We are looking for an Application Security Engineer to join our Security Engineering team.
You will take ownership of strengthening security across our products, services, and development lifecycle. This includes identifying and addressing security gaps in application architecture and code, APIs and service-to-service communication, authentication and authorization flows, open source dependencies and third-party libraries, CI/CD pipelines and build systems, secrets handling, and AI-powered product features.
As a Security Engineer, you will dig into how our systems actually work, understand where the real risk is, and decide what needs to be built to close it. Some problems are solved by changing an architecture or a design pattern, others by implementing a new control, embedding a security gate into the pipeline, integrating and tailoring a security platform, or writing something from scratch. You will own that decision and the implementation that follows.
The Security Engineering team works as a group of all-rounders. Alongside your core focus, you will contribute to cloud and infrastructure security, corporate IT security, detection engineering, incident response, and our growing AI security work, both securing AI workloads and using AI to make our own security capabilities better.
What You Will Work On
Identify security gaps across our applications, services, and development lifecycle, then translate them into practical technical solutions.
Design and implement scalable security controls that address root causes and fit our architecture and engineering practices.
Review architectures and designs, run threat modeling, and guide R&D teams toward secure patterns before code is written.
Secure APIs, authentication and authorization flows, service-to-service trust, data handling, and multi-tenant boundaries.
Own the secure development lifecycle end to end, including security gates in GitHub Actions, SAST, SCA, secrets scanning, and dependency and supply chain risk.
Build reusable security capabilities, libraries, paved-road patterns, and developer-facing tooling that make the secure path the default path.
Build custom AI agents and AI-powered capabilities that improve our security tools, workflows, visibility, and control.
דרישות:
Requirements
At least 5 years of hands-on experience in application security, product security, security engineering, DevSecOps, or a related field.
Strong experience securing production applications and services, including APIs, microservices, and cloud-native workloads on AWS and Kubernetes.
Proven ability to identify security gaps, design appropriate controls, and take solutions through implementation.
Hands-on experience with secure code review, threat modeling, API security, and common vulnerability classes in modern application stacks.
Practical experience embedding security into CI/CD and GitOps workflows, including GitHub Actions, SAST, DAST, SCA, and secrets scanning.
Strong understanding of authentication and authorization, session management, secrets management, cryptography in practice, TLS, SSO, SAML, and OIDC.
Ability to read and write code in at least one modern language, and enough engineering depth to work as a peer to developers.
A broad security mindset, strong engineering judgment, and the ability to collaborate effectively with technical teams.
Nice to Have
Experience building AI agents, LLM-based tools, or AI-powered security capabilities.
Experience assessing or securing AI workloads, including data exposure, prompt injection, agent permissions, and third-party integrations.
Experience with ASPM platforms, WAF, bot and abuse prevention, or runtime application protection.
Familiarity with cloud and infrastructure security, Terraform, policy as code, and container security.
Offensive security background, such as penetration testing, bug bounty, or exploit development.
Experience working in a regulated fintech or financial services environment.#EN המשרה מיועדת לנשים ולגברים כאחד.