דרושים » אבטחת מידע וסייבר » Cybersecurity Architecture Leader 2540

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Merkaz
We are seeking a highly skilled and experienced cybersecurity architecture to lead and manage cybersecurity protection initiatives within public sector organizations. The ideal candidate will play a pivotal role in enhancing cybersecurity resilience by developing and implementing professional guidelines and assessing organizational BCP against emerging threats.
עוד על התפקיד
Lead and manage cybersecurity protection efforts across public sector entities.
Develop and write high-level design (HLD) documents and professional guidelines to improve cybersecurity resilience.
Build and maintain working relationships with key contacts in public sector organizations and regulatory offices.
Analyze and present the cybersecurity readiness to the organizations.
Requirements:
Minimum 3 years of experience in one of the following roles: cybersecurity methodologist, cybersecurity implementer, security architect, cybersecurity incident manager, or a managerial role in cybersecurity.
Proven ability to write high-level design (HLD) documents and professional guidelines.
High communication and presentation skills, with the ability to deliver messages and lead processes effectively, including presenting to senior management.
Experience working with telecommunications companies and government entities- advantage.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8763911
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
חברה חסויה
Location: Herzliya
Job Type: Full Time and Hybrid work
we are looking for a cyber architect team leader to join our crew!
The Cyber architecture team is part of professional services delivery department and is dedicated to helping drive customers cyber security maturity forward. This includes both conducting enterprise grade organizations white-box maturity assessments, reviewing design issues or security controls configuration as well as offering relevant mitigations to identified risk during a penetration test, executed by red teamers.
As a cyber architect team leader, you will be responsible for overseeing the teams activities, validating engagements quality, creating new services and initiatives which will help our customers advance their cyber security program and helm complexed assessments and mitigations discussions with our clients.
Responsibilities:
Lead and mentor a team of cyber experts, providing guidance and support on executing activities with clients.
Preform architecture reviews on designed or deployed environments, identifying security flaws and recommending mitigations plans.
Collaborate with other departments to drive forward both product and services.
Determine KPIs to track teams performance.
Create processes to validate delivery quality.
Escort, evaluate and improve our clients security posture by elevating their infrastructures resilience and implement best-practice organizational procedures.
Escort mitigation plans and design practical implementations for security issues.
Research and advocate for new security solutions and technologies.
Requirements:
Proven experience (3+ years) leading a team of security architects or senior cybersecurity professionals, driving technical excellence, team development, architectural governance, and successful client engagements.
At least 5 years of Hand-on experience with securing large organizational networks, including security controls, OS hardening, network devices security etc.
Deep understanding of cyber security frameworks e.g., NIST CSF 2.0, ISO 27001, NIS2 directive, etc.
Experience in consulting services and risk assessments.
Experience with securing cloud environments - AWS, Azure, GCP.
Knowledge of security controls e.g., EDR/XDR, DLP, SASE, AI security etc.
Experience with implementing security monitoring procedures & systems (SOC, SIEM, SOAR)
Experience with Microsoft IT infrastructure i.e., AD, Entra-id, M365 productivity suite, GPO, protocols
Experience as a Deputy CISO/CISO - advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8793453
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Rehovot
Job Type: Full Time
The cyber & information security department is looking for a Security Solutions Architect to support our business and drive its growth.
As a Security Solutions Architect, you will play a pivotal role in information security department, contributing to the overall success of company. This position offers an exciting opportunity for individuals who are passionate about field and are eager to make a meaningful impact through responsibilities.
In this role, you will work closely with the IT, R&D, finance, and other departments in the company.
In this job you will have the opportunity to make big impact on the security level of the company.
Responsibilities
What will you be doing:
Develop and lead information security strategies by defining and implementing security policies, procedures, system hardening, incident response, disaster recovery, and addressing emerging cybersecurity threats and best practices.
Ensure secure project architectures by overseeing project and system designs to meet security requirements and integrating risk analysis.
Collaborate across teams by working with development, infrastructure, and security teams to resolve issues and implement improvements.
Act as a security design authority by reviewing, approving, and providing security sign‑off on solution architectures, including threat models, trust boundaries, and architecture decision records.
Participate in strategic meetings by engaging in project steering committees and regular discussions to drive security initiatives.
Conduct security reviews and risk assessments by assessing product features, technologies, and applications to meet security standards.
Plan and design security solutions by developing solutions to identify, protect, detect, respond, and recover from cyber threats.
Requirements:
Experience with security methodologies
Practical experience in the architecture of business processes and the integration of guidelines and information security technologies into them
Familiarity with types of attacks and relevant security solutions
Familiarity with SSDLC and DevSecOps processes
Knowledge of cloud security vendors and solutions.
Translating risk into requirements.
That special something you bring in:
Strong leadership skills, with the ability to lead cross-functional teams and communicate effectively with both technical and non-technical stakeholders.
Excellent communication skills and the ability to work independently
Verbal and writing skills in English.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8775910
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
Location: Herzliya
Job Type: Full Time and English Speakers
we are seeking a Cybersecurity Architect (GRC & Risk) to join our cybersecurity architecture team. In this role, you will lead security governance, risk, and control assessments, conduct third-party due diligence, support maturity assessments, and drive mitigation and architectural review processes. Youll work closely with CISOs, security leaders, engineering teams, and customers to develop risk-focused methodologies and improve security frameworks. This position is best suited for candidates with a technical GRC, risk, or security assessment background who excel in analysis, interpretation, and structuring of security information.
Responsibilites:
Lead customer third‑party security due diligence assessments.
Lead mitigation workshops to translate penetration test and assessment findings into prioritized remediation workplans.
Perform security maturity assessments, including reviews of organizational policies, standards, procedures, and governance practices, aligned with the NIST CSF 2.0 cybersecurity framework.
Develop and refine security methodologies, processes, and architectural guidance.
Maintain internal documentation and ensure alignment between frameworks, processes, and practical implementation.
Analyze technical findings and map them to governance, risk, and control gaps.
Produce clear, structured reports and executive‑ready summaries for technical and non‑technical audiences.
Requirements:
3-4 years in cybersecurity GRC, IT risk, compliance, audit/assurance, or related process‑oriented security roles.
Strong understanding of governance, risk management, and operational processes.
Familiarity with cybersecurity frameworks (NIST CSF, ISO 27001 concepts), risk assessment, mitigation planning, and third‑party risk management.
Basic conceptual understanding of cloud/SaaS shared responsibility models.
Ability to communicate technical issues in business‑aligned language.
Hands-on experience with security controls - an advantage.
Strong writing, communication, and facilitation skills.
Comfortable collaborating with internal stakeholders and external customers.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8793444
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/08/2026
חברה חסויה
Location: Hod Hasharon
Job Type: Full Time
We are looking for a CISO to turn expertise, initiative, and bold thinking into real impact on the next generation of AI-driven financial crime detection.



As CISO, you will define and execute global security strategy across both internal and product environments, serving as the primary security authority in front of customers, regulators, and auditors.



If you combine strong security leadership and cloud-native technical expertise with deep understanding of enterprise sales cycles and regulatory standards, and if you are motivated by directly influencing customer trust and enabling the world's largest financial institutions to adopt cutting-edge AI-driven solutions with confidence, could be your next challenge.



Responsibilities:

Define and lead a comprehensive, business-aligned security program that supports growth while mitigating global risk.
Act as the primary interface with customer CISOs, auditors, and regulators, leading security discussions, due diligence processes, and enabling successful deal closures.
Partner with Engineering and DevOps to secure our cloud-native architecture across AWS, Azure, or GCP, including Kubernetes environments, ensuring enterprise-grade resilience.
Embed security-by-design across the development lifecycle, including AI and ML models and data pipelines.
Own and drive compliance with global standards including ISO 27001, SOC 2, NIST, GDPR, and DORA.
Oversee modern security tooling and practices across IAM, SIEM, DLP, CASB, CSPM, and emerging AI security domains.
Lead incident response, business continuity, and cyber resilience planning, including executive-level simulations and ransomware readiness.
Own vendor risk management and ensure end-to-end security resilience across the ecosystem.
Requirements:
Proven experience in a CISO or equivalent senior security leadership role, preferably within fintech, SaaS, or cybersecurity environments.
Strong hands-on understanding of cloud security architecture and Kubernetes.
Deep knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, GDPR, and DORA.
Familiarity with modern security tooling including IAM, SIEM, DLP, CASB, and CSPM. Experience or strong interest in AI security is a significant advantage.
Proven ability to influence senior leadership and collaborate cross-functionally with R&D, Product, Legal, and Business teams.
Strong experience working directly with Tier-1 financial institutions, including CISOs, auditors, and regulators.
CISSP, CISM, or CISA are preferred certifications
Excellent English communication skills, with the ability to translate complex security topics into clear business impact.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8776052
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Join our company's Threat Prevention group and help shape the next generation of cyber security technologies.
We are looking for a highly technical and passionate Team Leader to lead the development of advanced Threat Prevention solutions, including next-generation security engines powered by AI and machine learning.
In this role, you will lead a team of engineers responsible for designing, building, and scaling innovative security technologies that protect organizations against modern cyber threats. You will combine strong technical leadership with hands-on development, working closely with architects, researchers, product teams and customers to deliver cutting-edge security capabilities.
Work on core technologies that protect millions of users worldwide.
Lead the development of next-generation Threat Prevention and AI-based security engines.
Influence product strategy, architecture, and innovation.
Be part of one of the industry's leading cybersecurity organizations.
Key Responsibilities
Lead and mentor a team of talented software engineers
Drive the design and development of advanced Threat Prevention technologies and security engines
Lead the development of new AI-powered detection and prevention capabilities
Own the team's technical roadmap, architecture, and execution
Take an active hands-on role in the design and implementation of core system components
Build highly scalable, high-performance backend solutions focused on security, reliability, and operational excellence
Drive innovation and introduce new technologies, methodologies, and security approaches.
Develop backend components using C++, C, and Python.
Requirements:
2+ years of experience leading software development teams
Extensive experience designing and developing large-scale software systems
Solid networking knowledge
Experience in cybersecurity, threat prevention, network security, or related domains - a significant advantage
Self-driven, innovative, and passionate about technology.
Very high technical competence with approximately 50% hands-on involvement.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785664
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Herzliya
Job Type: Full Time
We are seeking a Security Architect to drive cross-PR&D security alignment, lead complex security design reviews, and shape the security architecture of our strategic cross-technology initiatives. This role serves as the senior technical security authority across our R&D ecosystem- partnering with product, platform, and infrastructure teams to embed security into every layer of our Secure Software Development Lifecycle (SSDLC) and to guide us toward a robust, modern, and secure architecture.

The ideal candidate is highly professional, demonstrates a can-do attitude, and brings the seniority and presence to engage R&D architects and senior stakeholders as a peer. You will need strong technical depth, excellent communication skills, and the ability to translate complex security considerations into clear business and engineering decisions across a diverse range of stakeholders.

What you'll do:
Drive cross-PR&D alignment of the Secure Software Development Lifecycle (SSDLC), establishing consistent standards, controls, and practices across all engineering groups.
Lead complex security design reviews for new technologies, systems, services, and strategic cross-tech initiatives.
Define and own the security architecture for high-impact cross-team initiatives, ensuring security is embedded from the earliest design stages.
Serve as the security counterpart to PR&D architects- representing security in architecture forums, design discussions, and strategic technology decisions.
Partner with DevOps, Infrastructure, Platform, and R&D teams to integrate security into CI/CD pipelines, infrastructure-as-code, and shared platform services.
Perform threat modeling and architectural risk assessments to identify and mitigate weaknesses before they reach production.
Develop and maintain security guidelines, reference architectures, and best practices that scale across the organization.
Evaluate and recommend security tools and technologies to continuously strengthen AppsFlyers security posture.
Stay current on emerging threats, vulnerabilities, and architectural patterns, translating them into actionable improvements to our security strategy.
Requirements:
What you have:
7+ years of experience in security architecture, cloud/infrastructure security, application security, or DevSecOps roles.
Proven experience leading security design reviews and architecture work across multiple R&D teams or domains.
Strong understanding of SSDLC practices and how to scale them across a large engineering organization.
Deep knowledge of cloud-native architecture and services (AWS, GCP).
Hands-on experience securing CI/CD pipelines, containers, and infrastructure-as-code (e.g., Terraform, Kubernetes).
Deep knowledge of network and identity security concepts, such as zero trust, IAM, and secrets management.
Proven experience working with product and R&D teams performing architecture.
Experience working in a SaaS product company at scale.
Excellent communication skills, with the ability to translate complex technical risks into clear business impact and to influence senior R&D stakeholders.
A proactive mindset, strong problem-solving ability, and a passion for designing secure, scalable systems.
Strong collaboration skills and the ability to drive change across cross-functional teams.

Bonus Points:
Experience in high-scale distributed SaaS environments.
Certifications such as GCP or AWS Certified Security Specialty, OSCP or OSWE- Advantage
Being introduced by an AppsFlyer team member.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8788772
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.
As a Senior Staff Software Engineer on the Agent Platform Detection team, you will be the technical visionary responsible for defining and evolving the architecture of our detection, triage, and response platform. You will lead the design and execution of backend systems and SaaS services that power alert propagation, alert lifecycle management, and response capabilities at extraordinary scale. Your technical leadership will bridge the gap between long-term architectural strategy and high-velocity product delivery, influencing how detection and response workflows are built and operated across platform.
Requirements:
Extensive Backend Expertise: 12+ years of professional experience in backend development, with deep production-level mastery of Golang, Java, Python, or similar languages, and a strong track record of building and operating high-scale distributed services.
Platform Thinking: Proven experience building and evolving platforms - not just features - with a focus on API design (gRPC, REST), service boundaries, multi-tenancy, and shared infrastructure in a high-scale SaaS environment.
Full-Stack Capability: Practical frontend experience with React and TypeScript, with the ability to own production UI components and lead the frontend direction for a backend-heavy product area.
Data & Distributed Systems: Expert-level knowledge of RDBMS (PostgreSQL), query optimization, and extensive experience with high-throughput messaging systems such as Kafka and distributed caches such as Redis.
Cloud-Native Proficiency: Deep experience with AWS/GCP, Kubernetes, Docker, and modern CI/CD patterns in a hyper-scale SaaS environment.
Strategic Communication: Ability to articulate complex technical trade-offs to both technical and non-technical stakeholders, including Product Management, Directors, and VPs.
Cybersecurity Context: (Bonus) Familiarity with security event processing, alerting systems, detection and response workflows, or endpoint and security products in a high-growth cybersecurity context.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8774182
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
חברה חסויה
Location: Herzliya
Job Type: Full Time and Hybrid work
we are looking for a security architect to join our team! 
The cyber architecture team is part of professional services delivery department and is dedicated to helping drive customers' cybersecurity maturity forward. as a security architect you would be conducting enterprise level organizations' white-box risk assessments, reviewing design issues or security controls configuration, and offering relevant mitigations to identified risks during penetration testing, executed by red teamers.  
Responsibilities:
Perform security maturity assessments, including reviews of organizational policies, standards, procedures, and governance practices, aligned with the NIST CSF 2.0 cybersecurity framework.
Review designed or deployed environments, identifying security flaws and recommending mitigations plans
Review Implementation of technical security controls, identify gaps and offer practical mitigations.
Escort, evaluate and improve our clients security posture by elevating their infrastructure resilience and implement best-practice organizational procedures
Escort mitigation plans and design practical implementations for security issues e.g., firewall policies review, segmentation & segregation recommendations, Microsoft AD-tier Model implementation etc.
Research and advocate for new security solutions and technologies
Requirements:
3+ years of hands-on experience with securing large organizational networks, including security controls, OS hardening, network devices security, etc.
Strong understanding of governance, risk management, and operational processes.
Familiarity with cybersecurity frameworks (NIST CSF, ISO 27001 concepts), risk assessment, mitigation planning, and third‑party risk management.
Significant experience in at least five subjects from the following list:
Vast knowledge and expertise in cyber-security IT systems and cloud infrastructure
Deep understanding of Microsoft IT on-prem and cloud infrastructure, e.g., Entra-id, Office365, AD, GPO, protocols.
Practical experience with cloud environments - AWS, Azure, GCP- A significant advantage
Practical experience in consulting services and risk assessment
Practical experience with security configuration and maturity assessment
Knowledge of security controls, e.g., AV, EDR/XDR, DLP, Device control, etc.
ZTNA design & deployment experience.
Experience with implementing security monitoring procedures & systems (SOC, SIEM, SOAR)
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8793449
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Petah Tikva
Job Type: Full Time
Our Radar Team develops cutting-edge radar technology for autonomous driving (AV) and advanced driver-assistance systems (ADAS). We are looking for a Cyber Security Architect to lead the design and implementation of robust embedded security solutions that protect our radar systems from cyber threats.
In this role, you will define security architecture for radar hardware, embedded software, and communication interfaces, ensuring compliance with automotive cybersecurity standards and safeguarding our mission-critical sensing technology.
Youll be part of a team shaping the future of autonomous driving. Our radar technology is a critical component in delivering safe, reliable, and intelligent mobility solutions. Youll work on innovative projects in a collaborative environment, with the opportunity to influence security strategy at a global scale.
What will your job look like?
Security Architecture Design - Develop and maintain end-to-end security architecture for radar systems, including hardware, firmware, and software components.
Threat Modeling & Risk Assessment (TARA) - Perform Threat Analysis and Risk Assessment for radar components, software modules, and communication channels; identify vulnerabilities and design mitigation strategies.
Secure Communication - Implement encryption, authentication, and integrity checks for radar data transmission between hardware and software layers.
Secure Software Design - Define and enforce security controls for APIs, middleware, and integration points between radar systems and other vehicle subsystems.
Compliance & Standards - Ensure radar systems meet ISO 21434, UNECE WP.29, and other relevant automotive cybersecurity regulations.
Collaboration with R&D - Work closely with radar engineers, embedded software developers, and system architects to embed security into the design process.
Incident Response Support - Provide architectural guidance during security incidents involving radar systems.
Technology Evaluation - Assess and recommend security tools, frameworks, and methodologies for radar-specific applications.
Requirements:
B.Sc. or M.Sc. in Computer Science, Electrical Engineering, Cybersecurity, or related field.
7+ years of experience in cybersecurity roles, with at least 3 years in architecture or senior design positions.
Proven experience securing embedded systems - hardware connections, software modules, and real-time communication protocols.
Strong background in system architecture - ability to design and analyze complex, multi-component systems and ensure security is integrated at every layer.
Strong knowledge of cryptography, secure boot, firmware integrity verification, and secure API design.
Excellent communication and documentation abilities.
Strong problem-solving mindset and ability to work in cross-disciplinary teams.
Experience in radar system development or RF engineering - Advantage
Experience with automotive cybersecurity standards (ISO 21434, UNECE WP.29) - Advantage
Understanding of CAN, Ethernet, and automotive communication protocols - Advantage
Knowledge of AI/ML security considerations - Advantage
Certifications such as CISSP, CCSP, or CEH - Advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8763546
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly skilled and hands-on Application Security Lead to take ownership of our product and infrastructure security. Reporting directly to the CISO with a dotted line to the CTO, you will act as the critical bridge between our Security and Engineering teams, driving a robust "security-first" culture.
While this role encompasses both application and infrastructure security, our primary focus is on the Application Security domain. You will lead our transition towards a mature DevSecOps organization, ensuring that security is seamlessly embedded into every phase of our SDLC without compromising delivery speed.
Key Responsibilities:
Application Security & Secure Engineering:
Secure SDLC Integration: Embed security practices throughout the entire SDLC, from initial design and planning to deployment and maintenance.
Threat Modeling & Architecture: Lead threat modeling (e.g., STRIDE) and architectural reviews for high-risk features like authentication, PII, and payments.
AppSec Tooling & Automation: Integrate and manage automated security scanning (SAST, SCA, DAST) within CI/CD pipelines to ensure code integrity seamlessly.
Mobile & API Security: Enforce least-privilege models for API configurations. Lead security initiatives specifically tailored to mobile environments (iOS/Android), protecting our core mobility platform.
Offensive Security & Pentesting: Orchestrate internal red teaming and external penetration tests for web and mobile applications. Manage Vulnerability Disclosure Programs (VDP) / Bug Bounties.
Developer Empowerment & DevEx: Collaborate with developers to provide automated tools, coding guidelines, and frictionless guardrails for secure-by-design development, ensuring security acts as an enabler, not a blocker.
Incident & Vulnerability Management: Act as the technical escalation point for application security incidents, leading detection and recovery efforts, while prioritizing vulnerabilities across the product suite for timely remediation.
Cloud & Infrastructure Security:
Cloud & Network Posture: Manage cloud security posture (CSPM) across AWS/GCP and oversee broad network security measures, including WAF, Bot management, and environment segmentation.
Pipeline & Secrets Management: Secure the CI/CD infrastructure against tampering and enforce robust secret management and secure repository controls across the organization.
Resilience & Recovery: Manage disaster recovery (DR) and business continuity planning for production environments.
Governance, Culture & Compliance:
DevSecOps Strategy: Lead the strategic evolution of DevOps into a mature DevSecOps model, aligning with industry frameworks like OWASP SAMM and NIST SSDF.
Metrics & Measurement: Define and track key security metrics (e.g., MTTR, vulnerability density) to measure and improve program effectiveness.
Security Champions: Build and mentor a Security Champions program within R&D to scale security knowledge and foster a grassroots culture.
Compliance & Privacy: Ensure continuous compliance with PCI-DSS, ISO27001, and GDPR, championing privacy-by-design principles across all user data and R&D operations.
Requirements:
5+ years of proven experience with a strong emphasis on Application Security, Product Security, and Developer interaction. Cloud/Infrastructure security experience is highly valued but secondary to AppSec expertise.
Hands-on experience with AppSec tooling across the CI/CD pipeline, mobile application security (iOS/Android), and robust API security management.
Solid understanding of cloud architectures (AWS/GCP), secret management, and security posture tools.
Deep understanding of OWASP SAMM, NIST, Threat Modeling (STRIDE), and regulatory standards (PCI-DSS, GDPR).
Exceptional communication skills with the ability to bridge the gap between engineering, C-level executives (CISO/CTO), and security teams to embed a security culture seamlessly.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8788311
סגור
שירות זה פתוח ללקוחות VIP בלבד