Назад
Company hidden
3 дня назад

Senior Product Security Engineer (Fintech)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Israel
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (Fintech): Strengthening application and product security across a finance automation platform with an accent on hands-on reviews, vulnerability analysis, threat modeling, and secure development practices. Focus on securing APIs, microservices, containers, Kubernetes, and cloud-native services while automating security controls across the software development lifecycle.

Location: Tel Aviv District, Israel. Hybrid work model: two days per week from home and three days per week from the North Tel Aviv office.

Company

hirify.global provides an AI-powered finance automation platform covering accounts payable, global payouts, procurement, expenses, cards, supplier management, tax compliance, and treasury.

What you will do

  • Partner with development and product teams on application and product security throughout the software development lifecycle.
  • Conduct hands-on security reviews of applications, APIs, services, and code, and investigate and validate vulnerabilities.
  • Perform threat modeling and security analysis for new and existing product capabilities.
  • Provide remediation guidance and support secure coding practices across engineering teams.
  • Use and improve security controls and tooling, including SAST, SCA, DAST, API Security, and WAF.
  • Assess web applications, APIs, microservices, containers, Kubernetes, and cloud-native services, including vulnerability disclosure and Bug Bounty findings.

Requirements

  • 5+ years of hands-on experience in Application Security, Product Security, or a related software security role.
  • Ability to read and review application code using .NET, JavaScript/TypeScript, or comparable modern technologies.
  • Experience identifying application and API vulnerabilities, performing threat modeling, and conducting application security reviews.
  • Strong knowledge of authentication, authorization, session management, web security, API security, mobile security, and OWASP Top 10 remediation.
  • Hands-on experience with SAST, SCA, DAST, API Security, WAF, CI/CD, microservices, containers, Kubernetes, and cloud-native environments.
  • Knowledge of AWS and/or Azure security, with strong analytical, problem-solving, communication, and collaboration skills.

Nice to have

  • Experience developing security tooling or automation and securing software supply chains.
  • Experience with fintech, payments, security-sensitive SaaS products, vulnerability research, Bug Bounty, or vulnerability disclosure programs.
  • Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems.
  • Security research, open-source contributions, or other demonstrated hands-on security work.

Culture & Benefits

  • Collaborative, fast-paced environment with a start-up vibe that encourages innovation and critical thinking.
  • Opportunity to work with a diverse, global team of engineers, developers, and product leaders.
  • Flexible workplace, competitive benefits, and career coaching.
  • Shuttle services from the nearest train station and across Tel Aviv.
  • Employee parking, snacks, and treats at the North Tel Aviv office.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →