דרושים » ניהול ביניים » Information Security Manager

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
1 ימים
דרושים בריקרוטיקס בע"מ
Job Type: More than one
Our company specializes in cybersecurity consulting and is currently expanding our team. We offer a dynamic and challenging role in a company that greatly values human capital.

Job Description:
Lead and manage the company's cybersecurity strategies and processes.
Enhance cybersecurity across both on-premises and cloud networks.
Draft and maintain documents, including information security policies, procedures, and reports.
Provide consultancy on cybersecurity solutions and controls.
Requirements:
At least 1 year of experience in a CISO or CTO role.
Knowledge of web security and familiarity with the OWASP Top 10 security risks is advantageous.
Extensive knowledge of cybersecurity best practices for network and cloud infrastructure.
Professional certification in information technology/security.
Familiarity with privacy protection regulations and certifications such as ISO 27001 and SOC2.
Strong organizational skills, team-oriented, and service-focused.
Hands-on experience with technical security controls (FW, EDR, etc).
High proficiency in English.
This position is open to all candidates.
 
Hide
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8671648
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
Location: Herzliya
Job Type: Full Time
we are seeking a Cybersecurity Architect (GRC & Risk) to join our cybersecurity architecture team. In this role, you will lead security governance, risk, and control assessments, conduct third-party due diligence, support maturity assessments, and drive mitigation and architectural review processes. Youll work closely with CISOs, security leaders, engineering teams, and customers to develop risk-focused methodologies and improve security frameworks. This position is best suited for candidates with a technical GRC, risk, or security assessment background who excel in analysis, interpretation, and structuring of security information.

Responsibilities
Lead customer third‑party security due diligence assessments.
Lead mitigation workshops to translate penetration test and assessment findings into prioritized remediation workplans.
Perform security maturity assessments, including reviews of organizational policies, standards, procedures, and governance practices, aligned with the NIST CSF 2.0 cybersecurity framework.
Develop and refine security methodologies, processes, and architectural guidance.
Maintain internal documentation and ensure alignment between frameworks, processes, and practical implementation.
Analyze technical findings and map them to governance, risk, and control gaps.
Produce clear, structured reports and executive‑ready summaries for technical and non‑technical audiences.
Requirements:
3-4 years in cybersecurity GRC, IT risk, compliance, audit/assurance, or related process‑oriented security roles.
Strong understanding of governance, risk management, and operational processes.
Familiarity with cybersecurity frameworks (NIST CSF, ISO 27001 concepts), risk assessment, mitigation planning, and third‑party risk management.
Basic conceptual understanding of cloud/SaaS shared responsibility models.
Ability to communicate technical issues in business‑aligned language.
Hands-on experience with security controls - an advantage.
Strong writing, communication, and facilitation skills.
Comfortable collaborating with internal stakeholders and external customers.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8671044
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
29/04/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly experienced and visionary Information Security Group Leader. As a part of this role, you will define strategy and roadmap, design and implement scalable controls, and ensure robust protection of enterprise systems, applications, and data across on‑prem, hybrid, and cloud environments.
This role requires deep technical expertise, risk-based decision-making, and the ability to drive security outcomes through cross-functional partnership with IT, R&D, and business stakeholders.
This role combines strategic leadership, hands-on technical expertise, and cross-functional collaboration to continuously reduce risk, improve detection and response, and enable the business to move fast while meeting security and compliance obligations.

What will you do?
Security Leadership & Operations
Manage and mentor a team of security professionals, set objectives, develop skills, and build a high-performing, service-oriented security function.
Lead risk assessments and threat modeling for infrastructure and applications, drive remediation plans and risk acceptance decisions.
Oversee security operations, monitoring, and incident response in partnership with internal teams and service providers.
Define KPIs/KRIs and report security posture to leadership; manage budget, tools lifecycle, and security vendor relationships.
Security Architecture & Design
Define and maintain enterprise security architecture across applications, network, endpoints, identity, and core infrastructure.
Requirements:
Experience: 10+ years in information security, IT, and/or security architecture, with demonstrated leadership across security operations, infrastructure, and cloud environments.
Expertise:
Security frameworks and risk management (e.g., NIST CSF/800-53, ISO 27001, SOC 2), including control ownership and audit readiness.
Cloud security for AWS/Azure/GCP and hybrid architectures (identity, network, logging/monitoring, workload protection, CSPM/CWPP concepts).
Advanced networking and network security (firewalls, segmentation, SD-WAN, Zero Trust, VPN/secure remote access, DNS security).
Virtualization (Nutanix, VMware).
Storage systems (Netapp).
Identity & Access Management (SSO, MFA, PAM, lifecycle automation) and strong authentication/authorization patterns.
Application Security and DevSecOps (secure SDLC, code review practices, SAST/DAST, dependency and container security, CI/CD integrations).
Vulnerability management (scanning, prioritization, patching governance) and security hardening for endpoints, servers, and cloud workloads.
Security operations tooling and processes (SIEM, SOAR, EDR/XDR), logging strategy, detection engineering, and incident response.
Proven ability to lead through influence, driving a security-first culture across IT and business units while navigating complex organizational changes.
A track record of building high-performing teams by fostering a culture of continuous learning and clear career pathing for security professionals.
Exceptional ability to translate complex technical risks into business-impact narratives for leadership.
Strong "leader-as-a-partner" mindset, balancing security requirements with the need for business agility and speed.
Proficiency in developing security frameworks for the safe adoption of Generative AI and LLMs.
Certifications: CISSP and/or CISM, cloud security/architecture certifications (AWS/Azure/GCP) or equivalent experience.
Skills: Strong analytical and problem-solving skills, Strategic thinker with the ability to translate long term vision into practical execution, Comfortable navigating ambiguity and balancing competing priorities, Genuine interest in emerging technologies, including AI and security automation, Results-oriented with strong focus on measurable outcomes, Excellent written and verbal communication, stakeholder management, and program/project management.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8629592
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
26/04/2026
Location: Petah Tikva
Job Type: Full Time
Responsibilities
Develop, enforce, and maintain security policies and procedures for information systems in accordance with customer and corporate standards.
Manage the security authorization process to include supporting systems owners with accreditation and compliance reviews.
Monitor and manage security controls such as firewalls, access controls, data encryption, and system hardening.
Risk assessment and management to include conducting vulnerability assessments and developing risk mitigation strategies.
Incident response to include investigations, stakeholder communication, and reporting.
Manage and maintain personnel security qualifications, to include:
Initial processing
Briefings
Annual Trainings
Debriefings
Monitor secure facility compliance with facility accreditation standards.
Conduct inspections; manage preparations for and representation at security inspections and audits by customer security personnel.
Establish security trainings and briefings specifically tailored to the unique requirements of the program(s).
Assist with administering Insider Threat Awareness Program.
Oversee visitor and access control program.
Manage items lifecycle, to include creation, documentation, storage, transfer and destruction in accordance with customer procedures.
Support cross border collaboration and contribute to corporate best practices.
Maintain and administer information management plan for customer infrastructure.
Requirements:
Position Requirements

Prior experience as an Information System Security Officer or equivalent and at least eight years experience in the following areas:

Information Systems Security.

Implementation and administration of security processes and procedures.

Establishing and administering material control programs, including transfer, transmission, reproduction, destruction, and accountability.

Management of an accredited secure facility.

Delivering security awareness trainings and compliance programs.

Required Education/Skills:

Demonstrated leadership or command experience within the IDF, Police, or ISA

Working knowledge of cloud technologies and cloud-security frameworks.
Masterss degree in a relevant discipline (or equivalent) with 8+ years of security experience in support of sensitive programs within Defense Industry.

Must possess a high level of understanding of security related policies, procedures, and initiatives.

Ability to apply knowledge of security requirements in a complex multi-level secure environment to ensure program compliance.

Ability to work independently to identify, assess & resolve unique security situations to facilitate contract performance within the bounds of security.

Highly proficient written and verbal communications skills with emphasis on clear and concise presentation of complex information.

Must have a professional demeanor, good people skills, ability to communicate effectively, and be able to perform in a dynamic environment.

Full professional proficiency in English; portions of the recruitment process will be conducted in English.
Strong analytical and technological systems-evaluation capabilities.
Background in a global, matrixed corporate or cloud-service organization.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8624043
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
13/05/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly skilled and experienced Head of Application Security to join our dynamic team. This role is pivotal in driving the security of our software development lifecycle and ensuring the robustness of our applications against potential threats. The ideal candidate will have a strong background in secure software development practices, including SSDLC implementation, and a deep understanding of security risks & tools. This position reports directly to an R&D VP.
Key Responsibilities
Lead the application security team, providing strategic direction and mentorship.
Develop and implement a comprehensive Secure Software Development Lifecycle (SSDLC) framework.
Oversee the integration of security practices into all phases of the software development lifecycle, including CI/CD guardrails.
Conduct risk assessments and threat modeling to identify and mitigate potential security vulnerabilities.
Collaborate with development teams to ensure secure coding practices and adherence to security standards, while maintaining developer productivity.
Implement and manage security automation tools and processes to enhance the efficiency of security operations.
Stay up-to-date on the latest security trends, vulnerabilities, and technologies to continuously improve our security posture.
Provide expert guidance on security architecture and design for new and existing applications.
Lead incident response efforts related to application security breaches and vulnerabilities.
Foster a culture of security awareness and continuous improvement within the organization.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 7 years of experience in application security, with at least 3 years in a leadership role.
Proven experience in implementing and managing SSDLC frameworks.
In-depth knowledge of security frameworks and methodologies.
Strong understanding of threat modeling methodologies, secure coding practices and common vulnerabilities (e.g., OWASP Top Ten).
Proficiency in programming languages such as Java, Python, C#, or similar.
Experience in implementing security tools and technologies such as ASPM, SAST, DAST in complex and high-scale environment.
Excellent communication and leadership skills, with the ability and passion to drive change across the organization.
Relevant certifications such as CISSP, CISM, or CSSLP are desirable.
Proven experience in a similar role at another leading software development company.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8649501
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
looking for a Compliance Analyst to join the CISO team. Reporting to the GRC Team Leader, you will fulfill an essential role, joining the team in accomplishing important Compliance projects, ensuring that all systems and products are safe and meet the required standard.

What will you actually be doing?
Track enterprise compliance across multiple security frameworks including security, privacy and AI frameworks (ISO, SOC, etc) and maintain up-to-date records of requirements and corresponding mitigating controls.

Continuous monitoring of internal security processes to ensure compliance, and liaise with IT and business stakeholders to confirm current security arrangements and maintain systems security process.

Assist with the education and awareness programs to promote security and privacy in the company.

Creatively overcome obstacles so that the Compliance Controls will continuously operate alongside the business activities.

Review proposed changes on an ongoing basis to determine the impact on security and privacy.
Requirements:
1-2 years of experience in security compliance frameworks such as ISO 27001 and SOC 2.

High level of professionalism, analytical, detail-oriented, proactive, organized, responsible, deadline-focused, self-driven and highly motivated with a can do attitude.

Ability to work with cross-functional teams, maintain strong working relationships, and maximize collaboration.

BSc. in Computer Science, Information Systems or other information security-related certificates - Advantage.

Experience with Jira and Confluence - Advantage.

Experience in implementing compliance tools - Advantage.

Experience working in a Global, International, SaaS Company as an in-house Compliance function - Advantage.

Excellent written and verbal communication skills.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8636263
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We're building something special in our Israel-based Offensive Security organization, and we're hiring multiple people across three key areas:
Penetration Testing
Red Team Product
Security Research
While these roles share a common foundation in offensive security tradecraft, each brings its own unique focus and impact.
We're looking for deep expertise in at least one of these areas, with the ability to grow across others. We have multiple openings and are looking for talent at various levels. As we get to know you through the interview process, we'll work together to identify the best fit matching your expertise and interests with the specific role and level (Senior, Lead, or Principal) that makes the most sense for both you and the team.
Role Overview
We are seeking a highly skilled offensive security professional to join our elite team. This role is ideal for someone who thrives on breaking systems, finding creative attack paths, and using their findings to drive meaningful security improvements across our company's products and infrastructure.
You will work alongside some of the best minds in security, operating with significant autonomy and impact. Whether you specialize in deep application level penetration testing, red teaming, security research or vulnerability discovery, we want to hear from you-you don't need to be an expert in all three domains. What unites these roles is a relentless attacker mindset, a drive to find and demonstrate real-world impact, and the ability to translate offensive findings into lasting security improvements.
Responsibilities
Conduct advanced penetration testing, red team operations, or security research targeting our company's cloud infrastructure, applications, and services
Discover, exploit, and document security vulnerabilities using creative and methodical approaches
Develop custom tools, exploits, and attack techniques to simulate real-world adversaries
Collaborate with product teams to remediate vulnerabilities and improve secure design practices
Contribute to the maturity of our offensive security program through automation, tooling, and process improvements
Mentor and share knowledge with team members, fostering a culture of continuous learning
Present findings and security insights to technical and executive audiences
Stay ahead of emerging threats, attack techniques, and offensive security tradecraft.
Requirements:
5+ years of hands-on experience in offensive security (Senior), 7+ years (Lead), or 10+ years (Principal).
Deep, demonstrable expertise in at least one of the following domains: penetration testing, red teaming, application security research, or vulnerability discovery, with strong foundational knowledge and willingness to learn across other offensive security disciplines.
Proven ability to identify and exploit complex vulnerabilities in web applications, APIs, cloud environments, or infrastructure.
Strong programming/scripting skills (e.g., Python, Go, Bash, PowerShell) for tooling and automation.
Deep understanding of attack frameworks (MITRE ATT&CK), common vulnerability classes (OWASP, CWE), and exploitation techniques.
Excellent written and verbal communication skills, with the ability to clearly document technical findings.
Self-motivated, intellectually curious, and comfortable working independently or as part of a team.
Preferred Qualifications
Experience in cloud security (AWS, GCP, Azure) and containerized environments (Kubernetes, Docker).
Background in offensive security research, including CVE discoveries or contributions to security tools.
Familiarity with CI/CD pipeline security, supply chain attacks, or infrastructure-as-code security.
Experience with social engineering, physical security testing, or adversary simulation.
Active participation in the security community (bug bounties, CTFs, conferences, open-source contributions).
Relevant certifications (OSCP, OSCE, OSWE, GXPN, or equivalent).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8670402
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
14/05/2026
חברה חסויה
Location: Herzliya
Job Type: Full Time
At our company, we move fast. Were an ultra-collaborative company with brilliant people who care deeply about the details. Together, were solving interesting and complex puzzles to keep the worlds data safe.
We work in a flexible, hybrid model, so you can choose the home-office balance that works best for you.
Job Overview:
We are seeking a highly skilled and experienced Security GRC Specialist to join our team. This position reports directly to the GRC Manager, as part of the CISO group. The ideal candidate should have a strong background in GRC, with a proven track record of successfully implementing GRC programs. This role requires a diligent professional who thrives in a fast-paced environment and can manage multiple priorities while maintaining attention to detail.
Key Responsibilities:
Develop, implement, and maintain GRC frameworks, policies, and procedures.
Manage ISO 27001/ISO27017/ISO27018 compliance by conducting gap analyses, maintaining ISMS documentation, and coordinating audits to ensure ongoing certification.
Respond to customer due diligence requests and support the review of security and compliance clauses in customer and vendor contracts,
Conduct third-party risk assessments and identify potential security threats and vulnerabilities.
Manage and maintain the GRC platform to ensure accurate compliance monitoring, documentation, and audit support
Collaborate with cross-functional teams to integrate GRC initiatives into business processes.
Provide guidance and support to internal stakeholders on GRC-related matters.
Stay up to date with industry trends and emerging threats to continuously improve the GRC program.
Requirements:
Minimum of 3 years of experience in GRC, and information security.
Strong knowledge of regulatory requirements and industry standards (e.g., GDPR, ISO 27001).
Experience in responding to customer due diligence requests.
Experience in conducting security audits such as SOC 2 and ISO 27000 family.
Experienced with leading GRC platforms, covering third-party risk management, audit management, and security awareness programs.
Excellent analytical, attention to detail, problem-solving, and communication skills.
We are looking for a passionate candidate who can work independently and collaboratively as part of a team in a fast-paced environment.
Relevant certifications such as CISSP, CISM, or CRISC are preferred.
Highly advantageous experience with:
ISO 42001 compliance, including implementation, documentation, and audit coordination.
Payment Card Industry (PCI) standards.
Business Continuity Management.
Developing GRC platform automations, integrations, and workflows.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8651897
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Bnei Brak
Job Type: Full Time and Hybrid work
We are looking for a GRC Specialist to support our Governance, Risk, and Compliance (GRC) program, reporting directly to the CISO.

This is a hands‑on, execution‑focused role responsible for maintaining and scaling our compliance posture, reducing audit friction, addressing vendor risk, and supporting the integration of newly acquired companies into our security and compliance frameworks.

You will work closely with Security Engineering, IT, Legal, Privacy, Sales/Revenue, Procurement, Product, HR, and other business stakeholders to ensure security controls, compliance activities, and risk management processes are practical, effective, and aligned with business needs.


The day‑to‑day:
Lead audit preparation and ongoing compliance maintenance for frameworks such as SOC 2 / SOC 3, ISO 27001, ISO 27701, ISO 22301, NIST, and GDPR, including evidence collection, gap tracking, and remediation coordination.
Own and execute vendor and third‑party security assessments, helping reduce backlog and improve risk visibility across suppliers and partners.
Respond to customer security questionnaires and audits, partnering with Sales and Security teams to support deal velocity and customer trust.
Support the integration of newly acquired companies into our security, risk, and compliance programs, including gap assessments and remediation planning.
Maintain and improve the ISMS, governance processes, policies, standards, and procedures.
Act as a central point of contact for internal security and compliance inquiries from business and technical teams.
Support the administration and continuous improvement of GRC and compliance tooling, including workflows, evidence management, and reporting.
Contribute to the Security Awareness Program and cross‑organizational education efforts.

The perks:
Hybrid, flexible work environment.
Extended private health (including mental) insurance.
Personal and professional development programs.
Occasional Cross company long weekends.
Requirements:
Ideally, were looking for:
1-2 years hands‑on experience in GRC, information security, audit, or compliance, with a strong focus on execution and coordination.
Practical experience working with ISO 27001, SOC 2, GDPR, and/or NIST CSF, including audits and ongoing compliance activities.
Solid understanding of risk management, control design, and governance processes in a SaaS or cloud environment.
Experience performing vendor / third‑party risk assessments and driving remediation.
Strong ability to work cross‑functionally with technical and non‑technical stakeholders.
Clear, concise written and verbal communication skills in English, including customer‑facing documentation.
Strong organizational skills and attention to detail, with the ability to manage multiple parallel workstreams.


These would also be nice
Relevant certifications such as CISA, CISM, CRISC, or ISO 27001 Lead Auditor / Implementer.
Experience with privacy governance, DPIAs/PIAs, and collaboration with legal and privacy teams.
Familiarity with cloud and SaaS environments, particularly AWS.
Experience with GRC platforms or compliance automation tools.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8669028
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Senior Product Security Engineer
As a Senior Product Security Engineer, you will help shape how security is built, not just how it is tested or reviewed. Youll work closely with engineering teams to secure real systems in production, influencing how services, APIs, and data flows are implemented from the ground up.
This is a hands-on role, focused on solving real security problems across cloud-native architectures and AI-driven features. Youll work directly with developers and DevOps, dive into systems when needed, and apply strong technical judgment to ensure security is built into the product, not added later.
What Makes This Role Unique
A product where data sensitivity is real, not theoretical
We processe and analyze customer conversations at scale, creating unique challenges around data protection, privacy, and access control.
AI is deeply embedded in the product
Security challenges extend beyond traditional AppSec into data handling, model behavior, and misuse scenarios.
Security is part of how we build, not a layer on top
The role operates within engineering workflows, focusing on building secure systems rather than enforcing external controls.
Meaningful scale and real production impact
Youll work on systems that handle large volumes of data and traffic, where security decisions directly affect reliability and trust.
A culture that values practical, engineering-driven security
The focus is on solving real problems and enabling teams, not on process-heavy or compliance-driven approaches.
High ownership with room to grow
Youll have the autonomy to take initiative, drive improvements, and expand your impact as the platform evolves.
What Youll Do
Secure real product flows end-to-end - Work directly with engineers to identify and fix vulnerabilities across services, APIs, and data paths in production systems
Drive secure-by-design practices in engineering - provide practical guidance on authentication, authorization, data protection, and service-to-service communication
Secure cloud-native environments - strengthen identity (IAM), isolation, and access control across Kubernetes, containers, and cloud infrastructure
Build and scale security in the development lifecycle - integrate and tune security tooling (SAST, SCA, IaC scanning, secrets detection) into CI/CD pipelines to improve signal and developer adoption
Own vulnerability management as a system - prioritize risks, drive remediation with engineering teams, and eliminate recurring issues through root-cause fixes
Strengthen software supply chain security.
דרישות:
5+ years of experience in Product Security, Application Security, or a similar hands-on security engineering role
Proven experience working closely with engineering teams on real systems in production, not just assessments
Strong understanding of secure design and threat modeling, with the ability to influence architecture decisions
Deep knowledge of application security principles (OWASP Top 10 and beyond), including modern attack vectors
Hands-on experience securing web applications, APIs, and distributed systems
Strong experience with cloud environments (AWS, GCP, and/or Azure), including identity and access management (IAM)
Familiarity with Kubernetes, containers, and cloud-native architectures
Experience integrating security into CI/CD pipelines and improving developer workflows
Practical experience with security tooling (SAST, SCA, IaC scanning, secrets detection), including tuning and operationalizing
Experience working with modern development stacks (e.g., Java, Python, JavaScript/TypeScript, React or similar)
Strong problem-solving skills and the ability to analyze complex systems and prioritize meaningful risks
Ability to influence developers through technical credibility and practical guidance
Experience mentoring engineers and improving security practices across teams
Additional strengths:
Experience securing AI/ML or LLM-based systems
Background in o המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8665214
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Herzliya
Job Type: Full Time
our Security team is looking for a highly skilled and security-savvy Application Security Engineer to lead our product and application security efforts. In this role, you will drive security design, ensure secure coding practices, and validate our services and environments against the highest security standards.
You will work closely with our R&D and Product teams to identify, mitigate, and prevent security risks throughout the software development lifecycle (SDLC). As a senior engineer, you will own security initiatives, mentor developers on security best practices, and play a key role in shaping the security posture of products.
The ideal candidate is highly motivated, eager to learn, and has a security by design mindset. This role provides career growth opportunities, enabling you to deepen your expertise in AppSec, DevSecOps, and cloud security.
What you'll do:
Partner with development and product teams to integrate security best practices into the SDLC
Lead threat modeling and architecture security reviews to proactively identify and mitigate risks
Conduct security assessments, including code reviews, vulnerability scans, penetration testing, and secure product design reviews
Stay up to date with emerging security threats, vulnerabilities, and industry trends, ensuring remains ahead of evolving risks.
Support and contribute to security incident response activities, including root cause analysis and post-incident improvements
Automate security processes and integrate security tools within CI/CD pipelines
Develop and deliver secure coding training to engineering teams
Requirements:
4+ years of experience in Application Security, Penetration Testing, or Product Security in a SaaS company
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience)
Deep understanding and hands-on experience of web application security, including OWASP Top 10, authentication, encryption, and secure coding principles
Proficiency in scripting or programming languages (Python, JavaScript, Go, etc.) for security automation
Experience with cloud security best practices (AWS, GCP, or Azure)
Hands-on experience with DevSecOps and integrating security tools into CI/CD pipelines
Strong communication skills, with the ability to explain security risks and recommendations to technical and non-technical stakeholders, including executive management
Experience working with large-scale, complex R&D environments
Bonus Points:
Being introduced by an AppsFlyer team member
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8663169
סגור
שירות זה פתוח ללקוחות VIP בלבד