דרושים » אבטחת מידע וסייבר » Cyber Security Risk & Compliance Specialist (Office of the CISO)

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 5 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Cyber Security Risk & Compliance Specialist .
As a key member of the CISOs office, you will play a vital role in ensuring organizational resilience through risk management, policy enforcement, and compliance with stringent financial regulations. This position focuses on providing high-level oversight of technological processes, supporting complex projects, and continuously enhancing the organization's defense posture.
Responsibilities:
GRC & Policy Leadership: Writing, implementing, and updating information security policies and procedures. Ensuring alignment with banking standards and regulatory requirements (e.g., Directive 364).
Risk Assessment (CRA): Performing comprehensive cyber risk assessments for new systems and technological initiatives.
Oversight & Monitoring: Analyzing SIEM/SOC findings and technical risks. Providing guidance to implementation teams to improve detection capabilities and log management.
External Audit Management: Defining the scope and managing third-party security audits. Analyzing findings and tracking remediation efforts.
Security Benchmarking: Conducting comparative analysis of security products and general software from an information security perspective.
Detection Strategy: Formulating recommendations for log optimization, defining new alerts, and evaluating the effectiveness of existing control tools.
Strategy & Awareness: Building the annual information security work plan, leading cyber simulations, and conducting organizational security awareness training.
Requirements:
Professional Experience: 5+ years of experience in GRC, information systems auditing, or cyber risk management.
Risk Management Expertise: At least 4 years of hands-on experience in risk assessments or IT auditing.
Financial/Regulatory Background (Mandatory): Proven experience working in a regulated financial/banking environment under strict supervision (e.g., Proper Conduct of Banking Business).
Technical Understanding (Oversight Level): Ability to review security configurations, read logs, and understand network architectures (hands-on configuration is not required).
Exceptional Communication: High-level writing and drafting skills for complex procedures, official policies, and executive reports.
AI Proficiency: Practical experience using AI tools (e.g., ChatGPT, Claude, Copilot) to optimize workflows, technical writing, or data analysis.
Cloud Security: Familiarity with cloud security methodologies (Shared Responsibility Model) and SaaS/IaaS risk factors - an advantage
AI Security: Initial familiarity with GenAI risks and mitigation (e.g., OWASP Top 10 for LLMs) - an advantage
Benchmarking: Experience in performing Proof of Concept (POC) and comparative analysis of security products - an advantage
Certifications: CISM, CISA, or CISSP - Significant Advantage.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8621551
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/03/2026
חברה חסויה
Location: Tel Aviv-Yafo and Netanya
Job Type: Full Time
We're looking for a Senior Governance, Risk, and Compliance (GRC) Specialist to join our global GRC team. In this critical role, you will help secure the platform that powers the software supply chain for thousands of the world's top organizations.
Reporting to the GRC Manager, you will work alongside a talented team to enhance our security posture, establish GRC best practices, and embed security governance into our fast-paced, DevOps-driven culture. You will be a key advisor, helping to translate complex risks and compliance requirements into actionable controls that support missin.
As a Senior GRC specialist you will...
Drive Security Framework Adoption (New Markets): Lead the strategic adoption of net-new security frameworks to unlock business markets.
Oversee the Security Certification Program: Oversee the end-to-end execution of our security assurance portfolio (ISO 27001, SOC 2).
Lead Security Audits: Serve as a primary GRC contact for internal and external audits. You'll coordinate evidence gathering, craft management responses, and drive the remediation of findings.
Lead Governance Initiatives: Develop, maintain, and enhance the enterprise-wide security GRC framework, policies, standards, and procedures, ensuring they align with our cloud-native and SaaS environment.
Risk Management & TPRM: Evolve our Third-Party (TPRM) and Internal Security Risk programs, including executing and documenting comprehensive risk assessments, ensuring that findings are remediated and clearly aligned with risk appetite.
Collaborate Cross-Functionally: Partner with engineering, product, IT, and legal teams to embed security controls into daily business operations, ideally automated.
Mentor & Advise: Act as a subject matter expert on governance and risk for the wider organization and provide mentorship to junior GRC team members.
Requirements:
5+ years of direct experience in Information Security GRC, Risk Management, or Audit, preferably acquired within a high-growth SaaS or cloud-native environment.
A proactive, self-starting mentality with strong analytical, project management, and problem-solving skills, with proven ability to validate your own work and drive tasks to completion independently.
Demonstrable expertise in managing core compliance programs (SOC 2, ISO 27001)
Experience pursuing net-new compliance certifications and initiatives (e.g., R, C5, TISAX, IRAP).
Experience developing, drafting, and implementing security policies and standards from the ground up in a tech-focused environment, harmonizing controls across frameworks to create agile standards.
Experience leading complex security audits, serving as a primary liaison and "in-the-room" lead during internal and external audits.
Strong understanding of information security principles, risk management, and control frameworks in a cloud-first environment (AWS, GCP, Azure).
Exceptional communication and interpersonal skills, with a proven ability to build relationships and influence change across engineering, product, and business teams, and the ability to write concise, "Executive Ready" policies and risk reports.
Hands-on experience with GRC platforms and a drive to automate manual GRC workflows.
Bachelors degree in Cybersecurity, Information Technology, Law, or a related field, or equivalent practical experience.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8579715
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
29/03/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time and English Speakers
our Technology Consulting team is looking for a Cybersecurity Consultant to join our cyber department.
The Cyber Department works with a variety of clients in different fields: Government, Hi-tech, Industry, Retail, Hotels, Defense and more.
The Job Will Include:
Client Engagement: Leading, guiding and advising to clients in Israel and abroad as well as joint projects with various partners of global on cyber security projects based on methodology, regulation and standards
Technologies: Work with different aspects of cyber security in multiple fields such as IT, OT & Cloud
Security Assessments: Carrying out risk surveys including cyber, operational and supply chain risks
Advisory and Strategy Development: Developing business continuity plans (BCP) ,cyber security and maturity programs, secure architectures, policies and information security procedures
Collaboration: Leading representative and high-profile meetings with client internal senior management
Requirements:
Minimum of 2 years' experience of consulting in information and cyber security
Practical experience with cyber defense methodology and international standards such as: NIST800-53, CIS, Cyber defense theory 2.0 (INCD), CSF, CSA-Star
Experience with IT/OT/Cloud infrastructures and relevant information security standards in each realm
Experience in the field of conducting cyber risk assessment and GRC
Experience in formulating information security solutions
Advantage
Familiar with AI-based Security standards
Relevant Certifications: CISM, CISSP, CISO, CCSK, CCSP
Security clearance level 3 or higher
Skills:
Ability to work independently and in a team, time management and multi-tasking and Self-learning ability
Excellent written and expression abilities in Hebrew and English
Ability to write technological and methodological risk survey reports
Good Interpersonal, training, persuasion abilities
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8595892
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: More than one
we are looking for an experienced Cyber Security Consulting Manager (Engagement Manager) to lead proactive consulting engagements with clients worldwide. The appropriate candidate will be responsible for the engagement lifecycle - from engagement planning, throughout the day-to-day engagement execution, management of consulting team and client interaction, until the successful engagement presentation and delivery.
Main Responsibilities:
Lead a team of top cyber security consultants (matrix management), to conduct and deliver a variety of proactive cyber security assessments and resilience-enhancing engagements.
Work on multiple engagements in parallel, at client sites or remotely.
Ensure the timely and successful delivery of services according to the engagement scope, objectives, budget, timelines, and clients needs.
Develop and present status updates and summary reports to a variety of audiences, including technical teams, CISOs, CIOs/CTOs, and executive management.
Serve as the trusted advisor to industry-leading multinational organizations, acting as the primary point of contact with clients before, during, and after engagements.
Support the building of long-term relationships with clients, ensuring continuous client impact and success.
Participate in and lead business development activities, internal capability-building efforts, methodology development, and strategic discussions.
Requirements:
Minimum of five years of experience managing complex short to medium-term client-facing cyber security engagements in parallel, with excellent engagement management skills and a proven record.
Extensive understanding of cyber security, security governance, and cyber risk management best practices, frameworks, and principles.
Ability to collaborate with individuals across all levels in a dynamic matrix organizational structure, and coordinate with other departments.
Outstanding analytical, creative, and problem-solving skills and mindset, with the ability to handle uncertainty and complexity.
Excellent communication and presentation skills at all levels of the organization. Ability to articulate security concepts to technical staff and explain them to non-technical staff, including senior management.
Attention to detail and a commitment to maintaining high standards.
Certifications such as C-CISO, CISM, PMP, or similar are an advantage.
Knowledge of regulatory requirements and compliance standards such as NIST, ISO, and others is an advantage.
Excellent communication and presentation skills at all levels of the organization, in both English and Hebrew.
The position requires travel abroad (~15-20%).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8616696
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/03/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time and Hybrid work
We are seeking a highly skilled and experienced Head of Application Security to join our dynamic team.
Job Id: 24652
This role is pivotal in driving the security of our software development lifecycle and ensuring the robustness of our applications against potential threats. The ideal candidate will have a strong background in secure software development practices, including SSDLC implementation, and a deep understanding of security risks & tools. This position reports directly to an R&D VP.
Key Responsibilities
Lead the application security team, providing strategic direction and mentorship.
Develop and implement a comprehensive Secure Software Development Lifecycle (SSDLC) framework.
Oversee the integration of security practices into all phases of the software development lifecycle, including CI/CD guardrails.
Conduct risk assessments and threat modeling to identify and mitigate potential security vulnerabilities.
Collaborate with development teams to ensure secure coding practices and adherence to security standards, while maintaining developer productivity.
Implement and manage security automation tools and processes to enhance the efficiency of security operations.
Stay up-to-date on the latest security trends, vulnerabilities, and technologies to continuously improve our security posture.
Provide expert guidance on security architecture and design for new and existing applications.
Lead incident response efforts related to application security breaches and vulnerabilities.
Foster a culture of security awareness and continuous improvement within the organization.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 7 years of experience in application security, with at least 3 years in a leadership role.
Proven experience in implementing and managing SSDLC frameworks.
In-depth knowledge of security frameworks and methodologies.
Strong understanding of threat modeling methodologies, secure coding practices and common vulnerabilities (e.g., OWASP Top Ten).
Proficiency in programming languages such as Java, Python, C#, or similar.
Experience in implementing security tools and technologies such as ASPM, SAST, DAST in complex and high-scale environment.
Excellent communication and leadership skills, with the ability and passion to drive change across the organization.
Relevant certifications such as CISSP, CISM, or CSSLP are desirable.
Proven experience in a similar role at another leading software development company.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8597491
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/03/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Are you ready to evolve from a GRC Specialist into a strategic leader? We are looking for a high-potential GRC Specialist to join Fiverr. As a GRC at Fiverr you will be responsible for aligning Fiverr’s security compliance and regulatory requirements. You will be responsible for preparing the business for certifications and regulations. You will verify that existing controls are adequate and define and oversee the implementation of new security controls. In addition, you will be responsible for) Risk management, employee awareness and Vendor Security assessment. You will devise new policies and update existing ones while aligning with business processes.


What am I going to do?:

* Oversee the company's security GRC program.
* Lead annual certifications (ISO 27001, SOX-ITGC) and prepare for security audits (e.g., PCI DSS).
* Third-party risk management.
* Develop policies and guidelines aligned with security best practices for complex environments.
* Conduct risk management and build plans to mitigate risks while engaging stakeholders.
* Collaborate with IT, Legal, HR, Finance, and security teams to address gaps versus best practices.
* Drive the security awareness program and explore strategies to enhance the security posture.


Equal opportunities:
At Fiverr, we prioritize diversity. We celebrate difference and embed it into every aspect of our workplace and product, as well as our community. Fiverr is proud and committed to providing equal opportunity employment to all individuals regardless of race, color, religion, sex, sexual orientation, citizenship, national origin, disability, Veteran status, or any other characteristic protected by law. In addition, Fiverr will provide accommodation to individuals with disabilities or a special need.
Requirements:
* 1+ years in security & GRC.
* Proven experience in leading security compliance efforts, including certifications such as SOX, PCI DSS, and ISO 27001.
* Strong project management and familiarity with cloud and SaaS technologies.
* Basic working knowledge of AI tools and the ability to apply them in daily work to improve efficiency, drive innovation, and strengthen GRC activities.
* Experience in vendor management, including handling security agreements and security questionnaires (advantage).
* Technical mindset with experience in security tools (advantage).
* Curiosity, eagerness to learn, and a proactive attitude.
* Strong interpersonal skills and ability to work effectively with people.
At Fiverr, we’re not about checklists. If you don’t meet 100% of the requirements for this role but still feel passionate about the position and think you have the right skills and qualifications to excel at it, we want to hear from you.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8594922
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
7 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a passionate and experienced Governance, Risk, and Compliance (GRC) operations specialist to contribute to our companys efforts in making the most security and trusted provider of digital asset management solutions.
This role is critical in driving our day-to-day GRC programs, ensuring they are well maintained, run according to schedule, and align with our business needs.
As the GRC operations specialist, you will oversee the successful implementation and progress of GRC programs, practices, and projects, while collaborating with multiple cross-functional teams within the security department and outside of it.
What You Will Do:
Own, manage, and continuously improve the companys Third Party Risk Management (TPRM) program, making sure it is both aligned with expected security standards and best practices, and meets business requirements and SLAs.
Own, manage, and continuously improve the companys security awareness program, making sure its scope, content, cadence and overall performance are always aligned with the latest and most relevant expectations, while also well received and relevant to the business.
Manage ongoing operations within the GRC team including project management and tracking, financial planning and reporting, annual and periodic planning, and more.
Drive ongoing GRC efficiency through innovation, automation, data-driven decision making research and exploration.
Support and contribute to ongoing GRC operations such as internal and external audits, risk assessments, certification processes, policy management, business continuity program and more.
Requirements:
Minimum of 3+ years of experience in cybersecurity or GRC.
Proven experience in cyber or IT or third party risk management.
Proven experience in the security awareness domain, including development and implementation of security training programs and their testing (phishing, vishing, social engineering etc.).
Strong understanding of industry best practices, regulations, frameworks, standards and certifications such as SOC 2, ISO, NIST, CIS, DORA, GDPR, etc.
Visionary and innovation-driven, capable of implementing security and compliance programs in complex, fast-paced organizations.
Exceptional communication, collaboration, and interpersonal skills, with the ability to engage both technical and non-technical audiences.
Strong analytical, problem-solving skills and attention to detail, with the ability to manage multiple projects simultaneously and meet tight deadlines.
Preferred Qualifications:
Experience working with GRC software and utilities such as compliance management, policy management, risk management, vendor management, awareness, training and phishing simulation platforms, etc
Background in the financial/digital assets sector.
Good technological understanding and familiarity with product development practices.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8614258
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
31/03/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a GRC specialist who is excited to build and scale a modern compliance and security program from the ground up. This role is not just about maintaining SOC 2 and ISO certifications. It is about embedding security into our product, our engineering culture, and every customer conversation. You will partner closely with Engineering, Sales, and Leadership to turn compliance into a strategic advantage and help our company earn and maintain the trust of some of the most security-conscious organizations in the world.
About us:
The company Threat Exposure Management Platform is the first and only consolidated platform that integrates with your security tools to reveal, remediate, and mitigate the risk of exposures across your entire infrastructure. Backed by Sequoia and Cyberstarts, our company uses an agentless approach to reveal what is truly exploitable while reducing manual prioritization and remediation through automated response workflows.
What you will do:
Own and manage our companys security compliance program, including SOC 2, ISO 27001, and other relevant frameworks
Lead the response to customer security questionnaires and vendor security assessments, ensuring timely and accurate completion
Build and maintain our companys internal security controls framework and evidence collection processes
Establish and manage continuous compliance monitoring and validation initiatives
Develop and maintain security policies, standards, and procedures that support both compliance and business objectives
Manage relationships with external auditors and assessors during compliance audits
Drive security awareness training and secure development practices across the organization
Support customer-facing security conversations during sales cycles and onboarding
Monitor regulatory changes and emerging compliance requirements relevant to SaaS platforms
Build scalability into GRC processes through automation and tooling improvements.
Requirements:
4+ years of experience in information security and GRC
Proven track record managing SOC 2 Type 2, ISO 27001, or similar compliance frameworks for SaaS organizations
Experience working with SOC (cybersecurity operations center) and response to cybersecurity incidents
Hands-on experience with IT and Security tools
Strong understanding of security controls frameworks (NIST CSF, CIS Controls, OWASP)
Technical understanding of cloud security (AWS/Azure/GCP), application security, and infrastructure security
Excellent written and verbal communication skills with the ability to translate technical concepts for various audiences
Self-starter who can build processes from the ground up and operate with limited oversight
Relevant certifications preferred (CISSP, CISM, CISA, or equivalent).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8598892
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
29/03/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Cybersecurity Manager, AI Security Practice
Role Overview:
As a Manager in the Cybersecurity Practice with a focus on AI Security, you will drive strategic growth of offerings at the intersection of cybersecurity, artificial intelligence (AI), and governance risk & compliance (GRC). You will lead client engagements, shape innovative service offerings, influence go-to-market strategy, mentor delivery teams, and help organizations secure AI transformative initiatives.
This role sits at the convergence of consulting, technology, and risk advisory, requiring both deep technical expertise in AI and ML security architectures and senior client relationship leadership. You will work cross-functionally with global teams including cyber, cloud, data, AI and risk to embed security strategies into clients AI journeys.
Responsibilities:
Strategic Leadership & Practice Growth:
Define and execute the strategic roadmap for AI security offerings and solutions, including consulting frameworks, accelerators, and tool integrations.
Drive thought leadership in AI risk management, secure AI adoption, and cyber governance for emerging technologies.
Lead go-to-market strategy, including positioning, business development, proposals, pricing, and differentiation in AI security.
Influence global cyber offerings to incorporate AI risk, threat modeling, compliance, and resilience considerations.
Client Delivery & Engagement:
Lead complex client engagements end-to-end, from scoping through delivery, ensuring high quality, on-time and profitable execution.
Advise enterprise clients on secure AI adoption, AI threat landscape, governance frameworks, secure deployment patterns, and operational resiliency.
Architect secure AI and ML environments, including identification of risks such as data poisoning, model extraction, integrity attacks, and unauthorized access.
Integrate AI security with enterprise security programs, cloud, DevSecOps, identity and access management, and compliance controls.
Requirements:
10+ years of experience in cybersecurity or IT risk consulting roles, with strong experience in AI and ML security or adjacent domains including architecture, governance, or operations.
Proven track record of leading client engagements and complex technical teams.
Experience shaping commercial offerings, leading pre-sales activities, and winning new business.
Technical & Domain Expertise:
Deep understanding of AI and ML systems, models, data governance, and related threats including data poisoning, model evasion, extraction, and integrity risks.
Skilled in secure architecture design patterns for AI and ML platforms, cloud environments including AWS, Azure, and GCP, containers, orchestration with Kubernetes, and identity systems.
Familiarity with AI security frameworks and standards, including ISO 42001, and risk models.
Knowledge of NIST, MITRE ATT&CK, CSA, and GRC methodologies.
Leadership & Business Skills:
Strong client management and selling skills, including the ability to engage C-level stakeholders.
Excellent communication, presentation, and strategic thinking capabilities.
Ability to articulate complex technical risks in business terms.
Certifications (Preferred):
CISSP, CISM, CCSP, and AI security or data governance certifications.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8595862
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Security Engineer to join us. In this role, you will take part in securing our companys production environments across network, data, and AI domains. You will work closely with SRE, DevOps, platform, and internal security teams to design, operate, and continuously improve security controls, reduce risk, and strengthen our detection and response capabilities in a fast-growing, cloud-native environment.
Responsibilities
Support, maintain, and operate network, data, and AI security controls across our companys production environments, and continuously improve protection, detection, and response capabilities.
Design, implement, and troubleshoot network security mechanisms, including segmentation, access controls, and traffic inspection, to reduce attack surface and lateral movement.
Secure sensitive data and databases by enforcing encryption, permissions, and access governance, auditing, and monitoring to prevent data leakage and misuse.
Identify security risks related to AI systems, data pipelines, and inference services, and help define controls to protect models, training data, and AI-driven workflows.
Collaborate with engineering, SOC, and platform teams to identify high-risk assets, abuse scenarios, and attack paths, and translate them into actionable security controls and detections.
Support incident response activities by serving as an escalation point for complex network, data, and AI-related security incidents.
Contribute to improving security visibility, detection logic, and response processes, including documentation and knowledge sharing across the Cyber Defense Group.
Requirements:
Hands-on experience in security engineering or infrastructure security roles.
Strong understanding of network protocols, architectures, and common network-based attack techniques.
Experience securing databases and sensitive data, including encryption, access governance, and auditing.
Practical knowledge of AI/ML systems and modern AI usage patterns, including risks related to training data, inference APIs, and model access.
Understanding of emerging AI security threats, including prompt injection, data leakage, model abuse, and supply-chain risks.
Experience working in cloud environments (AWS, Azure, or GCP) and cloud-native security controls.
Experience participating in or leading security incident response and investigations.
Proven ability to take ownership, lead security processes end-to-end, and drive initiatives across multiple teams.
Strong analytical skills, proactive mindset, and ability to work effectively with cross-functional teams.
Advantage:
Experience with automation platforms and security-related workflows.
Familiarity with modern security architectures such as Zero Trust.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8598170
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/04/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly experienced Vulnerability Lead to join the Cyber Security organization, reporting directly to the Head of PMO under the CISO.
This role combines deep domain expertise in Vulnerability Management with strong project leadership capabilities. The primary focus is to lead and mature the organizations vulnerability management program, while also driving additional cross-functional security initiatives.
The ideal candidate brings hands-on experience in vulnerability lifecycle management, risk-based prioritization, and remediation at scale, along with the ability to operate across security, engineering, infrastructure, and product teams.
Responsibilities:
Vulnerability Management Leadership
Own and lead the organizations Vulnerability Management program across cloud, infrastructure, SaaS, and application environments.
Drive end-to-end vulnerability lifecycle: identification, assessment, prioritization, remediation, and validation.
Implement and enforce risk-based prioritization aligned with business impact and threat intelligence.
Define, track, and improve KPIs such as SLA adherence, remediation timelines, and exposure trends.
Work closely with Security, DevOps, Infrastructure, and Engineering teams to ensure effective remediation at scale.
Project & PMO Execution
Lead and deliver additional cross-functional cyber security projects under the CISO organization.
Define project scope, objectives, timelines, and success metrics aligned with security strategy.
Manage execution, dependencies, risks, and stakeholder alignment across multiple initiatives.
Prepare executive-level reporting and dashboards for the CISO and senior leadership.
Strategy & Improvement
Continuously improve vulnerability management processes, tooling, and governance.
Support audits, compliance requirements, and security risk reporting.
Act as a subject matter expert for vulnerability risk across the organization.
Requirements:
3-5 years of experience in Vulnerability Management, cyber security operations, or related domains.
Strong hands-on experience managing vulnerability lifecycle and remediation processes at scale.
Proven experience working with vulnerability management tools (e.g., Qualys, Tenable, Rapid7, Wiz, Prisma Cloud).
3+ years of experience in project or program management within technology or security environments.
Strong understanding of cloud, infrastructure, and application environments.
Experience working cross-functionally with Security, DevOps, Engineering, and IT teams.
Experience in risk-based prioritization and security risk management methodologies.
Hands-on experience with project management tools such as Jira, Monday, Asana, or similar systems.
Excellent communication skills with experience presenting to senior leadership.
Preferred Qualifications:
Experience working within a CISO organization or Security PMO.
Background in SaaS, cloud infrastructure, or large-scale enterprise environments.
Familiarity with regulatory frameworks (ISO 27001, SOC 2, NIST, etc.).
Experience leading enterprise-wide security or risk reduction initiatives. BSc in Industrial Engineering, Computer Science, or a related field.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8599452
סגור
שירות זה פתוח ללקוחות VIP בלבד