דרושים » אבטחת מידע וסייבר » Cyber Risk and Privacy Protection Manager

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
Location: Merkaz
Job Type: Full Time
we are looking for a Cyber Risk and Privacy Protection Manager The role includes overall responsibility for managing information security risks, privacy protection, and supply chain risks, working with multiple internal and external stakeholders, and supporting technological processes and projects. Key Responsibilities
* Manage information security, privacy, and supply chain risk frameworks
* Conduct risk assessments for systems, processes, and suppliers
* Lead supplier and supply chain risk reviews and remediation tracking
* Implement privacy and information security policies and procedures
* Support technology projects from security and privacy perspectives
* Monitor risk mitigation plans and report to management
* Coordinate cross-functional and external stakeholders
Requirements:
* Formal Education
* At least 3 years of experience in information security and cyber
* Experience in managing cyber risks, privacy protection risks, operational, technological, and regulatory risks
* Knowledge of regulations and standards: Israeli Privacy Protection Regulations, ISO 27001
* Experience in developing and implementing policies and procedures Advantages
* Graduate of a data Protection Officer (DPO) course
* Experience in writing and implementing organizational procedures
* Experience in supply chain risk management and working with suppliers Personal Skills and Competencies
* Excellent interpersonal skills and ability to work in a team
* Strong management, organization, and matrix task leadership abilities
* Analytical, planning, and initiative-taking skills
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8537058
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
27/01/2026
Location: Haifa
Job Type: Full Time
abra North is seeking an experienced and highly skilled Information Security Consultant (GRC) and Privacy Specialist with proven expertise in governance, risk management, compliance, and data protection.?? Central region |?? Full-time |?? Hybrid Work Model Key Responsibilities Lead certification and compliance programs for international standards such as ISO 27001, ISO 27799, and ISO 27017
* Provide guidance on privacy and regulatory requirements, including GDPR and the Israeli Protection of Privacy Law (with emphasis on Amendment 13).
* Deliver CISO?as?a?Service, including building and managing security programs, driving risk management activities, and presenting status and recommendations to executive leadership and boards.
* Conduct Cyber/IT Risk Assessments, perform Gap Analyses, and develop actionable remediation plans.
* Develop methodological frameworks, including security policies, procedures, and annual work plans aligned with industry best practices.
* Provide high?level advisory support to align technical security solutions (EDR, DLP, Cloud Security, IAM, etc.) with regulatory and organizational requirements.
* Deliver cybersecurity and privacy awareness training for employees and management.
Requirements:
Must have
* Academic degree in a relevant field, or completion of a recognized cybersecurity/information security program (200+ hours).
* 2+ years of experience in methodological consulting or in managing information security within organizations.
* Strong knowledge of ISO 27001 and familiarity with sector?specific regulations (e.g., financial, healthcare).
* Proven experience in privacy compliance and understanding of the DPO role.
* Excellent writing skills in Hebrew and English, with the ability to produce professional policies and procedures.
* Solid understanding of IT environments and enterprise security technologies (EDR, DLP, IAM, Cloud Security). Nice to have:
* Relevant certifications such as CISM, CISA, CIPP/E, CRISC
* Experience working with regulators (e.g., the Israeli Privacy Protection Authority, Israel National Cyber Directorate).
* Consulting experience in the financial or healthcare sectors, including standards such as HIPAA or HITRUST
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8308799
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Petah Tikva
Job Type: Full Time
Were looking for an experienced GRC Manager to join our team in Israel. Were seeking someone with solid, hands-on experience who can take ownership and lead both technically and operationally.
You will lead the certification and accreditation processes , managing all current compliance frameworks and certifications. This includes both preparation activities and direct engagement with external auditors, from readiness and gap analysis through to achieving final reports or certificates.
Roles and Responsibilities:
Lead internal and external audit and certification cycles, ensuring readiness and successful completion of assessments.
Maintain and continuously improve internal control framework, ensuring that security and compliance controls are effective, documented, and aligned across ISO 27001, SOC 2, and privacy requirements.
Develop, maintain, and enhance security and compliance documentation, including policies, procedures, and evidence repositories.
Manage the ongoing risk management process by maintaining a centralized risk register and ensuring alignment between business objectives, regulatory obligations, and security controls.
Conduct internal audits and risk assessments to evaluate the effectiveness of technical and organizational controls.
Manage the cybersecurity onboarding and ongoing risk assessments of third-party vendors, while cooperating with Legal to ensure alignment with privacy compliance requirements.
Manage relationships with external auditors and consultants, ensuring timely completion of certification milestones.
Partner with cross-functional teams to strengthen the companys overall GRC posture and support continuous improvement initiatives.
Requirements:
3-5 Years of proven experience in GRC, information security compliance, or audit management roles.
Experience with audit and certification processes of information security frameworks (e.g., ISO 27001, SOC 2).
Ability to manage cross-functional projects and collaborate effectively with internal stakeholders and external auditors, and consultants.
Excellent communication skills and attention to detail.
Fluent in English (written and spoken).
Preferred Skills:
Experience with risk assessments and managing a risk register end-to-end.
Experience with third-party vendor risk management.
Experience in compliance frameworks of cloud infrastructure.
Knowledge of privacy regulations such as GDPR and CCPA.
Background in cybersecurity or IT risk management.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8486342
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
Location:
Job Type: Full Time
we are seeking a skilled Project Manager to lead our Management Penetration Testing & Cyber Assessments team. Project Manager specializing in penetration testing and Cyber security assessments Responsibilities:
* Define and manage work plans for the execution of penetration tests and Cyber security assessments.
* Conduct meetings with system owners and stakeholders to gain familiarity with technological environments.
* Define and document the scope of cyber surveys and penetration tests, including application, infrastructure, and secure development (SSDLC) assessments
* Manage negotiations and engagements with external penetration testing and cyber assessment vendors.
* Lead penetration tests and surveys end-to-end, coordinating between external vendors and internal system owners.
* Review draft reports and validate findings.
* Support system owners in remediation activities, including re-testing and verification of findings closure.
* Perform Cyber security surveys related to supply chain security, including assessments of external service providers.
* Prepare presentations summarizing activities, findings, and risk insights.
* Work in a matrix organizational environment, coordinating and driving collaboration with stakeholders within and outside the Cyber Division.
* Interface with a wide range of internal stakeholders and external parties (vendors, integrators, service providers, etc.).
* Mobility required - ability to travel across Ben Gurion Airport campus and Authority sites
* Strong interpersonal skills and the ability to independently lead and drive activities.
Requirements:
Mandatory Requirements Qualifications Formal Education / Professional Training / Experience One of the following:
* Academic degree (Bachelors) or Practical Engineering diploma, with an emphasis on Information Systems / ICT / Industrial Engineering and Management minimum of 3 years of relevant experience
* Graduate of relevant professional courses with a cumulative scope of at least 400 training hours minimum of 4 years of relevant experience At least 5 years of experience in ICT project management Professional Experience and Knowledge
* Proven experience in managing Cyber security surveys and penetration tests for organizations with at least 2,000 users
* In-depth knowledge of security vulnerabilities and findings from application-level and infrastructure penetration testing At least 5 years of experience within the past 8 years in the following areas:
* Leading projects involving analysis, planning, procedure writing, and driving cross-functional professional collaboration
* Proven knowledge and experience with information security methodologies, standards, regulations, concepts, and technologies
* Familiarity with information security products and security solutions
* Full proficiency in Microsoft Office, including preparation of professional presentations Languages Native-level proficiency in Hebrew (reading, writing, and speaking). High-level proficiency in English, including reading, writing, and speaking
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8536317
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Ra'anana
Job Type: Full Time
This position should take ownership of the following key responsibilities:
Policy & Governance Management
Maintain and update the full security policy library (ISO 27001, SOC 2, GDPR, etc.).
Ensure version control, approval workflows, and cross-departmental adoption.
Lead annual policy reviews and align with new business or regulatory needs.
Security Risk Management
Own the corporate Risk Register (e.g., in Monday.com) and drive risk assessments across domains.
Track mitigation progress and report key risks to leadership.
Compliance & Certification Programs
Manage and maintain compliance frameworks (ISO 27001, GDPR, customer-driven requirements).
Prepare evidence and documentation for internal and external audits.
Vendor & Third-Party Risk Management
Oversee the Vendor Security Review process - reviewing new suppliers, SaaS tools, and renewals.
Monitor vendor security posture via SecurityScorecard or similar tools.
Ensure data processing agreements (DPAs) are aligned with legal.
Customer & Partner Assurance
Manage all RFI / RFP / security questionnaire responses.
Provide standardized documentation (e.g., SOC 2 reports, penetration testing summaries).
Support Sales / Customer Success during security discussions.
Security Process Governance
Define and enforce structured approval workflows for new tools, tokens, and architecture changes.
Integrate approvals into Jira or ServiceNow for traceability.
Collaborate with IT / AppSec / Legal for end-to-end governance.
Awareness & Training
Drive company-wide security awareness campaigns.
Onboard new hires with security and compliance training.
Ensure developers and business teams understand their compliance obligations.
Metrics & Reporting
Define KPIs for compliance maturity, audit readiness, and risk reduction.
Deliver quarterly GRC posture updates to the CISO / Security Steering Committee.
Requirements:
5-8 years of experience in Governance, Risk, and Compliance (GRC) or Information Security management, preferably within a technology or SaaS organization.
Proven track record of developing, implementing, and maintaining security policies and frameworks (e.g., ISO 27001, SOC 2, GDPR, NIST).
Hands-on experience owning and managing a corporate risk register, driving risk assessments, and ensuring timely mitigation across multiple business domains.
Strong background in compliance management, including preparing evidence and documentation for both internal and external audits.
Demonstrated ability to lead vendor and third-party security assessments, evaluate supplier risks, and align data processing agreements (DPAs) with legal and privacy teams.
Experience managing customer assurance programs, responding to RFIs/RFPs, and supporting sales teams with security documentation and due diligence.
Skilled in security process governance - establishing approval workflows for new tools, integrations, and architectural changes, and embedding controls into systems like Jira or ServiceNow.
Proven ability to drive security awareness initiatives, design training programs, and communicate compliance responsibilities effectively across departments.
Experience defining and reporting KPIs and metrics related to compliance maturity, audit readiness, and overall risk posture.
Strong collaboration skills - capable of partnering with cross-functional stakeholders (Engineering, IT, Legal, AppSec, and Product) to strengthen the organizations security and compliance posture.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8485733
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
02/02/2026
חברה חסויה
Location: Herzliya
Job Type: Full Time
Lead, mentor, and manage a team of analysts and incident responders, fostering a culture of continuous improvement and collaboration.
Oversee real-time monitoring, analysis, and escalation of security events using SIEM, SOAR, and other security tools.
Develop, implement, and optimize SOC processes, playbooks, and standard operating procedures.
Coordinate incident response activities, ensuring timely investigation, containment, eradication, and recovery from cyber incidents.
Serve as the primary point of contact for major security incidents, coordinating with internal stakeholders and external partners as needed. Ensuring effective communication and coordination among stakeholders throughout the lifecycle of security incidents.
Stay informed on the latest cyber threats, vulnerabilities, and regulatory developments to adapt the organizations security posture proactively.
Prepare and deliver regular reports, metrics, and presentations to executive management regarding Cyber Defense Center's performance and emerging risks.
Support compliance efforts and audits related to cybersecurity frameworks (e.g., SOC2, ISO 27001).
Manage Cyber Defense Center's technology stack, including evaluating and recommending tools and solutions for threat detection and response.
Establish and lead a dedicated purple team to enhance detection, response, and resilience against threats.
Requirements:
5+ years of experience in cybersecurity.
3+ years in a Security Operation Management role.
Strong knowledge of security operations, incident response, threat intelligence, and digital forensics.
Experience with SIEM, EDR, SOAR, firewalls, and other SOC technologies.
Relevant certifications such as CISSP, CISM, GIAC, or equivalent are highly desirable.
Knowledge of attacker tactics, techniques, and procedures (TTPs), as well as methods for defense.
Excellent analytical, problem-solving, and organizational skills.
Exceptional communication skills, with the ability to convey complex security concepts to technical and non-technical audiences.
Ability to work under pressure, manage multiple priorities, and respond to high-impact incidents effectively.
Demonstrated experience in developing, tracking, and reporting on key performance indicators (KPIs) to measure SOC effectiveness and drive continuous improvement.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8527908
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
25/01/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a Product & Data Protection Counsel to join our Legal team and help drive our success. This is a fantastic opportunity for an ambitious product counsel to join a global, rapidly growing B2B cybersecurity company.
WHAT YOULL DO
Work as part of the Product & Data Protection Team, with members based in Israel and the US.
Act as a key partner and advisor to our Product and R&D teams, advising on legal, commercial, regulatory, and data protection aspects throughout the product lifecycle.
Assess, mitigate, and manage risks related to the product lifecycle and serve as a subject matter expert on product issues.
Handle reviews of new product features and processing activities from a privacy, data protection, and compliance perspective.
Review and negotiate product-related vendor and integration agreements.
Requirements:
A minimum of 3 years of experience in an in-house product counsel role. Cybersecurity experience is a plus.
Technical understanding of the development and functionality of SaaS products.
Familiarity with privacy, data protection, and IP laws, as well as practical issues including AI, open source, and export control.
Experience negotiating and drafting commercial agreements, including SaaS and integration agreements, with a focus on privacy and security terms.
Excellent ability to communicate legal requirements to a non-legal audience and identify practical solutions.
Proven ability to collaborate effectively with other teams, including Security, GRC, Product, and R&D.
Strong operational and organizational skills with experience building and managing processes.
Strong research and analytical skills.
Fluency in English is a must.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8515997
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
29/01/2026
חברה חסויה
Location: Rehovot
Job Type: Full Time
We are seeking an experienced Cybersecurity Manager to oversee a global cybersecurity team. This role is responsible for protecting enterprise systems, networks, and data, driving security initiatives, ensuring regulatory compliance, and managing cyber risk across the organization.



Key Responsibilities:

Lead daily operations of the cybersecurity team, ensuring high levels of performance and service.
Execute, implement, and enforce cybersecurity strategies, standards, and policies.
Manage security incident response, threat detection, vulnerability management, and risk mitigation.
Collaborate closely with IT, Compliance, Legal, and Executive teams to align security initiatives with business needs.
Drive adoption and optimization of Microsoft 365 security tools and services.
Ensure secure configuration and management of Active Directory, Azure AD, Windows Server, DNS, DHCP, and related systems.
Support cybersecurity audits, compliance programs, and regulatory reporting efforts.
Mentor and develop cybersecurity staff, promoting continuous improvement and skill advancement.
Stay informed on emerging threats, technologies, and regulatory changes.
Requirements:
Bachelors or Masters degree in Cybersecurity, Computer Science, Information Technology, or related field.
7+ years of cybersecurity experience, with 3+ years in a leadership role.
2 years of Incident Response and or SOC management role.
Deep expertise in Microsoft 365 security (Defender suite, Microsoft Purview, Azure AD Identity Protection, Sentinel).
Strong knowledge of Active Directory, Azure Active Directory, Windows Servers, DNS, DHCP, and Group Policy.
Broad experience with SIEM, EDR, Threat intelligence, and vulnerability management tools.
Proven knowledge of security frameworks: NIST, ISO 27001, CIS, or equivalent.
Professional certifications required: CISSP, CISM, CEH, MS-500, SC-200, or comparable.
Strong leadership, communication, and problem-solving skills.
Experience working within multinational, matrixed environments.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8523342
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
20/01/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a highly skilled Cybersecurity Governance, Risk, and Compliance Engineer with strong technical and hands-on cybersecurity expertise. This role bridges the gap between compliance and technology - ensuring that GRC frameworks are not just compliant on paper but effective in practice across infrastructure, SaaS, and cloud environments.
As the Cybersecurity GRC Engineer you will oversee the technical execution of GRC initiatives, collaborating with cross-functional teams (Security Engineering, IT, DevOps, Product) to drive resilience, risk reduction, and audit readiness across the organization.
Reporting line: GRC Director
What you will do:
Collaborate with R&D and DevOps teams to integrate security into development and deployment processes.
Perform technical risk assessments, vulnerability trend analysis, and threat modeling to ensure risk registers reflect the true security posture.
Lead security awareness and social-engineering simulations, correlating campaign results with real technical findings (phishing, MFA bypass, insider threat trends).
Initiate and coordinate offensive security activities including penetration testing, red teaming, and vulnerability assessments to proactively identify and mitigate risks.
Support incident response readiness by integrating lessons learned into policy, control design, and awareness materials.
Leverage AI to automate GRC reporting, surface risk insights, and maintain intelligent dashboards integrated with platforms like ServiceNow, Jira, and internal data sources.
Partner with Security Engineering and IT teams to ensure consistent endpoint hardening, patch management, and configuration compliance.
Coordinate DR exercises and tabletop simulations, track findings, and oversee remediation to strengthen resilience.
Prepare for and support internal and external audits, including SOC 2, ISO 27001, NYDFS, and customer due-diligence requests.
Requirements:
+3 years of experience in GRC, IT Risk, or Security Operations, with at least 2 years hands-on in technical environments (e.g., system administration, cloud security, endpoint management, vulnerability management).
Strong working knowledge of cloud security (AWS, GCP, or Azure) and endpoint management (Jamf, Intune, CrowdStrike).
Proven ability to automate or optimize GRC workflows using tools, APIs, and AI.
Practical experience designing or testing Disaster Recovery and Business Continuity programs.
Strong analytical and problem-solving skills; able to translate complex technical risks into actionable business terms.
Visionary and innovation-driven, capable of implementing security and compliance programs in complex, fast-paced organizations.
Exceptional communication, collaboration, and interpersonal skills, with the ability to engage both technical and non-technical audiences.
Strong analytical, problem-solving skills and attention to detail, with the ability to manage multiple projects simultaneously and meet tight deadlines.
Preferred Qualifications:
Certifications such as CISA, CISM, CISSP, or Security+.
Background in the financial / digital assets sector or regulated environments.
Strong technological understanding and familiarity with product development practices.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8509955
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
The ideal candidate will bridge high-level security governance with hands-on, automated security implementation across the Software Development Life Cycle (SDLC).
This individual will be a critical enabler, empowering teams to move swiftly and deliver exceptional value to our clients, all while upholding the required security standards. A proven track record in successfully balancing rapid innovation with robust security practices is essential for this role.
How youll make an impact:
As the DevSecOps Leader / Program Manager, you will be responsible for creating a secure-by-design culture and leading the operational implementation of our security strategy. You will:
Build the Secure SDLC (SSDLC) Strategy: Develop, own, and execute the companys comprehensive DevSecOps strategy, focusing on automation to manage security at scale from code check-in to production deployment.
Lead Key Security Engineering Initiatives: Lead and manage security engineering programs, including:
Maturing the security tools stack (e.g., implementing WAF, and automating SCA/SAST tools).
Owning the bug bounty and responsible disclosure programs triage and remediation tracking.
Enhancing the Identity and Access Management (IAM) framework through concepts like Just-In-Time (JIT) and Zero Trust principles.
Operationalize CVE Tracking and Remediation: Design and implement a scalable system for discovering, tracking, and prioritizing Common Vulnerabilities and Exposures (CVEs) in third-party and custom code. Drive the engineering teams to achieve security risk remediation goals by providing clear, actionable data and automated patching mechanisms.
Measure & Drive Improvement: Develop and maintain key DevSecOps metrics (e.g., Mean Time To Detect/Remediate - MTTD/MTTR, percentage of code coverage by SAST/SCA tools) to measure the effectiveness of automated controls and provide a data-driven picture of the application security posture.
Embed Security Engineering: Spearhead R&D DevSecOps initiatives, partnering directly with engineering teams to select, deploy, and maintain security tools, establishing security gates and best practices throughout the product development lifecycle.
Requirements:
Deep DevSecOps Expertise: 5+ years of experience in a senior DevSecOps or Application/Product Security role, with a strong, working knowledge of DevSecOps principles and the modern application threat landscape (e.g., OWASP Top 10).
DevSecOps Focus: Proven ability to shift left security by embedding automated security controls (SAST, DAST, SCA, IAST) into CI/CD pipelines.
Open Source Security & Supply Chain Mastery: Deep, hands-on experience managing and hardening open-source software dependencies.
Key Focus: Expertise in utilizing Software Composition Analysis (SCA) tools (e.g., Dependency-Check, Snyk, Black Duck) to maintain an accurate Software Bill of Materials (SBOM) for all products.
Vulnerability & Risk Management Pro: Proven ability to establish and own a continuous CVE tracking and remediation process.
Key Focus: Expertise in risk-rating vulnerabilities based on exploitability and business impact, and driving engineering teams to remediate security risks efficiently using automation and clear Service Level Objectives (SLOs).
Audit & Compliance Automation: Proven, hands-on experience managing security audits and certification programs (e.g., SOC 2, ISO 27001) by leveraging security as code principles and automating evidence collection to demonstrate compliance across the pipeline.
Leadership & Influence: Strong leadership skills with the ability to build consensus and partner with R&D, Platform Engineering, and IT teams to embed security practices without being a bottleneck.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8498379
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 16 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly skilled and experienced Head of Application Security to join our dynamic team. This role is pivotal in driving the security of our software development lifecycle and ensuring the robustness of our applications against potential threats. The ideal candidate will have a strong background in secure software development practices, including SSDLC implementation, and a deep understanding of security risks & tools. This position reports directly to an R&D VP.
Key Responsibilities
Lead the application security team, providing strategic direction and mentorship.
Develop and implement a comprehensive Secure Software Development Lifecycle (SSDLC) framework.
Oversee the integration of security practices into all phases of the software development lifecycle, including CI/CD guardrails.
Conduct risk assessments and threat modeling to identify and mitigate potential security vulnerabilities.
Collaborate with development teams to ensure secure coding practices and adherence to security standards, while maintaining developer productivity.
Implement and manage security automation tools and processes to enhance the efficiency of security operations.
Stay up-to-date on the latest security trends, vulnerabilities, and technologies to continuously improve our security posture.
Provide expert guidance on security architecture and design for new and existing applications.
Lead incident response efforts related to application security breaches and vulnerabilities.
Foster a culture of security awareness and continuous improvement within the organization.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 7 years of experience in application security, with at least 3 years in a leadership role.
Proven experience in implementing and managing SSDLC frameworks.
In-depth knowledge of security frameworks and methodologies.
Strong understanding of threat modeling methodologies, secure coding practices and common vulnerabilities (e.g., OWASP Top Ten).
Proficiency in programming languages such as Java, Python, C#, or similar.
Experience in implementing security tools and technologies such as ASPM, SAST, DAST in complex and high-scale environment.
Excellent communication and leadership skills, with the ability and passion to drive change across the organization.
Relevant certifications such as CISSP, CISM, or CSSLP are desirable.
Proven experience in a similar role at another leading software development company.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8540450
סגור
שירות זה פתוח ללקוחות VIP בלבד