Senior Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (Cybersecurity): Embedding security into the software development lifecycle (SDLC) to proactively identify risks and ensure secure product deployment with an accent on secure design and threat modeling. Focus on integrating security tools into CI/CD pipelines, automating vulnerability workflows, and leveraging AI/ML for enhanced detection.
Location: Hybrid (Tel Aviv, Israel) — Must be based in Israel and work from the office at least two days per week
Company
provides a cloud-native Zero Trust platform to help global businesses and governments prevent the theft of sensitive data and intellectual property.
What you will do
- Lead threat modeling and secure design (SxD) activities to shift security left in the SDLC.
- Conduct manual and tool-assisted code reviews, SAST, DAST, and penetration testing.
- Integrate and automate security scanning, reporting, and ticketing within CI/CD pipelines.
- Assess exploitability and impact of vulnerabilities to prioritize remediation efforts.
- Provide technical mentorship to engineers and deliver security awareness training.
- Collaborate with R&D, product managers, and leadership to communicate risks and influence engineering decisions.
Requirements
- Bachelor’s degree in Computer Science, Security, or equivalent professional experience.
- 5+ years of experience in application security or security-focused software engineering.
- Deep knowledge of OWASP Top 10, secure coding practices, APIs, and microservices.
- Strong coding skills in C++ and Java to effectively read and review code.
- Hands-on experience with ASPM, SAST, DAST, and SCA tools.
- Must have the legal right to work in Israel.
Nice to have
- Professional certifications such as CISSP, CSSLP, or OSCP.
- Experience with Windows internals and cloud-native stacks.
- Proven track record of applying AI/automation to security workflows.
- Familiarity with compliance frameworks like SOC2 or ISO27001.
Culture & Benefits
- Inclusive and diverse workplace culture.
- Mission-driven environment focused on creating a safer digital world.
- Hybrid work flexibility combining remote work and office collaboration.
- Equal opportunity employer commitment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →