דרושים » אבטחת מידע וסייבר » Senior Threat Engineer- Detection

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
05/07/2026
משרה זו סומנה ע"י המעסיק כלא אקטואלית יותר
שם חברה חסוי
מיקום המשרה: תל אביב יפו
סוג משרה: משרה מלאה
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
04/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As an AI Security Researcher , you will play a key role in shaping the future of modern runtime AI security. You will investigate how real-world attacks unfold across AI-enabled applications, agents, tools, executed in cloud environments, and turn those insights into innovative, production-grade security capabilities across our AI Security Posture Management (AI-SPM) and AI Detection & Response (AI-DR) products.

This role is ideal for a deeply technical researcher who is driven to understand AI attacks at their core - not just identify suspicious prompts or surface-level indicators. You will research how prompt injection, tool misuse, agent drift, model abuse, and other emerging AI attack techniques translate into real runtime behavior and security impact. You will then apply that knowledge to build protections that are precise, resilient, scalable, and grounded in how attacks actually work in production.

Specifically, you will:

Research real-world attacks targeting models, agents, MCP/tooling ecosystems, RAG applications, and AI-enabled production systems.
Drive research end-to-end - explore, design, develop, validate, and deploy detection logic and protections based on runtime telemetry, exploit PoCs, technical analysis, and threat intelligence.
Shape AI-SPM capabilities by identifying what telemetry, signals, and modeling are required to continuously discover AI components, classify AI behavior, map risk, and detect unsafe or anomalous usage in production.
Shape AI-DR capabilities by researching how to detect AI-driven attacks, prove runtime impact, establish causality, and distinguish failed attempts from real compromise.
Work closely with engineering and product teams to turn deep technical research into practical security capabilities that deliver clear customer value.
Requirements:
5+ years of experience in security research, vulnerability research, detection engineering, threat research, application security, or a related technical security role.
Strong understanding of modern attack techniques, including the ability to analyze vulnerabilities, exploitation flows, and attacker behavior in real systems.
Familiarity with AI application architectures and concepts, including LLM-based applications, agents, tooling layers, models, RAG.
Experience designing and conducting hands-on technical research, including investigations, experiments, exploit analysis, and PoC development.
Strong programming skills for code analysis, research tooling, proof-of-concepts, and building vulnerable or instrumented test environments.
Experience working with runtime telemetry, behavioral signals, or detection-oriented datasets, and the ability to translate research into scalable detection logic.
High degree of ownership and ability to independently navigate ambiguous technical problem spaces and turn them into structured research plans and actionable outcomes.
Strong communication and teamwork skills, with a collaborative approach to problem-solving across research, engineering, and product teams.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8768190
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
25/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
our company's attack surface spans several distinct businesses: the engine and editor developers build on, a wide portfolio of cloud products and services, a large monetization business, and a growing set of AI-assisted creation tools. Code built with our company runs everywhere from a developer's workstation to billions of end-user devices, so targets range from native binaries to distributed cloud systems to AI pipelines, and findings here matter.
This role brings an attacker's mindset to that landscape: penetration testing and red team engagements built on complex attack chains. You would combine manual techniques with automation and tooling you develop as part of your craft, extending your reach across the company ecosystem.
What you'll be doing
Plan and execute objective-based penetration tests and red team engagements across our company's products, cloud services, and infrastructure
Find and validate exploitable vulnerabilities, chain them into realistic attack paths, and demonstrate impact with reproducible proofs of concept
Develop the automation and tooling that extend the team's offensive reach across the company ecosystem
Run joint exercises with the SOC and detection engineering teams to validate telemetry and improve detections
Deliver clear findings to engineering teams and surface recurring risk patterns to security leadership.
Requirements:
5+ years of hands-on experience in offensive security, penetration testing, or red teaming
Proven ability to find, exploit, and chain vulnerabilities across applications
Deep understanding of how modern web applications and APIs break
Hands-on experience assessing cloud environments (AWS or GCP)
Strong ability to develop and validate offensive tooling
You might also have
Adversary emulation experience: designing engagements around real threat actor TTPs
Security research in real-time 3D, game engines or SDKs, or mobile runtimes
Experience attacking CI/CD and build systems.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796320
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a SecOps Lead , you will own the core of the security operations function: detection, response, automation, and the processes that connect them. You will guide incident response from first alert through post-mortem, keeping efforts structured and stakeholders informed along the way. You will shape how the team detects, triages, and resolves, and communicate that work clearly to leadership, engineering, and customers.

This is a hands-on role with broad ownership. You should be comfortable writing a detection rule, coordinating a live incident, and walking stakeholders through a post-incident review.

Key Responsibilities

Lead Incident Response: Own the end-to-end incident response lifecycle across infrastructure and enterprise browser platform, driving investigations, coordinating responders, and ensuring timely resolution and post-incident improvements.
Own the IR Framework: Build, maintain, and continuously improve incident response processes, including runbooks, severity definitions, escalation paths, on-call procedures, and communication standards.
Drive Detection Engineering: Design, implement, and continuously improve high-fidelity detections across SIEM, EDR, cloud, and endpoint security platforms, closing visibility gaps and strengthening detection coverage.
Automate Security Operations: Build automation and AI-driven workflows that streamline triage, investigation, enrichment, and response, reducing manual effort and improving operational efficiency.
Threat Hunting & Research: Proactively hunt for threats, leverage threat intelligence, and identify emerging attack techniques relevant to modern enterprise environments.
Own Security Operations: Serve as the technical owner for Security Operations within Product Security, driving strategy, setting best practices, and continuously improving detection and response capabilities.
Partner Across Engineering: Collaborate closely with Engineering, IT, Infrastructure, and Compliance teams to embed security into new services, infrastructure changes, FedRAMP initiatives, and customer-facing security requirements.
Communicate During Incidents: Provide clear, timely communication throughout incident response, keeping technical teams, leadership, and stakeholders aligned on impact, progress, risks, and next steps.
Requirements:
5+ years of hands-on experience in Security Operations, Incident Response, or Detection Engineering.
Proven experience leading end-to-end incident response for high-severity security incidents in cloud or enterprise environments.
Strong understanding of detection engineering, threat hunting, and modern security operations, with hands-on experience using SIEM, EDR, and cloud security platforms.
Experience building and improving incident response processes, including runbooks, severity frameworks, escalation paths, and post-incident reviews.
Hands-on experience automating security operations using SOAR platforms and AI-powered workflows (Torq, Tines, or similar).
Solid understanding of AWS security fundamentals, including IAM, CloudTrail, and containerized environments (EKS is an advantage).
Strong knowledge of modern attack techniques, threat intelligence, detection methodologies, and investigation best practices.
Excellent written and verbal communication skills, with the ability to communicate effectively during incidents and present findings to both technical and non-technical stakeholders.
Experience collaborating across Engineering, Infrastructure, IT, and Compliance teams to improve security posture.
Experience mentoring engineers or leading cross-functional security initiatives is an advantage.
Familiarity with SOC2, FedRAMP, or other regulated compliance frameworks is a plus.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769437
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
11/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a Principal Cloud Security Researcher to serve as a senior technical leader within our Research team. This is a high-impact individual contributor role -- you won't manage people, but you'll shape the direction of our entire research function, mentor researchers, and act as a force multiplier across the organization.

You'll be the person who takes a vague threat signal and turns it into a detection strategy, a published finding, or a product capability. You'll operate as a trusted deputy to the research team lead, owning the most complex and ambiguous research challenges while raising the technical bar for the team.

What You'll Do
Drive Groundbreaking Research

Own and drive our most critical research initiatives end-to-end - from initial threat hypothesis through detection logic, product integration, and external publication.
Set the technical direction for cloud threat research across AWS, Azure, and GCP, identifying emerging attack surfaces and novel techniques before they become mainstream threats.
Investigate real-world cloud and SaaS security incidents, dissecting attacker tradecraft and extracting insights that evolve our detection capabilities.
Pioneer new forensic investigation techniques and detection methodologies for cloud-native and SaaS environments - pushing the state of the art, not just following it.
Be a Voice in the Community

Represent our company as a thought leader through high-quality research publications, conference presentations (BlackHat, DEF CON, RSA, fwd:cloudsec, and similar venues), and open-source contributions.
Build and maintain our reputation as a research-driven company that advances the field - not just a vendor with a blog.
Engage with the broader security research community, fostering relationships and collaborative knowledge-sharing.
Shape the Product

Bridge research and product - translate threat findings into actionable product requirements, working closely with engineering and product teams to ensure our CDR platform stays ahead of evolving threats.
Design and develop advanced detection algorithms that directly feed into our platform, closing the gap between research insight and customer protection.
Elevate the Team

Act as the team's go-to technical authority. When researchers hit a wall on complex cloud attack chains, IAM edge cases, or detection gaps - you're who they turn to.
Mentor and grow other researchers through research reviews, pair investigations, code reviews, and by setting quality standards and methodology best practices.
Influence technical decisions org-wide - contributing to architecture, tooling, and strategic research priorities.
Step in as the research team lead's deputy when needed - driving prioritization, representing research cross-functionally, and ensuring continuity.
דרישות:
8+ years in security research, threat research, or closely related fields (offensive security, detection engineering, incident response, cloud security engineering). Fewer years are fine if your depth and track record are exceptional.
Deep multi-cloud expertise - strong hands-on experience across at least two of the major cloud providers (AWS, Azure, GCP), with working knowledge of the third. You understand the IAM models, logging pipelines, APIs, and attack surfaces that matter in each.
A track record of original research - you've published meaningful technical findings through blog posts, conference talks, open-source tools, or vulnerability discoveries that moved the needle. We want someone who doesn't just consume research - you produce it.
Strong adversarial mindset and critical thinking - you think like an attacker targeting cloud infrastructure, SaaS platforms, identity systems, and Kubernetes. You can model threat scenarios, map out attack paths, and poke holes in defenses.
Ability to operate autonomously on ambiguous, high-stakes problems. You don't wait for detailed specs - you identify what matters and drive it forward.#ENGLI המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8777209
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Security Researcher to join our research group as part of a growing team developing Autopilot, an innovative product for autonomous investigation and response.
As a core member of the team, you'll go beyond research: youll research, design, and develop investigation modules that allow Autopilot to autonomously detect, investigate, and respond to advanced threats at a massive scale.
Youll analyze everything from new malware behaviors to attacker techniques and process activity in enterprise-scale networks, using data collected from across millions of endpoints. Your work will span identifying attack patterns and uncovering statistical anomalies, as well as validating that the system responds effectively to real-world attacks and APT campaigns using production data.
Key Responsibilities
Research and implement new autonomous methods for investigating and responding to targeted attackers, using large-scale, diverse security datasets
Develop and design the graph-based algorithms that power autonomous investigation and decision-making capabilities
Design automated incident response by developing reusable logic that transforms raw security data and alerts into clear, actionable insights.
Leverage graph algorithms, AI techniques, and statistical methods to mimic and scale human security analyst workflows
Conduct deep, hands-on investigations into modern malware, APTs, and complex attack flows to inform detection and response logic
Stay up to date with attacker methodologies, tools, and techniques (TTPs), ensuring our product remains effective against evolving threats
Contribute to a collaborative, fast-paced research team, helping shape our research strategy, improve processes, and continuously enhance the product.
Requirements:
5+ years of experience in security or threat research, in which you conducted deep research with actionable insights and real-world impact.
Proven experience as part of an R&D/development team, along with strong proficiency in Python programming
Intimate knowledge and understanding of attack methods and techniques over endpoints and enterprise networks
Comfortable working with large-scale datasets to extract meaningful insights through advanced analysis
Strong sense of ownership and ability to independently drive projects from concept to execution
Critical thinker who thrives both independently and in collaborative team environments
Excellent verbal and written communication skills
A cybersecurity professional driven to solve the next generation of security challenges.
Preferred Qualifications
In-depth knowledge of the inner workings of operating systems (especially Windows)
Experience working with graph DB and algorithms
Experience in statistics, advanced data studies, or machine learning.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769895
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
07/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Senior Security Researcher to join our Identity Threat Detection and Response team. In this role, you will research the evolving threat landscape and develop advanced detections to protect SAAS, Cloud, on-premises, and hybrid identities. You will focus on identifying and mitigating identity-related threats across networks, endpoints, and cloud environments, using statistical classification methods to build effective detection models and protecting customers at scale. Additionally, you will collaborate with cross-functional teams, validate detection concepts on real-world data, and continuously enhance detection capabilities to stay ahead of emerging threats.
Key Responsibilities
Research innovative methods for detecting targeted attackers operating in endpoints, networks, cloud and SAAS environments.
Simulate real-world attacks in lab environments and conduct a deep analysis of the behavior.
Develop and refine statistics-based classification algorithms and techniques to create and improve detection models.
Research specific scenarios to enhance our model's capabilities.
Collaborate within a diverse research group, improving our research processes and leading us to be a better team creating a better product.
Stay informed on the latest APTs, attacker methodologies, and TTPs to ensure our models stay ahead of emerging threats.
Requirements:
At least 5 years experience with Active Directory security and identity related attacks.
In-depth knowledge of the inner-workings of operating systems.
In-depth Knowledge of network protocols, including but not limited to Kerberos, RPC, SMB, HTTP, SMTP, DNS, DHCP, etc.
In-depth knowledge of enterprise infrastructure, including Active Directory, FW, VPN, Security products, etc.
Ability to drive and own projects from start to finish.
Independent and a team player, a critical thinker.
Preferred Qualifications
2+ years of experience with Entra ID (formerly Azure AD) or SAAS application.
At least 2 years of experience coding in Python.
Strong knowledge of SQL language.
Experience with red-teaming / pentesting of Entra ID.
Experience with machine learning, data analysis, cloud infrastructure, or security.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8772397
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Platform Security Director to lead the engineering of our security infrastructure. Your mission is to build a Security Machine that is as sophisticated as our AI. You will move us beyond traditional "defense" into a "Secure-by-Default" reality, where our multi-cloud infrastructure (AWS and Azure) is hardened, automated, and resilient by design.
Youll Own:
The end-to-end security strategy across Application Security, Cloud (AWS/Azure), and Platform layers, ensuring a Secure-by-Default framework, as measured by deployment coverage, critical vulnerability reduction, and developer adoption metrics.
A unified Security Engineering organization covering AppSec, SecDevOps, and AI Security leadership, collaboration points with adjacent teams (Infrastructure, R&D, Product Engineering), and building and mentoring a high-performing team.
Lead our Platform Security domain - from Layer 7 protections to AWS architecture, security tooling, automated risk scoring, and AI-assisted automation workflows that improve detection and remediation times.
Security controls (WAF, Rate Limiting) embedded into the SDLC and CI/CD pipelines, including mandatory security gates, artifact scanning, and automated deployment checks.
Lead our AI strategy - enabling secure use in our platform products as well as for our internal engineering usage, and scaling AI security governance and controls.
The evolution of scalable infrastructure security, including Kubernetes, containers, IAM, and Zero Trust architectures, strengthening Kubernetes and cloud security posture.
Own and execute the comprehensive Vulnerability Management program, from discovery (SAST/DAST/OSS scanning) through remediation tracking, and manage the external Bug Bounty program, with a focus on improving remediation SLAs and automation coverage.
Mature secure-by-default engineering practices across the SDLC.
Increase developer adoption of automated security tooling.
Youll Solve:
Eliminating manual bottlenecks through code-driven guardrails and frictionless developer experiences.
Securing complex production systems and multi-tenant AI architectures in cloud-native production environments, with a focus on model integrity, training data provenance, data exfiltration prevention, and minimizing unique risks associated with Large Language Models (LLMs), by applying specific AI threat models.
Operationalizing Red/Purple Team exercises, penetration testing, and the Bug Bounty program to ensure a continuous feedback loop that drives proactive risk reduction.
Youll Impact:
Support a culture where security is embedded into the foundation of engineering
Turn security into a strategic product advantage and customer trust differentiator
Improve developer experience by making the secure path the easiest path
Increase engineering velocity while strengthening platform resilience
Shape the future intersection of Security, AI, and Platform Engineering
Create scalable systems, processes, and relationships that grow with the companys innovation pace.
Requirements:
An Experienced Leader: 10+ years in Security/Software Engineering with a track record of scaling departments in high-growth R&D environments.
A Technical Architect: Deep expertise in AWS/Kubernetes and modern platform security practices, Infrastructure-as-Code (Terraform/Crossplane), and secure coding (Java/Python/TypeScript).
A Systems Thinker: You have a proven track of building security machines from the ground up, with a people-first mindset, technology, and process.
Your work ensures that as our company defines the future of AI-driven revenue, we do so on the most secure and resilient platform in the industry, building customer trust and promoting responsible AI adoption.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8788377
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a passionate Lead or Senior Offensive Security Engineer for our growing Offensive Security Automation team. This hands-on offensive security position requires a cyber security professional whose primary focus is to perform security assessments and vulnerability research using internal AI tools using frontier models, with a focus of designing and developing the AI automation and autonomous harnesses together with the team.
This is a role for someone who can perform offensive security testing at scale, combining deep security expertise with the judgment to direct and improve AI-driven tooling.

Key Responsibilities:

Offensive Security & Vulnerability Research (primary)

Perform security assessments and vulnerability research across web applications, APIs, and cloud/hybrid infrastructure, using internal AI tools and frontier models to scale coverage and depth that you will develop.

Make sure our internal solution can perform exploitation, vulnerability chaining, business logic and authorization abuse, privilege escalation, and lateral movement, beyond what automated tooling alone can find.

Run end-to-end engagements: scoping, execution, reporting, and remediation guidance.

Discover systemic/architectural weaknesses, not just isolated bugs, and drive secure-by-default fixes.

Partner with engineering, security architecture, and detection & response teams to close root causes and validate control effectiveness.

Produce high-quality technical reports with clear exploitation paths and prioritized remediation.


AI Automation & Autonomous Harness Design (secondary)

Develop the automation and autonomous harnesses that direct frontier models to perform offensive security testing continuously and at scale.

Design agent-based workflows that reason over large data, plan for risk signals, business logic and execute multi-step offensive testing that will adapt based on results, recon, hypothesis ranking, chaining of bugs exploitation, AI-Driven assessments, and reporting.

Establish human-in-the-loop checkpoints so automation scales offensive coverage without sacrificing safety or precision.

Translate your own tradecraft into reusable, explainable automation that the team can run and build on.
Requirements:
Required Qualifications:

6+ years (Senior) / 8+ years (Lead) hands-on offensive security experience such as pentesting, red teaming, or app/security research, with proven complex engagement delivery.

Deep, must-have vulnerability knowledge in cloud and web application security: OWASP Top 10+ vulnerability classes, identity/authz attack vectors, and cloud/hybrid attack surfaces.

Hands-on experience using internal AI tools and frontier models to perform or accelerate security testing, not just conceptual familiarity!

Software engineering fundamentals: System design, API integration, working with distributed services and technologies.

Ability to write custom scripts/tooling/payloads and contribute to building automation and autonomous harnesses including prompt engineering.

Excellent written and verbal communication skills.


Preferred Qualifications:

Experience with agentic frameworks, prompt optimization, agent evaluation, or lightweight model fine-tuning.

Published security research, CVEs, or conference talks.

Familiarity with MITRE ATT&CK/ATLAS and offensive AI/ML attack surfaces (prompt injection, agentic privilege abuse).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798562
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a Product Security Architect , you will be responsible for designing, shaping, and evolving the security architecture of the Enterprise Browser. This role combines deep technical expertise with strategic thinking, focusing on proactively reducing risk through secure design, architectural reviews, and close collaboration with engineering and product teams. You will play a key role in defining security standards, guiding threat modeling efforts, and ensuring security is built into the product from its earliest design stages throughout its production lifecycle and evolutions.

Key Responsibilities:

Security Architecture & Design: Define and own product security architecture across browser components, OS integrations, and enterprise-facing features, ensuring security-by-design principles are consistently applied.
Threat Modeling & Risk Assessment: Lead threat modeling efforts for new features and architectural changes, identifying attack surfaces, trust boundaries, and mitigation strategies in collaboration with engineers and product leaders.
Security Reviews & Guidance: Perform architecture and design reviews, providing actionable security recommendations and guiding teams on secure implementation patterns.
Vulnerability & Attack Surface Analysis: Proactively assess systemic risks, design flaws, and high-impact vulnerability classes relevant to browsers and enterprise platforms.
Security Standards & Enablement: Develop and maintain security guidelines, patterns, and reference architectures; support teams in adopting secure coding and design practices.
Cross-Functional Collaboration: Partner closely with engineering, product, and product security leadership to balance security, usability, and performance tradeoffs.
Security Strategy & Innovation: Track emerging threats, exploitation techniques, and industry trends to continuously improve long-term security posture.
Requirements:
Strong background in security architecture, secure systems design, or product security engineering.
Deep understanding of browser security models, OS security primitives, or application-level security.
Experience conducting threat modeling, design reviews, and architectural risk assessments.
Proficiency in one or more programming languages (e.g., Python, JavaScript, C/C++, Go) with the ability to reason about implementation-level risk.
Solid knowledge of common vulnerability classes and systemic security failures (e.g., sandbox escapes, RCE, privilege escalation).
Ability to translate complex security concepts into clear guidance for engineering teams.
Security research or vulnerability research experience is a strong advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769489
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
25/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
our company builds the real-time 3D platform that powers games and interactive experiences, along with tools used across ads, automotive, aerospace, architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top of it, safe for millions of creators and their users.
We are seeking a Senior Application Security Engineer with profound expertise in application security. In this role, you will execute fundamental AppSec tasks, including threat modeling, secure design reviews, code evaluation, and vulnerability management, leveraging both manual methods and advanced AI tooling. You will also help secure the AI systems our company itself is building, including agentic tools and AI-assisted development workflows.
You will work directly with engineering teams across the US and EMEA.
What you will do
Lead threat modeling, secure design reviews, and penetration testing for our company products and services, from the engine and editor to cloud services, APIs, and internal platforms.
Perform deep code review and manual testing on high-risk systems, using AI-assisted review processes and covering areas automated tooling cannot fully reach.
Build and operate security automation. Use and extend AI-assisted tooling for continuous code review, finding triage, and automated penetration testing, and step in where human judgment is required.
Secure our company's AI and agentic systems. Assess AI-native products, LLM integrations, and agent workflows for the risks specific to them.
Partner with engineering teams to drive remediation, turning recurring findings into guardrails, secure defaults, and paved paths.
Investigate and respond to application security incidents, including root cause analysis and durable corrective action.
Contribute to our company's secure development lifecycle and to compliance work.
Requirements:
5+ years in application security, with a track record on complex, large-scale systems.
Strong command of secure coding and common vulnerability classes (OWASP Top 10 and beyond)
Hands-on secure development experience across several languages.
Practical penetration testing, security assessment, and vulnerability management experience with standard tooling (SAST, DAST, SCA, and manual techniques).
Experience with Cloud security (GCP, AWS, or Azure).
Working knowledge of authentication, authorization, cryptography, and secure architecture patterns.
Clear technical communication for both engineers and non-technical partners across regions.
Preferred Qualifications
Experience in the technology, gaming industry or Ad tech.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796309
סגור
שירות זה פתוח ללקוחות VIP בלבד