Security): Leading a product security team and developing security practices for web, mobile, API, microservices, Kubernetes, and cloud-native products with an accent on SSDLC, threat modeling, vulnerability management, and secure architecture. Focus on assessing exploitability and business impact, automating security tooling and attack-surface monitoring, and guiding engineering teams through complex product-security risks.
Location: Herzliya, Israel
Company
develops mobile games used by millions of players worldwide and combines the scale of a public company with the speed of a startup.
What you will do
- Lead and develop a product security team, setting priorities, standards, measurable goals, and the team roadmap.
- Partner with R&D, architecture, security champions, and business stakeholders on secure product development.
- Drive SSDLC practices including threat modeling, secure design and architecture reviews, code reviews, penetration testing, and vulnerability remediation.
- Assess and advise on the security of web, mobile, API, microservices, Kubernetes, container, and cloud-native products.
- Oversee vulnerability management, SAST/DAST, WAF and runtime protection, bug-bounty programs, external research, and security-finding triage.
- Develop security tooling, automation, attack-surface monitoring, training, and enablement programs, and coordinate with incident response teams during product-security incidents.
Requirements
- 5+ years of hands-on experience in application security, product security, or a related security engineering discipline.
- Strong expertise in web application, API, mobile application, and service-to-service security.
- Knowledge of authentication and authorization flaws, injection, SSRF, business-logic abuse, secrets exposure, supply-chain risks, and cloud misconfigurations.
- Strong understanding of Kubernetes, containers, microservices, cloud environments, and CI/CD pipelines.
- Strong communication, stakeholder-management, analytical, problem-solving, ownership, and people-leadership skills.
Nice to have
- Experience leading or managing an application or product security team or function.
- Experience with SSDLC, threat modeling, secure design reviews, security architecture, vulnerability remediation, and risk prioritization.
- Experience with penetration testing, vulnerability management, SAST, DAST, software composition analysis, and API security testing.
- Experience with external attack-surface management, runtime application protection, WAF, API gateways, service-mesh security, or cloud security.
Culture & Benefits
- Work in a global mobile-gaming company with an innovation, data, and creativity-focused environment.
- Collaborate across global studios and product, engineering, architecture, and security functions.
- Support technical compliance efforts related to GDPR, CCPA, and other applicable requirements.
- Equal-opportunity workplace that values diversity.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →