Назад
Company hidden
10 дней назад

Product Security Engineer (Fintech)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
UK/US/Netherlands +4 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (Fintech): Strengthening product and application security across finance automation products and the software development lifecycle with an accent on vulnerability analysis, threat modeling, and secure cloud-native environments. Focus on reviewing applications, APIs, microservices, containers, and code, automating security controls, and guiding engineering teams through practical remediation.

Location: Tel Aviv District, Israel. Hybrid work model: two days per week from home and three days per week from the North Tel Aviv offices.

Company

hirify.global is an AI-powered fintech platform that automates finance operations, including accounts payable, global payouts, procurement, expenses, corporate cards, supplier management, tax compliance, and treasury.

What you will do

  • Partner with development and product teams on application and product security throughout the software development lifecycle.
  • Perform hands-on security reviews of applications, APIs, services, and code, and assess vulnerabilities and security findings.
  • Conduct threat modeling and security analysis for new and existing product capabilities.
  • Provide remediation guidance and support secure coding practices across engineering teams.
  • Use and improve security controls and tooling, including SAST, SCA, DAST, API Security, and WAF.
  • Assess web applications, APIs, microservices, containers, Kubernetes, and cloud-native services, including vulnerability disclosure and Bug Bounty findings.

Requirements

  • 3+ years of hands-on experience in Application Security, Product Security, or a closely related software security role.
  • Ability to read and review application code written in .NET, JavaScript/TypeScript, or comparable modern technologies.
  • Hands-on experience identifying application and API vulnerabilities, performing threat modeling, and conducting application security reviews.
  • Strong knowledge of authentication, authorization, session management, web security, API security, mobile security, and OWASP Top 10.
  • Experience with SAST, SCA, DAST, API Security, WAF, microservices, containers, Kubernetes, cloud-native environments, AWS or Azure security, and CI/CD.
  • Strong analytical, problem-solving, communication, and collaboration skills.

Nice to have

  • Experience developing security tooling or automation and securing software supply chains.
  • Experience with fintech, payments, or security-sensitive SaaS products.
  • Experience with vulnerability research, Bug Bounty, vulnerability disclosure programs, or security research.
  • Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems.
  • Open-source security contributions or other demonstrated hands-on security work.

Culture & Benefits

  • Fast-paced, startup-style environment focused on innovation and critical thinking.
  • Collaborative work with a diverse, global team of engineers, developers, and product leaders.
  • Flexible hybrid workplace and competitive benefits.
  • Career coaching and opportunities to make an impact on a global finance automation product.
  • Tel Aviv office shuttle services, employee parking, and snacks and treats.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →