דרושים » אבטחת מידע וסייבר » Staff InfoSec Engineer - Endpoint, Identity & AI Security

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 9 שעות
Location: Petah Tikva
Job Type: Full Time
Lead the design, implementation, and management of security controls across three critical domains: Endpoint Security, Identity & Access Management, and AI Security, safeguarding Palo Alto Networks' global infrastructure with a Zero Trust approach.
Key Responsibilities
Design, build and implement enterprise security capabilities to protect Palo Alto Networks global infrastructure
Develop strategies to maintain security architecture, prevent unauthorized access, and ensure identity governance across the enterprise
Establish, maintain, and enforce hardened security baselines for Endpoints, Identity, and AI tools
Lead AI security governance, define controls, policies, and threat models for safe enterprise adoption of AI tools and models
Evaluate and secure AI-related data flows, including prompt injection risks, model access controls, and data exfiltration vectors
Implement and manage Identity Security, Endpoint security, and Access Management capabilities with a Zero Trust approach
Design and enforce endpoint hardening strategies across managed and unmanaged devices, endpoint DLP controls, drive mobile security and BYOD posture management
Be the first customer for Palo Alto Networks products and provide practitioner feedback to the product teams
Perform threat modeling and security architecture reviews for complex enterprise systems, infrastructure, and third-party integrations
Work with Security Operations team to investigate identity and endpoint breach incidents, identify root cause and provide appropriate remediation or risk reduction plans
Collaborate with legal and governance, risk and compliance (GRC) teams to ensure adherence to Identity and data protection regulations
Evaluate ongoing practices and procedures, technical documentation, and diagrams for appropriate security measure maturity and effectiveness
Lead hands-on POCs and technology evaluations with rigorous benchmarks; champion adoption with a collaborative team mindset
Be a strong thought leader and clearly communicate and build support for your ideas.
Requirements:
8+ years of hands-on experience in enterprise security engineering, spanning identity & access management, endpoint security, and/or cloud security, with a Zero Trust mindset
Deep understanding of the AI security domain, trends, and risks, with hands-on experience securing AI models, LLM integrations, and implementing enterprise security controls
Strong experience in designing and securing Enterprise Identity architecture, including Identity Providers (Okta, Ping, Entra ID), Access Governance & IGA (SailPoint, Saviynt), and directory services (Active Directory, RedHat)
In depth knowledge of public cloud architecture, such as GCP, AWS and Azure, with focus on securing Identities in the cloud environments
Hands-on experience with endpoint security platforms like Palo Alto Networks XDR, device management (Microsoft Intune, JAMF), and endpoint DLP
In depth knowledge of threat model, application security assessments, network security, encryption, authentication and authorization
Proficiency in programming / scripting / automation (e.g. Python, Golang, or Powershell) for security engineering workflows
Bachelor's degree or equivalent training and education.
Preferred Qualifications
Experience in security engineering related to identity & access, data security, network security, intrusion prevention, monitoring, analytical and correlation tools a PLUS
Certification in any of the following is a plus: Google Cloud Architect; AWS Cloud Architect, CISSP-ISSEP - Sec. Eng. Professional, GIAC Certified Enterprise Defender (GCED), CCSP.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8782301
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בSQLink
סוג משרה: משרה מלאה
ארגון בריאות באזור המרכז מגייס Cloud Security Engineer
התפקיד כולל: עבודה עם מערכות אבטחה בענן, אחריות על זמינות, אמינות וביצועי פתרונות אבטחה בסביבות Cloud, ניהול מעטפת האבטחה במספר Landing Zones, עבודה עם תהליכי CI/CD מאובטחים ו-IaC באמצעות Terraform, הובלת מערכות אבטחה בקטגוריות CNAPP, SAST ו-SCA, שותפות בתכנון Landing Zones חדשים ובפרויקטי מעבר לענן, ועבודה מול צוותי Platform, DevOps, סייבר וארכיטקטורה ועוד.
דרישות:
- 7 שנות ניסיון באבטחת מידע, מתוכן לפחות 3 שנות ניסיון בענן ציבורי
- ניסיון בעבודה עם ארכיטקטורות Cloud בארגוני Enterprise ורכיבי אבטחה כגון
ניסיון עם AZURE - יתרון
- ניסיון בכתיבת תשתיות IaC באמצעות Terraform או כלי מקביל
- ניסיון באבטחת Kubernetes (AKS / OpenShift), כולל Network Policies,
RBAC, Secrets Management, Image Scanning ו-Admission Control
- תואר במדעי המחשב/ הנדסת מחשבים / מערכות מידע /יוצא יחידות צבאיות/קורסים
מתקדמים בתחום המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8777282
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/07/2026
Location: Petah Tikva
Job Type: Full Time and Hybrid work
We are looking for a Staff Security Engineer to be a core contributor on this team.
Security R&D operates in two complementary modes: open contribution to product engineering - writing code alongside product teams where security expertise adds value - and developing its own security capabilities, including internal tooling, externally facing product features, AI-powered security automation, and third-party integrations.
This is a new team being stood up in Petah Tikva, Israel, co-located with our AI Security Research team. You will help shape the teams engineering practices and technical foundation from day one.
This role reports to the Sr. Engineering Manager, Security R&D.
What You Will Do
Build Security Capabilities:
Design and develop security tooling, automation, and platform services that operate at our enterprise scale.
Contribute code directly into our viceNow product engineering codebases, embedding security capabilities where they have the highest impact.
Build AI-powered security automation by integrating in-house models and third-party services into production workflows.
Leverage our platform - Agent Framework runtime, ACL enforcement, data layer, and workflow engine - to create security capabilities that external vendors cannot match.
Requirements:
To be successful in this role, you have:
8+ years of professional software engineering experience building production systems at scale.
Bachelors degree in Computer Science, Engineering, or a related technical field.
Strong hands-on proficiency in Python and Java. You write production code daily and take pride in software craftsmanship.
Solid foundation in distributed systems, cloud-native architectures, and building services that meet enterprise requirements for scalability, reliability, and performance.
Experience working in collaborative engineering environments, contributing to shared codebases with high code quality standards.
Interest in or exposure to security engineering concepts - application security, infrastructure security, identity systems, or trust & safety. A security mindset is valued; deep security expertise can be developed on the team.
Curiosity about AI/ML and next-generation AI technologies. You dont need to be an AI expert, but you should be excited about building at the intersection of security and AI.
Preferred:
Experience with security tooling development, SSDLC automation, or building security features into a product.
Familiarity with container/Kubernetes environments, cloud security, or infrastructure-as-code.
Exposure to AI/ML pipelines, LLM integration, or agentic frameworks.
Experience in a SaaS or platform company building multi-tenant enterprise software.
Experience working in a globally distributed engineering team.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8751327
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/07/2026
Location: Petah Tikva
Job Type: Full Time and Hybrid work
We seek a Senior Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.
The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.
As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.
Key Responsibilities:
Triage and Resolve Bug Bounty Reports:
Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition.
Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed.
Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues.
Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom.
Propose remediations, or design them with engineering, and verify the fix resolves the issue.
Assign and defend severity ratings using the program's severity framework.
Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure.
Own Researcher and Stakeholder Communication:
Act as our primary technical point of contact for bug bounty researchers across the full lifecycle of a report.
Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible.
Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk.
Mentor the Team and Raise Triage Standards:
Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication.
Set and maintain the bar for triage quality and strengthen program practices over time.
Requirements:
8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.
Expertise in:
Common web and application vulnerability classes and exploitation techniques.
Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity.
Coordinated vulnerability disclosure.
Code and development fluency:
Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests.
Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code.
Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC.
Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research.
Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8751365
סגור
שירות זה פתוח ללקוחות VIP בלבד