דרושים » אבטחת מידע וסייבר » Senior Application Security Engineer

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 58 דקות
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a Senior Application Security Engineer with profound expertise in application security. In this role, you will execute fundamental AppSec tasks, including threat modeling, secure design reviews, code evaluation, and vulnerability management, leveraging both manual methods and advanced AI tooling. You will also help secure the AI systems Unity itself is building, including agentic tools and AI-assisted development workflows.

You will work directly with engineering teams across the US and EMEA.

What you will do
Lead threat modeling, secure design reviews, and penetration testing for Unity products and services, from the engine and editor to cloud services, APIs, and internal platforms.

Perform deep code review and manual testing on high-risk systems, using AI-assisted review processes and covering areas automated tooling cannot fully reach.

Build and operate security automation. Use and extend AI-assisted tooling for continuous code review, finding triage, and automated penetration testing, and step in where human judgment is required.

Secure AI and agentic systems. Assess AI-native products, LLM integrations, and agent workflows for the risks specific to them.

Partner with engineering teams to drive remediation, turning recurring findings into guardrails, secure defaults, and paved paths.

Investigate and respond to application security incidents, including root cause analysis and durable corrective action.

Contribute to secure development lifecycle and to compliance work.
Requirements:
5+ years in application security, with a track record on complex, large-scale systems.

Strong command of secure coding and common vulnerability classes (OWASP Top 10 and beyond)

Hands-on secure development experience across several languages.

Practical penetration testing, security assessment, and vulnerability management experience with standard tooling (SAST, DAST, SCA, and manual techniques).

Experience with Cloud security (GCP, AWS, or Azure).

Working knowledge of authentication, authorization, cryptography, and secure architecture patterns.

Clear technical communication for both engineers and non-technical partners across regions.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8845769
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for an Application Security Engineer to join our Security Engineering team.

You will take ownership of strengthening security across our products, services, and development lifecycle. This includes identifying and addressing security gaps in application architecture and code, APIs and service-to-service communication, authentication and authorization flows, open source dependencies and third-party libraries, CI/CD pipelines and build systems, secrets handling, and AI-powered product features.

As a Security Engineer, you will dig into how our systems actually work, understand where the real risk is, and decide what needs to be built to close it. Some problems are solved by changing an architecture or a design pattern, others by implementing a new control, embedding a security gate into the pipeline, integrating and tailoring a security platform, or writing something from scratch. You will own that decision and the implementation that follows.

The Security Engineering team works as a group of all-rounders. Alongside your core focus, you will contribute to cloud and infrastructure security, corporate IT security, detection engineering, incident response, and our growing AI security work, both securing AI workloads and using AI to make our own security capabilities better.

What You Will Work On
Identify security gaps across our applications, services, and development lifecycle, then translate them into practical technical solutions.
Design and implement scalable security controls that address root causes and fit our architecture and engineering practices.
Review architectures and designs, run threat modeling, and guide R&D teams toward secure patterns before code is written.
Secure APIs, authentication and authorization flows, service-to-service trust, data handling, and multi-tenant boundaries.
Own the secure development lifecycle end to end, including security gates in GitHub Actions, SAST, SCA, secrets scanning, and dependency and supply chain risk.
Build reusable security capabilities, libraries, paved-road patterns, and developer-facing tooling that make the secure path the default path.
Build custom AI agents and AI-powered capabilities that improve our security tools, workflows, visibility, and control.
דרישות:
Requirements
At least 5 years of hands-on experience in application security, product security, security engineering, DevSecOps, or a related field.
Strong experience securing production applications and services, including APIs, microservices, and cloud-native workloads on AWS and Kubernetes.
Proven ability to identify security gaps, design appropriate controls, and take solutions through implementation.
Hands-on experience with secure code review, threat modeling, API security, and common vulnerability classes in modern application stacks.
Practical experience embedding security into CI/CD and GitOps workflows, including GitHub Actions, SAST, DAST, SCA, and secrets scanning.
Strong understanding of authentication and authorization, session management, secrets management, cryptography in practice, TLS, SSO, SAML, and OIDC.
Ability to read and write code in at least one modern language, and enough engineering depth to work as a peer to developers.
A broad security mindset, strong engineering judgment, and the ability to collaborate effectively with technical teams.

Nice to Have
Experience building AI agents, LLM-based tools, or AI-powered security capabilities.
Experience assessing or securing AI workloads, including data exposure, prompt injection, agent permissions, and third-party integrations.
Experience with ASPM platforms, WAF, bot and abuse prevention, or runtime application protection.
Familiarity with cloud and infrastructure security, Terraform, policy as code, and container security.
Offensive security background, such as penetration testing, bug bounty, or exploit development.
Experience working in a regulated fintech or financial services environment.#EN המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8831047
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Senior Security Engineer.
As a Senior Product Security Engineer, you will help ensure that security is built into the products, platforms, AI systems, and clinical workflows that support healthcare providers and patients at scale. This is a hands-on technical role focused on securing real systems in production, influencing architecture, and partnering closely with engineering, AI, DevOps, product, quality and regulatory.
You will work across cloud-native services, medical imaging workflows, healthcare integrations, AI/ML pipelines, APIs, data flows, and regulated product development processes. Your work will directly support ability to deliver secure, reliable, and trusted clinical AI solutions to healthcare organizations worldwide.
What Makes This Role Unique :
Clinical AI with real-world patient impact - we operate in an environment where security is not only about protecting systems and data. Security decisions can affect clinical workflows, care-team coordination, customer trust, and patient safety.
Highly sensitive healthcare data - You will help protect medical imaging data, clinical metadata, PHI/PII, customer environments, and AI-driven workflows that require strong privacy, access control, data protection, and auditability.
Security for AI/ML and medical imaging systems - The role extends beyond traditional AppSec into AI/ML security, data pipeline protection, inference integrity, model-related risks, and misuse scenarios in clinical workflows.
Complex healthcare integrations - we integrates with hospital systems and healthcare workflows that may include PACS, EHR, VNA, RIS/worklists, scheduling systems, and communication platforms. You will help secure the data flows, authentication models, APIs, and deployment patterns behind these integrations.
Engineering-driven security in a regulated environment - This is not a checkbox compliance role. However, because operates in healthcare and clinical AI, security must be practical, evidence-based, and aligned with regulatory, customer, and quality expectations.
Cloud-native scale and production ownership - You will work with modern cloud infrastructure, Kubernetes, containers, CI/CD pipelines, identity and access management, observability, vulnerability management, and software supply-chain controls.
דרישות:
5+ years of experience in Product Security, Application Security, Cloud Security, or a similar hands-on security engineering role.
Strong hands-on experience securing production systems, not only performing assessments or reviews.
Strong understanding of secure design, threat modeling, and architecture risk analysis.
Deep knowledge of application security, including OWASP Top 10, API security, authentication, authorization, access control, secure session handling, input validation, and modern attack vectors.
Experience securing distributed systems, APIs, web applications, backend services, and cloud-native architectures.
Strong experience with cloud environments, especially AWS and/or Azure, including IAM, network security, encryption, logging, monitoring, and workload security.
Experience with Kubernetes, containers, infrastructure-as-code, CI/CD pipelines, and modern DevOps workflows.
Practical experience with security tooling such as SAST, SCA, IaC scanning, container scanning, secrets detection, SBOM tools, vulnerability scanners, and cloud security tools.
Experience with vulnerability management, risk prioritization, remediation planning, and working with engineering teams to fix issues at scale.
Strong understanding of software supply-chain security, including dependency risk, build/release integrity, artifact security, and third-party component governance.
Experience working with modern development stacks such as Python, Java, JavaScript/TypeScript, React, microservices, APIs, and cloud-native services.
Ability to influence engineers through technical credibility, practical guidance, and strong collaboration.
Strong commu המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805560
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Senior Application Security Engineer
As a Senior Application Security Engineer, youll plan, build, and support efforts to strengthen security across the organization. As part of our Security & Platform organization, youll work across the software development lifecycle and the underlying cloud and platform environment.
Youll own application security throughout the SDLC, including security requirements, threat modeling, secure design reviews, code reviews, application and API security testing, and production hardening. The role combines application security, cloud and platform security, and security automation. Youll partner closely with Security, Engineering, Platform, DevOps, and IT teams to build secure-by-default systems and reduce risk at scale.
Youll also define and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance. This is a hands-on engineering role for someone who can move comfortably between architecture and threat modeling, code and API reviews, cloud and identity guardrails, CI/CD security controls, vulnerability remediation, and automation.
Responsibilities
Define, track, and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance.
Own application security across the SDLC, from security requirements and threat modeling through secure design, code reviews, testing, and production hardening.
Strengthen cloud and platform security by implementing scalable security controls, identity guardrails, and secure-by-default practices.
Partner closely with Security, Engineering, Platform, DevOps, and IT teams to reduce security risk and improve security practices across the organization.
Designing controls for multi-account or multi-cloud environments using Terraform, policy-as-code technologies such as OPA or Sentinel, or automated remediation workflows.
Experience running a Security Champions, bug bounty or responsible disclosure program, or delivering hands-on secure engineering training.
You'll translate technical risk into clear remediation guidance and influence engineering and leadership stakeholders through strong written and verbal communication.
Requirements:
6+ years of relevant experience across security engineering, application/product security, cloud/platform security, software engineering, or infrastructure engineering, including substantial hands-on security ownership.
Deep expertise in either application/product security or cloud/platform security, with demonstrated hands-on capability across the other domain.
Strong programming and automation skills; proficiency in Python is required, with Go or Bash beneficial, together with practical CI/CD and infrastructure-as-code experience.
Experience embedding security into the SDLC through threat modeling, secure design and code review, application/API testing and CI/CD controls, supported by strong knowledge of OWASP risks and secure design principles.
Hands-on experience with Kubernetes admission controls, image and dependency scanning, supply-chain security and CIS benchmarks.
Familiarity with OWASP ASVS/SAMM, NIST SSDF/CSF, MITRE ATT&CK, SOC 2 or ISO 27001 control environments.
Experience securing AI-assisted development workflows, enterprise AI tools, agent-based integrations, or MCP-connected systems.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8836117
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly skilled and hands-on Application Security Lead to take ownership of our product and infrastructure security. Reporting directly to the CISO with a dotted line to the CTO, you will act as the critical bridge between our Security and Engineering teams, driving a robust "security-first" culture.



While this role encompasses both application and infrastructure security, our primary focus is on the Application Security domain. You will lead our transition towards a mature DevSecOps organization, ensuring that security is seamlessly embedded into every phase of our SDLC without compromising delivery speed.

Key Responsibilities

Application Security & Secure Engineering

Secure SDLC Integration: Embed security practices throughout the entire SDLC, from initial design and planning to deployment and maintenance.
Threat Modeling & Architecture: Lead threat modeling (e.g., STRIDE) and architectural reviews for high-risk features like authentication, PII, and payments.
AppSec Tooling & Automation: Integrate and manage automated security scanning (SAST, SCA, DAST) within CI/CD pipelines to ensure code integrity seamlessly.
Mobile & API Security: Enforce least-privilege models for API configurations. Lead security initiatives specifically tailored to mobile environments (iOS/Android), protecting core mobility platform.
Offensive Security & Pentesting: Orchestrate internal red teaming and external penetration tests for web and mobile applications. Manage Vulnerability Disclosure Programs (VDP) / Bug Bounties.
Developer Empowerment & DevEx: Collaborate with developers to provide automated tools, coding guidelines, and frictionless guardrails for secure-by-design development, ensuring security acts as an enabler, not a blocker.
Incident & Vulnerability Management: Act as the technical escalation point for application security incidents, leading detection and recovery efforts, while prioritizing vulnerabilities across the product suite for timely remediation.
Cloud & Infrastructure Security

Cloud & Network Posture: Manage cloud security posture (CSPM) across AWS/GCP and oversee broad network security measures, including WAF, Bot management, and environment segmentation.
Pipeline & Secrets Management: Secure the CI/CD infrastructure against tampering and enforce robust secret management and secure repository controls across the organization.
Resilience & Recovery: Manage disaster recovery (DR) and business continuity planning for production environments.
Governance, Culture & Compliance

DevSecOps Strategy: Lead the strategic evolution of DevOps into a mature DevSecOps model, aligning with industry frameworks like OWASP SAMM and NIST SSDF.
Metrics & Measurement: Define and track key security metrics (e.g., MTTR, vulnerability density) to measure and improve program effectiveness.
Security Champions: Build and mentor a Security Champions program within R&D to scale security knowledge and foster a grassroots culture.
Compliance & Privacy: Ensure continuous compliance with PCI-DSS, ISO27001, and GDPR, championing privacy-by-design principles across all user data and R&D operations.
Requirements:
5+ years of proven experience with a strong emphasis on Application Security, Product Security, and Developer interaction. Cloud/Infrastructure security experience is highly valued but secondary to AppSec expertise.
Hands-on experience with AppSec tooling across the CI/CD pipeline, mobile application security (iOS/Android), and robust API security management.
Solid understanding of cloud architectures (AWS/GCP), secret management, and security posture tools.
Deep understanding of OWASP SAMM, NIST, Threat Modeling (STRIDE), and regulatory standards (PCI-DSS, GDPR).
Exceptional communication skills with the ability to bridge the gap between engineering, C-level executives (CISO/CTO), and security teams to embed a security culture seamlessly.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8842835
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
Location: Tel Aviv-Yafo
Job Type: Full Time
The Exposure Management Research Group at our company Software Technologies is expanding. We are looking for an experienced Offensive Security Researcher to join our newly formed AEV Team and lead the offensive side of our Agentic Exposure Validation (AEV) research.
About the group
The Exposure Management Research Group is the research arm behind our company's Exposure Management platform. The platform helps organizations see and reduce their risk from the outside in, across their external attack surface, threat intelligence, and digital risk. The group brings together vulnerability researchers, threat intelligence analysts, phishing researchers, and data scientists. Together, we track threat actors and campaigns, analyze vulnerabilities and active exploitation, and turn that research into detections, intelligence, and validation capabilities that serve thousands of customers worldwide. Our work relies heavily on data science, machine learning, and agentic AI to operate at scale.
About the position
Exposure validation goes beyond identifying that a vulnerability exists. Its purpose is to show whether an attacker could actually exploit that vulnerability, and how far they could get. In this position, you are responsible for bringing real offensive expertise into our AEV capability, which runs on an agentic AI system that validates exposures across our customers' environments.
You conduct hands-on offensive research, define the exploitation methodologies the system follows, and set the standard for what a validated, customer-ready finding looks like. You also work closely with our threat intelligence and detection teams, so that proven attack paths turn into protections for our customers.
This is a research position with direct product impact. It combines practical red team work with shaping how an AI-driven platform conducts, reasons about, and reports offensive activity.
What you'll do
Design and run offensive research against external attack surfaces: web applications, APIs, cloud-exposed services, identity, and edge infrastructure
Turn single findings into demonstrated impact through exploit chaining, lateral movement, and blast-radius analysis
Write and maintain the exploitation methodologies and attack hypotheses our agentic AEV engine runs on
Review agent runs and findings. Separate proven impact from claimed impact, and turn the gaps you find into better prompts, methods, and guardrails
Set the bar for customer-ready findings: a clear impact story, a reproducible chain, and remediation guidance a security team can act on
Work with threat intelligence researchers to turn in-the-wild attacker behavior (named actors, active campaigns, newly exploited vulnerabilities) into validation plays
Help close the purple loop by turning proven attack paths into detection and protection logic, and working with detection engineering on coverage
Contribute to the team's research output, including internal knowledge sharing and, where it fits, external publications and talks.
Requirements:
2+ years of hands-on offensive security experience: red teaming, penetration testing, or offensive research
Real exploitation depth beyond confirming vulnerabilities, including exploit chaining, privilege escalation, lateral movement, and showing business impact
Comfort with the non-deterministic side of offense: business logic flaws, misconfigurations, credential and token abuse, and using information disclosure as an entry point
Strong scripting and automation skills (Python preferred)
Clear written communication. You can explain a complex attack chain to an engineer and to a CISO
Strong advantage
A consulting background covering many customer environments, not one internal estate. You know what customers value in an engagement deliverable and how to present it
Broad exposure to defensive technologies, security controls, and vendors, and an understanding of what attacks look like from the defender's side.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8841884
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.
As a Staff Software Engineer in the Detection Platform group, you will be responsible for defining and evolving the architecture of the cloud-native systems that power our AI SIEM detection, hunting, and response capabilities, including large-scale real-time detection engines, stateful detection engines, anomaly detections, ML pipelines, agentic SOC and threat-hunting capabilities. You will participate in the design and execution of backend systems that process billions of events and several petabytes of data daily and serve tens of thousands of security specialists at enterprise and government customers worldwide.
Requirements:
7+ years of software engineering experience with deep production-level mastery of Go and/or Java (Python a plus), and a strong track record of building and operating high-scale distributed backend services.
A track record of being a recognized subject-matter expert others seek out to review and elevate their designs, with a passion for building high-scale distributed systems.
Deep experience with AWS and/or GCP, Kubernetes, Docker, Postgres, Redis, Kafka.
Hands-on experience leveraging AI in the development process (e.g. AI coding assistants and agentic dev tools such as Claude Code, Cursor, or Copilot) and a desire to reshape how a team builds software to better utilize AI.
The ability to turn vaguely specified, complex requirements into efficient, future-proof end-to-end designs, and to drive multi-team initiatives and influence the engineering roadmap.
Strategic communication: able to articulate complex technical trade-offs to both technical and non-technical stakeholders.
Ability to swiftly delve into new products, and to collaborate effectively with local and remote teams across time zones.
Customer focus: you care about delivering value and want to hear directly from customers on how to evolve your systems.
Previous experience developing security-related products is a strong advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8835420
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time and Hybrid work
Were growing and looking to hire a Senior Security Operations Engineer who embodies our core values: People First, Customer Obsession, Strive for Excellence, and Integrity.
About the Company:
A global leader in cyber-physical systems (CPS) protection, dedicated to securing the critical infrastructure that keeps the world running. Were a fast-growing, award-winning team where innovation meets purpose-and we want you to help us define the future of cybersecurity.
About the Role:
In this role, you will be a key architect and operator of our modern security posture, focusing heavily on Cloud Access Security Broker (CASB/SSE) architecture, next-generation Endpoint Detection & Response (EDR), and securing the deployment and usage of Artificial Intelligence (AI) and Large Language Models (LLMs) across the enterprise.
As threats evolve, we are proactively embedding AI-driven defense mechanisms while managing the unique threat vectors introduced by enterprise AI adoption. If you thrive at the intersection of data protection, cloud edge security, and cutting-edge automation, this position offers an exceptional opportunity to impact our global defense strategy.
Responsibilities
As a Senior Security Operations Engineer, your responsibilities will include:
Engineering level oversight and support of the operational security environment including endpoint security, cloud/SaaS security, email security, AI security, and network security.
Design, implement, and maintain security solutions for on-premises and cloud environments (e.g., AWS, Azure, GCP).
Architect, configure, and maintain Security Service Edge (SSE), including CASB, Next-Gen SWG, and ZTNA. Establish data loss prevention (DLP) profiles, threat protection policies, and granular access controls across multi-cloud and SaaS environments.
Assist in responses to internal and external compliance audits, penetration tests and vulnerability assessments.
Provide recommendations regarding direction of systems and applications to help secure access, data and assets.
Research and analyze Security Operations Center (SOC) related cyber threats , alerts, and vulnerabilities and ensure our systems are properly protected.
Conduct research on emerging products, services, protocols, and standards relative to the information security arena.
Work with IT Security product vendors and service providers, to evaluate potential security offerings, including product evaluations, pilots and proof of concept installations
Ability to understand and troubleshoot cyber security issues, network configurations, system configurations and upgrades, user authentication, etc..
Ability to work well with other technology areas to deploy security technologies.
Customer service-oriented
Strong work ethic and sense of urgency
Develop and maintain security architecture diagrams, documentation, and standards.
Requirements:
Minimum 5 years experience with Cybersecurity Operations
BA/BS degree in MIS/Computer Science or related degree strongly preferred (or relevant experience)
Relevant Certifications are a plus (e.g. CISSP, CEH, etc).
Fluent in both English and Hebrew
Experience with endpoint security tools, network security tools related to deployment, management, support, and troubleshooting.
Knowledge of IT security regarding ID access, data protection, system\application monitoring, system and application access.
Working Knowledge of Windows, Mac OS, and Linux OS.
Experience with the rollout of new technologies and migrations.
Knowledge of AWS, GCP security and Azure security (deployment, configuration, monitoring, etc).
Strong knowledge in SSE, ZTNA, CASB, DLP, EDR
Experience with AI security policies and tools
Knowledge of security frameworks and standards.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8839311
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for an Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC.

What you will do
Build and maintain Application Security Posture Management (ASPM) at the Company scale.
Automate and support SAST, SCA tools, etc as part of CI/CD pipelines.
Improving SAST, secrets detection rules. Keeping false positive rate low.
Identify, analyze, and remediate application security vulnerabilities.
Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
Develop and maintain secure coding guidelines for development teams.
Conduct, run threat modeling and risk assessments for new and existing applications.
Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc.
Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
Requirements:
6+ years of experience in application security.
Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.
Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
Understanding of authentication protocols like SAML or OIDC.
Experience in conducting threat-modeling sessions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817475
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
As a Principal Security Researcher , you will act as an architect for the Autonomous SOC, focusing directly on Cortex AgentiX. You will design and build intelligent, automated investigation and remediation agents that empower thousands of customers to secure their environments at scale.
We are looking for a practitioner who combines deep hands-on expertise investigating threats and protecting organizations with a pragmatic approach to solving complex security challenges.
Key Responsibilities
Develop in-product specialized agents to accelerate detection, respond to real-time threats, prioritize, and mitigate risks.
Establish guardrails, continuous evaluation metrics, and deterministic controls for agentic AI, ensuring complex multi-step plans execute reliably.
Drive the complete product development lifecycle, encompassing definition, design, implementation, and testing phases.
Partner cross-functionally with product management, engineering, and research teams.
Requirements:
10+ years of hands-on experience securing enterprise organizations.
Proven track record in DFIR and threat hunting, including containing and remediating complex security incidents using dozens of tools.
Practical experience utilizing industry standard frameworks, such as MITRE ATT&CK, for threat modeling.
Coding proficiency, preferably Python.
Advanced expertise leveraging AI capabilities for cybersecurity.
Exceptional analytical and problem-solving skills with a demonstrated ability to resolve complex challenges.
Excellent written and verbal communication skills to effectively collaborate with cross-functional teams.
Preferred Qualifications
Experience with Agentic AI SOC and Security Orchestration, Automation, and Response (SOAR) platforms, preferably Cortex XSOAR/XSIAM.
Relevant security certifications, such as CISSP.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830089
סגור
שירות זה פתוח ללקוחות VIP בלבד