דרושים » אבטחת מידע וסייבר » Senior Application Security Engineer

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 2 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Senior Application Security Engineer
As a Senior Application Security Engineer, youll plan, build, and support efforts to strengthen security across the organization. As part of our Security & Platform organization, youll work across the software development lifecycle and the underlying cloud and platform environment.
Youll own application security throughout the SDLC, including security requirements, threat modeling, secure design reviews, code reviews, application and API security testing, and production hardening. The role combines application security, cloud and platform security, and security automation. Youll partner closely with Security, Engineering, Platform, DevOps, and IT teams to build secure-by-default systems and reduce risk at scale.
Youll also define and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance. This is a hands-on engineering role for someone who can move comfortably between architecture and threat modeling, code and API reviews, cloud and identity guardrails, CI/CD security controls, vulnerability remediation, and automation.
Responsibilities
Define, track, and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance.
Own application security across the SDLC, from security requirements and threat modeling through secure design, code reviews, testing, and production hardening.
Strengthen cloud and platform security by implementing scalable security controls, identity guardrails, and secure-by-default practices.
Partner closely with Security, Engineering, Platform, DevOps, and IT teams to reduce security risk and improve security practices across the organization.
Designing controls for multi-account or multi-cloud environments using Terraform, policy-as-code technologies such as OPA or Sentinel, or automated remediation workflows.
Experience running a Security Champions, bug bounty or responsible disclosure program, or delivering hands-on secure engineering training.
You'll translate technical risk into clear remediation guidance and influence engineering and leadership stakeholders through strong written and verbal communication.
Requirements:
6+ years of relevant experience across security engineering, application/product security, cloud/platform security, software engineering, or infrastructure engineering, including substantial hands-on security ownership.
Deep expertise in either application/product security or cloud/platform security, with demonstrated hands-on capability across the other domain.
Strong programming and automation skills; proficiency in Python is required, with Go or Bash beneficial, together with practical CI/CD and infrastructure-as-code experience.
Experience embedding security into the SDLC through threat modeling, secure design and code review, application/API testing and CI/CD controls, supported by strong knowledge of OWASP risks and secure design principles.
Hands-on experience with Kubernetes admission controls, image and dependency scanning, supply-chain security and CIS benchmarks.
Familiarity with OWASP ASVS/SAMM, NIST SSDF/CSF, MITRE ATT&CK, SOC 2 or ISO 27001 control environments.
Experience securing AI-assisted development workflows, enterprise AI tools, agent-based integrations, or MCP-connected systems.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8836117
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
25/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Senior Product Security Engineer to own and evolve our Application and Cloud Security programs end-to-end. You'll embed security early in the development lifecycle, drive automation-first security practices across engineering, and partner closely with DevOps and product teams to keep our platform secure by design - from code to cloud.

What Youll Do
Responsibilities:
Own, maintain, and continuously improve the Secure Design Review process, ensuring security considerations are integrated early in the development lifecycle.
Develop, implement, and maintain our Application Security Program, including controls, standards, developer enablement, and automation - managing SAST and DAST tooling, integrations, alerting, and program-wide reporting.
Develop and maintain our Cloud Security Program, defining guardrails, policies, and automated controls for secure-by-default cloud deployments, including CSPM tooling, findings triage, and alignment with internal risk and compliance processes.
Monitor and enforce SDLC security controls, ensuring consistent application of secure development practices across all engineering teams.
Partner with DevOps to design, implement, and maintain a fully secured CI/CD pipeline, embedding security checks, guardrails, and automated gates throughout build, test, and deployment stages.
Collaborate closely with engineering teams to deliver actionable guidance, model threats, advise on architecture, and support secure implementations.
Identify gaps in product, application, and cloud security posture, and drive end-to-end remediation and vulnerability management campaigns.
Define and track KPIs, metrics, and reporting for application and cloud security health.
Drive automation-first approaches to product and cloud security, reducing friction and enabling fast, safe development, while promoting a culture of security and developer empowerment.
Requirements:
5+ years of experience in Engineering / Security Engineering, including 3+ years in an Application Security or Product Security focused role.
2+ years of experience managing enterprise-wide security projects, with strong project planning and organizational skills.
Proven experience leading AppSec-focused Security Review programs and CloudSec-focused Secure Design reviews.
Hands-on experience owning the migration or deployment of AppSec tooling (SAST, DAST, ASPM, or similar).
Strong proficiency with Kubernetes, Helm, and Terraform.
Strong proficiency with Python and TypeScript.
A builder's mindset - comfortable developing in-house solutions when faced with a capability gap.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796083
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for an Application Security Engineer to join our Security Engineering team.

You will take ownership of strengthening security across our products, services, and development lifecycle. This includes identifying and addressing security gaps in application architecture and code, APIs and service-to-service communication, authentication and authorization flows, open source dependencies and third-party libraries, CI/CD pipelines and build systems, secrets handling, and AI-powered product features.

As a Security Engineer, you will dig into how our systems actually work, understand where the real risk is, and decide what needs to be built to close it. Some problems are solved by changing an architecture or a design pattern, others by implementing a new control, embedding a security gate into the pipeline, integrating and tailoring a security platform, or writing something from scratch. You will own that decision and the implementation that follows.

The Security Engineering team works as a group of all-rounders. Alongside your core focus, you will contribute to cloud and infrastructure security, corporate IT security, detection engineering, incident response, and our growing AI security work, both securing AI workloads and using AI to make our own security capabilities better.

What You Will Work On
Identify security gaps across our applications, services, and development lifecycle, then translate them into practical technical solutions.
Design and implement scalable security controls that address root causes and fit our architecture and engineering practices.
Review architectures and designs, run threat modeling, and guide R&D teams toward secure patterns before code is written.
Secure APIs, authentication and authorization flows, service-to-service trust, data handling, and multi-tenant boundaries.
Own the secure development lifecycle end to end, including security gates in GitHub Actions, SAST, SCA, secrets scanning, and dependency and supply chain risk.
Build reusable security capabilities, libraries, paved-road patterns, and developer-facing tooling that make the secure path the default path.
Build custom AI agents and AI-powered capabilities that improve our security tools, workflows, visibility, and control.
דרישות:
Requirements
At least 5 years of hands-on experience in application security, product security, security engineering, DevSecOps, or a related field.
Strong experience securing production applications and services, including APIs, microservices, and cloud-native workloads on AWS and Kubernetes.
Proven ability to identify security gaps, design appropriate controls, and take solutions through implementation.
Hands-on experience with secure code review, threat modeling, API security, and common vulnerability classes in modern application stacks.
Practical experience embedding security into CI/CD and GitOps workflows, including GitHub Actions, SAST, DAST, SCA, and secrets scanning.
Strong understanding of authentication and authorization, session management, secrets management, cryptography in practice, TLS, SSO, SAML, and OIDC.
Ability to read and write code in at least one modern language, and enough engineering depth to work as a peer to developers.
A broad security mindset, strong engineering judgment, and the ability to collaborate effectively with technical teams.

Nice to Have
Experience building AI agents, LLM-based tools, or AI-powered security capabilities.
Experience assessing or securing AI workloads, including data exposure, prompt injection, agent permissions, and third-party integrations.
Experience with ASPM platforms, WAF, bot and abuse prevention, or runtime application protection.
Familiarity with cloud and infrastructure security, Terraform, policy as code, and container security.
Offensive security background, such as penetration testing, bug bounty, or exploit development.
Experience working in a regulated fintech or financial services environment.#EN המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8831047
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Platform Security Director to lead the engineering of our security infrastructure. Your mission is to build a Security Machine that is as sophisticated as our AI. You will move us beyond traditional "defense" into a "Secure-by-Default" reality, where our multi-cloud infrastructure (AWS and Azure) is hardened, automated, and resilient by design.
Youll Own:
The end-to-end security strategy across Application Security, Cloud (AWS/Azure), and Platform layers, ensuring a Secure-by-Default framework, as measured by deployment coverage, critical vulnerability reduction, and developer adoption metrics.
A unified Security Engineering organization covering AppSec, SecDevOps, and AI Security leadership, collaboration points with adjacent teams (Infrastructure, R&D, Product Engineering), and building and mentoring a high-performing team.
Lead our Platform Security domain - from Layer 7 protections to AWS architecture, security tooling, automated risk scoring, and AI-assisted automation workflows that improve detection and remediation times.
Security controls (WAF, Rate Limiting) embedded into the SDLC and CI/CD pipelines, including mandatory security gates, artifact scanning, and automated deployment checks.
Lead our AI strategy - enabling secure use in our platform products as well as for our internal engineering usage, and scaling AI security governance and controls.
The evolution of scalable infrastructure security, including Kubernetes, containers, IAM, and Zero Trust architectures, strengthening Kubernetes and cloud security posture.
Own and execute the comprehensive Vulnerability Management program, from discovery (SAST/DAST/OSS scanning) through remediation tracking, and manage the external Bug Bounty program, with a focus on improving remediation SLAs and automation coverage.
Mature secure-by-default engineering practices across the SDLC.
Increase developer adoption of automated security tooling.
Youll Solve:
Eliminating manual bottlenecks through code-driven guardrails and frictionless developer experiences.
Securing complex production systems and multi-tenant AI architectures in cloud-native production environments, with a focus on model integrity, training data provenance, data exfiltration prevention, and minimizing unique risks associated with Large Language Models (LLMs), by applying specific AI threat models.
Operationalizing Red/Purple Team exercises, penetration testing, and the Bug Bounty program to ensure a continuous feedback loop that drives proactive risk reduction.
Youll Impact:
Support a culture where security is embedded into the foundation of engineering
Turn security into a strategic product advantage and customer trust differentiator
Improve developer experience by making the secure path the easiest path
Increase engineering velocity while strengthening platform resilience
Shape the future intersection of Security, AI, and Platform Engineering
Create scalable systems, processes, and relationships that grow with the companys innovation pace.
Requirements:
An Experienced Leader: 10+ years in Security/Software Engineering with a track record of scaling departments in high-growth R&D environments.
A Technical Architect: Deep expertise in AWS/Kubernetes and modern platform security practices, Infrastructure-as-Code (Terraform/Crossplane), and secure coding (Java/Python/TypeScript).
A Systems Thinker: You have a proven track of building security machines from the ground up, with a people-first mindset, technology, and process.
Your work ensures that as our company defines the future of AI-driven revenue, we do so on the most secure and resilient platform in the industry, building customer trust and promoting responsible AI adoption.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8788377
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
25/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
our company builds the real-time 3D platform that powers games and interactive experiences, along with tools used across ads, automotive, aerospace, architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top of it, safe for millions of creators and their users.
We are seeking a Senior Application Security Engineer with profound expertise in application security. In this role, you will execute fundamental AppSec tasks, including threat modeling, secure design reviews, code evaluation, and vulnerability management, leveraging both manual methods and advanced AI tooling. You will also help secure the AI systems our company itself is building, including agentic tools and AI-assisted development workflows.
You will work directly with engineering teams across the US and EMEA.
What you will do
Lead threat modeling, secure design reviews, and penetration testing for our company products and services, from the engine and editor to cloud services, APIs, and internal platforms.
Perform deep code review and manual testing on high-risk systems, using AI-assisted review processes and covering areas automated tooling cannot fully reach.
Build and operate security automation. Use and extend AI-assisted tooling for continuous code review, finding triage, and automated penetration testing, and step in where human judgment is required.
Secure our company's AI and agentic systems. Assess AI-native products, LLM integrations, and agent workflows for the risks specific to them.
Partner with engineering teams to drive remediation, turning recurring findings into guardrails, secure defaults, and paved paths.
Investigate and respond to application security incidents, including root cause analysis and durable corrective action.
Contribute to our company's secure development lifecycle and to compliance work.
Requirements:
5+ years in application security, with a track record on complex, large-scale systems.
Strong command of secure coding and common vulnerability classes (OWASP Top 10 and beyond)
Hands-on secure development experience across several languages.
Practical penetration testing, security assessment, and vulnerability management experience with standard tooling (SAST, DAST, SCA, and manual techniques).
Experience with Cloud security (GCP, AWS, or Azure).
Working knowledge of authentication, authorization, cryptography, and secure architecture patterns.
Clear technical communication for both engineers and non-technical partners across regions.
Preferred Qualifications
Experience in the technology, gaming industry or Ad tech.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796309
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Senior Security Engineer.
As a Senior Product Security Engineer, you will help ensure that security is built into the products, platforms, AI systems, and clinical workflows that support healthcare providers and patients at scale. This is a hands-on technical role focused on securing real systems in production, influencing architecture, and partnering closely with engineering, AI, DevOps, product, quality and regulatory.
You will work across cloud-native services, medical imaging workflows, healthcare integrations, AI/ML pipelines, APIs, data flows, and regulated product development processes. Your work will directly support ability to deliver secure, reliable, and trusted clinical AI solutions to healthcare organizations worldwide.
What Makes This Role Unique :
Clinical AI with real-world patient impact - we operate in an environment where security is not only about protecting systems and data. Security decisions can affect clinical workflows, care-team coordination, customer trust, and patient safety.
Highly sensitive healthcare data - You will help protect medical imaging data, clinical metadata, PHI/PII, customer environments, and AI-driven workflows that require strong privacy, access control, data protection, and auditability.
Security for AI/ML and medical imaging systems - The role extends beyond traditional AppSec into AI/ML security, data pipeline protection, inference integrity, model-related risks, and misuse scenarios in clinical workflows.
Complex healthcare integrations - we integrates with hospital systems and healthcare workflows that may include PACS, EHR, VNA, RIS/worklists, scheduling systems, and communication platforms. You will help secure the data flows, authentication models, APIs, and deployment patterns behind these integrations.
Engineering-driven security in a regulated environment - This is not a checkbox compliance role. However, because operates in healthcare and clinical AI, security must be practical, evidence-based, and aligned with regulatory, customer, and quality expectations.
Cloud-native scale and production ownership - You will work with modern cloud infrastructure, Kubernetes, containers, CI/CD pipelines, identity and access management, observability, vulnerability management, and software supply-chain controls.
דרישות:
5+ years of experience in Product Security, Application Security, Cloud Security, or a similar hands-on security engineering role.
Strong hands-on experience securing production systems, not only performing assessments or reviews.
Strong understanding of secure design, threat modeling, and architecture risk analysis.
Deep knowledge of application security, including OWASP Top 10, API security, authentication, authorization, access control, secure session handling, input validation, and modern attack vectors.
Experience securing distributed systems, APIs, web applications, backend services, and cloud-native architectures.
Strong experience with cloud environments, especially AWS and/or Azure, including IAM, network security, encryption, logging, monitoring, and workload security.
Experience with Kubernetes, containers, infrastructure-as-code, CI/CD pipelines, and modern DevOps workflows.
Practical experience with security tooling such as SAST, SCA, IaC scanning, container scanning, secrets detection, SBOM tools, vulnerability scanners, and cloud security tools.
Experience with vulnerability management, risk prioritization, remediation planning, and working with engineering teams to fix issues at scale.
Strong understanding of software supply-chain security, including dependency risk, build/release integrity, artifact security, and third-party component governance.
Experience working with modern development stacks such as Python, Java, JavaScript/TypeScript, React, microservices, APIs, and cloud-native services.
Ability to influence engineers through technical credibility, practical guidance, and strong collaboration.
Strong commu המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805560
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Security Engineering Lead to join the Cyber Security organization, reporting to the Corporate Security Engineering Manager under the CISO.

This is a senior technical lead role focusing on engineering and execution without direct people management responsibilities. This role combines hands-on security engineering to deliver end-to-end protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will be responsible for implementing, managing, integrating and maintaining security systems across the organizations IT landscape. The role requires deep technical proficiency in multiple platforms and tools, combined with the ability to collaborate with Security, IT, Engineering, Product, GRC and other business units to reduce risks and embed strong security practices.

Your responsibilities will include:

Engineer, deploy, and continuously tune systems such as Identity & Access, Threat Detection & Response, Cloud & Network Security.
Define, enforce and maintain security policies & configurations across endpoints, email, SaaS, network, and cloud platforms.
Design and implement solutions to gain continuous visibility into systems and processes, sensitive data, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Monitor, triage, and investigate security alerts and risks, collaborating with Security, IT, Network teams on escalation and remediation.
Conduct risk assessments and identify gaps in security controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed security controls into systems, and workflows.
Maintain documentation, runbooks, and guidelines for operations, security posture management, and security practices.
Requirements:
6+ years of experience in IT security, with a strong focus on System, Network, Information, Cyber. With at least 3 years in a Security Engineering role.
Proven hands-on engineering experience with enterprise security platforms - including policy authoring, tuning, incident workflow configuration, and platform administration.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governance principles.
Experience working cross-functionally with Security, IT, Engineering, Product, and GRC teams.
Strong analytical mindset with the ability to communicate security risks clearly to technical and non-technical stakeholders.
Excellent written and verbal communication skills in English.
Proactive, detail-oriented, and ownership-driven.
Hand-on experience with multiple technologies such as: XDR (Extended Detection & Response), SWG (Secure Web Gateway), DLP (Data Leakage Prevention), Email Security, Network security (Firewalls, NAC, NDR), IGA (Identity Governance & Administration), CASB (Cloud Access Security Broker), PAM (Privileged Access Management), EPM (Endpoint Privilege Management), BAS (Breach & Attack Simulation), Vulnerability Scanners, SIEM (Security Information & Event Management), SOAR (Security Orchestration, Automation & Response), CTI (Cyber Threat Intelligence), Patch Management, TPRM (Third-Party Risk Management), EASM (External Attack Surface Management).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817717
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
26/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a Security Engineer - Product to spread the power. The ideal candidate will have experience performing security reviews, vulnerability management, and detection and response operations in cloud-native environments. Youll get to collaborate with our software development and DevOps teams to secure our products, CI/CD infrastructure, and production infrastructure. Youll also have the opportunity to influence our product roadmap by utilizing our platform to assess, monitor, and harden our environments.
Responsibilities:
Lead threat modeling and security review exercises across our production and CI/CD environments - identifying and mitigating risks in our products and the cloud services that support them.
Drive vulnerability management and remediation efforts - prioritizing issues, implementing mitigations, and designing strategic preventative controls.
Extend our detection and response capabilities - building scalable solutions to identify malicious activity, triage alerts, and investigate and remediate incidents.
Collaborate with our Federal team - extending our DevSecOps and Product Security practices to our FedRAMP environment and ensure it meets key security requirements.
Build deep functional partnerships with our engineering and operations teams - helping them deliver secure-by-design solutions.
Requirements:
Minimum Qualifications
5+ years of experience in security engineering or security operations work in cloud environments.
Experience with AWS platforms and services (equivalent experience in Azure and GCP also considered), Kubernetes (AWS EKS), and container infrastructure.
Experience with IAM, managing cloud identities at-scale, and secure development and application of IAC solutions (Terraform, Helm).
Experience with cloud-native observability and management tools.
Experience with automation and tooling development in one or more: Python, Go, Shell, HCL, Rego.
Preferred Qualifications:
Bachelor's degree in computer science or a related field and / or candidates with equivalent job experience in lieu of a degree.
Experience working with remote, globally distributed teams.
Experience working in organizations that develop software and / or operate managed infrastructure and technology services for their own customers.
Experience with CNAPP, CSPM, or CIEM solutions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798565
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a passionate Lead or Senior Offensive Security Engineer for our growing Offensive Security Automation team. This hands-on offensive security position requires a cyber security professional whose primary focus is to perform security assessments and vulnerability research using internal AI tools using frontier models, with a focus of designing and developing the AI automation and autonomous harnesses together with the team.
This is a role for someone who can perform offensive security testing at scale, combining deep security expertise with the judgment to direct and improve AI-driven tooling.

Key Responsibilities:

Offensive Security & Vulnerability Research (primary)

Perform security assessments and vulnerability research across web applications, APIs, and cloud/hybrid infrastructure, using internal AI tools and frontier models to scale coverage and depth that you will develop.

Make sure our internal solution can perform exploitation, vulnerability chaining, business logic and authorization abuse, privilege escalation, and lateral movement, beyond what automated tooling alone can find.

Run end-to-end engagements: scoping, execution, reporting, and remediation guidance.

Discover systemic/architectural weaknesses, not just isolated bugs, and drive secure-by-default fixes.

Partner with engineering, security architecture, and detection & response teams to close root causes and validate control effectiveness.

Produce high-quality technical reports with clear exploitation paths and prioritized remediation.


AI Automation & Autonomous Harness Design (secondary)

Develop the automation and autonomous harnesses that direct frontier models to perform offensive security testing continuously and at scale.

Design agent-based workflows that reason over large data, plan for risk signals, business logic and execute multi-step offensive testing that will adapt based on results, recon, hypothesis ranking, chaining of bugs exploitation, AI-Driven assessments, and reporting.

Establish human-in-the-loop checkpoints so automation scales offensive coverage without sacrificing safety or precision.

Translate your own tradecraft into reusable, explainable automation that the team can run and build on.
Requirements:
Required Qualifications:

6+ years (Senior) / 8+ years (Lead) hands-on offensive security experience such as pentesting, red teaming, or app/security research, with proven complex engagement delivery.

Deep, must-have vulnerability knowledge in cloud and web application security: OWASP Top 10+ vulnerability classes, identity/authz attack vectors, and cloud/hybrid attack surfaces.

Hands-on experience using internal AI tools and frontier models to perform or accelerate security testing, not just conceptual familiarity!

Software engineering fundamentals: System design, API integration, working with distributed services and technologies.

Ability to write custom scripts/tooling/payloads and contribute to building automation and autonomous harnesses including prompt engineering.

Excellent written and verbal communication skills.


Preferred Qualifications:

Experience with agentic frameworks, prompt optimization, agent evaluation, or lightweight model fine-tuning.

Published security research, CVEs, or conference talks.

Familiarity with MITRE ATT&CK/ATLAS and offensive AI/ML attack surfaces (prompt injection, agentic privilege abuse).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798562
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
24/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Information Security Engineer
The world of digital assets is accelerating in speed, scale, and complexity, opening new ways to leverage blockchain. Our platform and network provide the simplest and most secure way for companies to work with digital assets, and it is trusted by some of the largest financial institutions, banks, globally-recognized brands, and Web3 companies in the world, including BNY Mellon, BNP Paribas, ANZ Bank, Revolut, and thousands more.
Security isnt an afterthought; its the foundation of everything we do.
Making Security Real:
As a Senior Information Security Engineer, youll be on the front lines of protecting the systems, users, and data at scale. This role is about turning strategy, architecture, and intent into enforced controls, effective detections, and resilient operations. Youll work hands-on with the tools, signals, and incidents that define our real security posture.
If you believe security should be practical, measurable, and embedded into daily operations-and not just documented-we want you on the team.
What the Role Looks Like in Practice:
You will be the technical anchor of our internal security posture:
Architectural Ownership: Deploy, manage, and tune enterprise-grade security stacks (EDR, DLP, IAM, CASB, MDM) with a focus on deep integration and automation.
The AI Frontier: Lead the charge on AI Security. You will implement and secure AI-driven workflows, ensuring LLM use is governed and protected against emerging threats such as data leakage and prompt injection.
Proactive Defense: Build and maintain high-fidelity detections and guardrails that align with real-world attack techniques.
Cross-Functional Synergy: Partner as a peer with Engineering, IT, and DevOps to ensure security controls are frictionless, automated, and effective.
Requirements:
What Youll Bring
Technical Must-Haves:
4+ Years of Experience: Extensive hands-on experience in InfoSec Engineering or SecOps within high-growth, cloud-native environments.
AI Security Mastery (Required): You are ahead of the curve. You have practical experience securing AI adoption and leveraging AI-driven platforms to scale defensive capabilities.
Deep Technical Stack: Expert-level knowledge of endpoint security (macOS/Linux), SaaS ecosystems, and Identity (Okta/OIDC).
The Developer Mindset: Advanced scripting skills (Python is a must) to automate away manual toil and build custom security integrations.
Professional & Interpersonal Excellence:
Strategic Communication: The ability to articulate complex technical risks as actionable business intelligence for diverse stakeholders, ensuring alignment between security objectives and business goals.
Collaborative Influence: A track record of fostering strong partnerships with R&D and DevOps. You are a facilitator of Secure-by-Design principles, focused on engineering solutions rather than creating administrative bottlenecks.
Crisis Management & Decisiveness: The capacity to maintain operational composure during high-stakes incidents, applying rigorous prioritization and risk-based analysis to drive remediation.
Pragmatic Professionalism: A disciplined approach to balancing theoretical security ideals with the functional requirements of a high-velocity, global financial infrastructure.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8794668
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
15/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We seek a dynamic and experienced Cyber Security Engineer to join Tipalti! This role presents an exciting opportunity to work in a fast-growing company with great opportunities to make a difference.
In this role, you will be responsible for:
Design, implement, and maintain security architectures and controls across the organization's Cloud, SaaS, AI, and Corporate environments.
Secure enterprise infrastructure by strengthening cloud security, protecting sensitive data, managing identity and access, and continuously improving the organization's security posture.
Deploy, operate, and optimize enterprise security technologies across Identity, Endpoint, Network, Email, Cloud, SaaS, Data Protection, and Security Operations domains.
Identify, prioritize, and remediate security risks, vulnerabilities, cloud exposures, and SaaS security findings.
Lead end-to-end security projects across multiple teams, collaborating with Engineering, DevOps, IT, and Security Operations to implement scalable security solutions and drive automation.
Support the secure adoption of AI technologies while ensuring security controls align with industry best practices and frameworks such as ISO 27001, SOC 2, NIST CSF, and CIS Controls.
Requirements:
5+ years of Information Security experience, including 4+ years of hands-on Security Engineering experience implementing and operating enterprise security technologies across Identity, Endpoint, Network, Data Protection, and Secure Access domains (e.g., Firewalls, VPN, WAF, EDR/XDR, IDS/IPS, IAM, DLP, SIEM, and SASE). Must
3+ years of IT Infrastructure or Systems Engineering experience, including Active Directory, Microsoft Entra ID, Microsoft 365, MDM, and enterprise networking. Must
Strong hands-on experience securing AWS, Azure, and GCP using modern Cloud Security platforms (e.g., CNAPP/CSPM), alongside modern SaaS environments.
Hands-on experience implementing and managing Identity & Access Management (IAM), including SSO, MFA, RBAC, PAM, Conditional Access, Zero Trust, and encryption.
Experience securing enterprise AI environments, including AI governance, security controls, and Model Context Protocol (MCP). Advantage
Familiarity with industry security frameworks, including ISO 27001, SOC 2, NIST CSF, CIS Controls, and MITRE ATT&C
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8822386
סגור
שירות זה פתוח ללקוחות VIP בלבד