דרושים » אבטחת מידע וסייבר » Application Security Lead

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 9 שעות
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly skilled and hands-on Application Security Lead to take ownership of our product and infrastructure security. Reporting directly to the CISO with a dotted line to the CTO, you will act as the critical bridge between our Security and Engineering teams, driving a robust "security-first" culture.



While this role encompasses both application and infrastructure security, our primary focus is on the Application Security domain. You will lead our transition towards a mature DevSecOps organization, ensuring that security is seamlessly embedded into every phase of our SDLC without compromising delivery speed.

Key Responsibilities

Application Security & Secure Engineering

Secure SDLC Integration: Embed security practices throughout the entire SDLC, from initial design and planning to deployment and maintenance.
Threat Modeling & Architecture: Lead threat modeling (e.g., STRIDE) and architectural reviews for high-risk features like authentication, PII, and payments.
AppSec Tooling & Automation: Integrate and manage automated security scanning (SAST, SCA, DAST) within CI/CD pipelines to ensure code integrity seamlessly.
Mobile & API Security: Enforce least-privilege models for API configurations. Lead security initiatives specifically tailored to mobile environments (iOS/Android), protecting core mobility platform.
Offensive Security & Pentesting: Orchestrate internal red teaming and external penetration tests for web and mobile applications. Manage Vulnerability Disclosure Programs (VDP) / Bug Bounties.
Developer Empowerment & DevEx: Collaborate with developers to provide automated tools, coding guidelines, and frictionless guardrails for secure-by-design development, ensuring security acts as an enabler, not a blocker.
Incident & Vulnerability Management: Act as the technical escalation point for application security incidents, leading detection and recovery efforts, while prioritizing vulnerabilities across the product suite for timely remediation.
Cloud & Infrastructure Security

Cloud & Network Posture: Manage cloud security posture (CSPM) across AWS/GCP and oversee broad network security measures, including WAF, Bot management, and environment segmentation.
Pipeline & Secrets Management: Secure the CI/CD infrastructure against tampering and enforce robust secret management and secure repository controls across the organization.
Resilience & Recovery: Manage disaster recovery (DR) and business continuity planning for production environments.
Governance, Culture & Compliance

DevSecOps Strategy: Lead the strategic evolution of DevOps into a mature DevSecOps model, aligning with industry frameworks like OWASP SAMM and NIST SSDF.
Metrics & Measurement: Define and track key security metrics (e.g., MTTR, vulnerability density) to measure and improve program effectiveness.
Security Champions: Build and mentor a Security Champions program within R&D to scale security knowledge and foster a grassroots culture.
Compliance & Privacy: Ensure continuous compliance with PCI-DSS, ISO27001, and GDPR, championing privacy-by-design principles across all user data and R&D operations.
Requirements:
5+ years of proven experience with a strong emphasis on Application Security, Product Security, and Developer interaction. Cloud/Infrastructure security experience is highly valued but secondary to AppSec expertise.
Hands-on experience with AppSec tooling across the CI/CD pipeline, mobile application security (iOS/Android), and robust API security management.
Solid understanding of cloud architectures (AWS/GCP), secret management, and security posture tools.
Deep understanding of OWASP SAMM, NIST, Threat Modeling (STRIDE), and regulatory standards (PCI-DSS, GDPR).
Exceptional communication skills with the ability to bridge the gap between engineering, C-level executives (CISO/CTO), and security teams to embed a security culture seamlessly.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8842835
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly skilled and experienced Head of Application Security to join our dynamic team. This role is pivotal in driving the security of our software development lifecycle and ensuring the robustness of our applications against potential threats. The ideal candidate will have a strong background in secure software development practices, including SSDLC implementation, and a deep understanding of security risks & tools. This position reports directly to an R&D VP.
Key Responsibilities
Lead the application security team, providing strategic direction and mentorship.
Develop and implement a comprehensive Secure Software Development Lifecycle (SSDLC) framework.
Oversee the integration of security practices into all phases of the software development lifecycle, including CI/CD guardrails.
Conduct risk assessments and threat modeling to identify and mitigate potential security vulnerabilities.
Collaborate with development teams to ensure secure coding practices and adherence to security standards, while maintaining developer productivity.
Implement and manage security automation tools and processes to enhance the efficiency of security operations.
Stay up-to-date on the latest security trends, vulnerabilities, and technologies to continuously improve our security posture.
Provide expert guidance on security architecture and design for new and existing applications.
Lead incident response efforts related to application security breaches and vulnerabilities.
Foster a culture of security awareness and continuous improvement within the organization.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 7 years of experience in application security, with at least 3 years in a leadership role.
Proven experience in implementing and managing SSDLC frameworks.
In-depth knowledge of security frameworks and methodologies.
Strong understanding of threat modeling methodologies, secure coding practices and common vulnerabilities (e.g., OWASP Top Ten).
Proficiency in programming languages such as Java, Python, C#, or similar.
Experience in implementing security tools and technologies such as ASPM, SAST, DAST in complex and high-scale environment.
Excellent communication and leadership skills, with the ability and passion to drive change across the organization.
Relevant certifications such as CISSP, CISM, or CSSLP are desirable.
Proven experience in a similar role at another leading software development company.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8840733
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Senior Security Engineer.
As a Senior Product Security Engineer, you will help ensure that security is built into the products, platforms, AI systems, and clinical workflows that support healthcare providers and patients at scale. This is a hands-on technical role focused on securing real systems in production, influencing architecture, and partnering closely with engineering, AI, DevOps, product, quality and regulatory.
You will work across cloud-native services, medical imaging workflows, healthcare integrations, AI/ML pipelines, APIs, data flows, and regulated product development processes. Your work will directly support ability to deliver secure, reliable, and trusted clinical AI solutions to healthcare organizations worldwide.
What Makes This Role Unique :
Clinical AI with real-world patient impact - we operate in an environment where security is not only about protecting systems and data. Security decisions can affect clinical workflows, care-team coordination, customer trust, and patient safety.
Highly sensitive healthcare data - You will help protect medical imaging data, clinical metadata, PHI/PII, customer environments, and AI-driven workflows that require strong privacy, access control, data protection, and auditability.
Security for AI/ML and medical imaging systems - The role extends beyond traditional AppSec into AI/ML security, data pipeline protection, inference integrity, model-related risks, and misuse scenarios in clinical workflows.
Complex healthcare integrations - we integrates with hospital systems and healthcare workflows that may include PACS, EHR, VNA, RIS/worklists, scheduling systems, and communication platforms. You will help secure the data flows, authentication models, APIs, and deployment patterns behind these integrations.
Engineering-driven security in a regulated environment - This is not a checkbox compliance role. However, because operates in healthcare and clinical AI, security must be practical, evidence-based, and aligned with regulatory, customer, and quality expectations.
Cloud-native scale and production ownership - You will work with modern cloud infrastructure, Kubernetes, containers, CI/CD pipelines, identity and access management, observability, vulnerability management, and software supply-chain controls.
דרישות:
5+ years of experience in Product Security, Application Security, Cloud Security, or a similar hands-on security engineering role.
Strong hands-on experience securing production systems, not only performing assessments or reviews.
Strong understanding of secure design, threat modeling, and architecture risk analysis.
Deep knowledge of application security, including OWASP Top 10, API security, authentication, authorization, access control, secure session handling, input validation, and modern attack vectors.
Experience securing distributed systems, APIs, web applications, backend services, and cloud-native architectures.
Strong experience with cloud environments, especially AWS and/or Azure, including IAM, network security, encryption, logging, monitoring, and workload security.
Experience with Kubernetes, containers, infrastructure-as-code, CI/CD pipelines, and modern DevOps workflows.
Practical experience with security tooling such as SAST, SCA, IaC scanning, container scanning, secrets detection, SBOM tools, vulnerability scanners, and cloud security tools.
Experience with vulnerability management, risk prioritization, remediation planning, and working with engineering teams to fix issues at scale.
Strong understanding of software supply-chain security, including dependency risk, build/release integrity, artifact security, and third-party component governance.
Experience working with modern development stacks such as Python, Java, JavaScript/TypeScript, React, microservices, APIs, and cloud-native services.
Ability to influence engineers through technical credibility, practical guidance, and strong collaboration.
Strong commu המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805560
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Security Engineering Lead to join the Cyber Security organization, reporting to the Corporate Security Engineering Manager under the CISO.

This is a senior technical lead role focusing on engineering and execution without direct people management responsibilities. This role combines hands-on security engineering to deliver end-to-end protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will be responsible for implementing, managing, integrating and maintaining security systems across the organizations IT landscape. The role requires deep technical proficiency in multiple platforms and tools, combined with the ability to collaborate with Security, IT, Engineering, Product, GRC and other business units to reduce risks and embed strong security practices.

Your responsibilities will include:

Engineer, deploy, and continuously tune systems such as Identity & Access, Threat Detection & Response, Cloud & Network Security.
Define, enforce and maintain security policies & configurations across endpoints, email, SaaS, network, and cloud platforms.
Design and implement solutions to gain continuous visibility into systems and processes, sensitive data, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Monitor, triage, and investigate security alerts and risks, collaborating with Security, IT, Network teams on escalation and remediation.
Conduct risk assessments and identify gaps in security controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed security controls into systems, and workflows.
Maintain documentation, runbooks, and guidelines for operations, security posture management, and security practices.
Requirements:
6+ years of experience in IT security, with a strong focus on System, Network, Information, Cyber. With at least 3 years in a Security Engineering role.
Proven hands-on engineering experience with enterprise security platforms - including policy authoring, tuning, incident workflow configuration, and platform administration.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governance principles.
Experience working cross-functionally with Security, IT, Engineering, Product, and GRC teams.
Strong analytical mindset with the ability to communicate security risks clearly to technical and non-technical stakeholders.
Excellent written and verbal communication skills in English.
Proactive, detail-oriented, and ownership-driven.
Hand-on experience with multiple technologies such as: XDR (Extended Detection & Response), SWG (Secure Web Gateway), DLP (Data Leakage Prevention), Email Security, Network security (Firewalls, NAC, NDR), IGA (Identity Governance & Administration), CASB (Cloud Access Security Broker), PAM (Privileged Access Management), EPM (Endpoint Privilege Management), BAS (Breach & Attack Simulation), Vulnerability Scanners, SIEM (Security Information & Event Management), SOAR (Security Orchestration, Automation & Response), CTI (Cyber Threat Intelligence), Patch Management, TPRM (Third-Party Risk Management), EASM (External Attack Surface Management).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817717
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Data Protection Lead to join the Cyber Security organization.

This role combines hands-on Data Leakage Prevention (DLP) engineering with Data Security Posture Management (DSPM) to deliver end-to-end data protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will own the data protection lifecycle from discovery and classification through policy enforcement and incident response. The role requires deep technical proficiency in DLP platforms and DSPM tooling, combined with the ability to collaborate with Security, IT, Engineering, Product, Privacy and GRC teams to reduce data exposure risks and embed strong data governance practices.

Your responsibilities will include:
Lead and own the organizations data protection domain, including strategy, standards, and hands-on technical implementation
Engineer, deploy, and continuously tune DLP policies across endpoints, email, SaaS, network proxies, and cloud platforms - covering both inline and API-based enforcement modes.
Design and implement DSPM solutions to gain continuous visibility into sensitive data posture, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Drive data discovery initiatives to identify and inventory sensitive data across databases, SaaS applications, endpoints, and cloud storage.
Define and implement data classification frameworks, labeling standards, and data handling policies integrated with DLP and DSPM controls.
Build and maintain DLP detection rules, regular expressions, fingerprinting, and machine learning-based classifiers to minimize false positives and maximize coverage.
Integrate DSPM findings into DLP enforcement workflows to create a closed-loop data protection architecture.
Define and enforce data access governance, including least-privilege principles and monitoring of sensitive data access patterns.
Monitor, triage, and investigate DLP alerts and DSPM-identified risks, collaborating with SOC and Security teams on escalation and remediation.
Conduct risk assessments and identify gaps in data protection controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to data security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed data security controls into CI/CD pipelines, systems, and workflows.
Maintain documentation, runbooks, and guidelines for DLP operations, DSPM posture management, and data security practices.
דרישות:
6+ years of experience in cyber security, with a strong focus on data security, data protection, or information security.
Proven hands-on engineering experience with enterprise DLP platforms - including policy authoring, rule tuning, incident workflow configuration, and platform administration (e.g., Microsoft Purview DLP, Symantec DLP, Forcepoint, or equivalent).
Hands-on experience deploying and operating DSPM tools (e.g., Cyera, Varonis, Rubrik Security Cloud, Normalyze, Securiti, or equivalent) to manage cloud data exposure and classification at scale.
Deep understanding of DLP enforcement mechanisms: endpoint DLP, network DLP, email DLP, and cloud/API-based DLP controls.
Strong experience with data discovery and classification across cloud environments (AWS, Azure, GCP), SaaS platforms, and on-premises systems.
Ability to write and optimize detection logic - regular expressions, data fingerprinting, document fingerprinting, and EDM (Exact Data Matching).
Experience integrating DLP and DSPM tools with SIEM, SOAR, and ticketing systems for alert routing and automated response.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governanc המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818177
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for an Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC.

What you will do
Build and maintain Application Security Posture Management (ASPM) at the Company scale.
Automate and support SAST, SCA tools, etc as part of CI/CD pipelines.
Improving SAST, secrets detection rules. Keeping false positive rate low.
Identify, analyze, and remediate application security vulnerabilities.
Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
Develop and maintain secure coding guidelines for development teams.
Conduct, run threat modeling and risk assessments for new and existing applications.
Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc.
Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
Requirements:
6+ years of experience in application security.
Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.
Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
Understanding of authentication protocols like SAML or OIDC.
Experience in conducting threat-modeling sessions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817475
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Head of Security Reliability to establish and lead the Security Reliability pillar. Reporting directly to the CISO, this leader will be accountable for the ongoing effectiveness, resilience, and operational maturity of security products after implementation.

The role ensures that security platforms remain properly configured, maintained, integrated, monitored, adopted, and optimized to deliver measurable risk reduction. It also owns Third-Party Risk Management (TPRM) program and the security-review process for new products, services, and technologies introduced across the company.

This is a hands-on leadership position for someone who combines security expertise, operational discipline, vendor-management experience, and a strong product mindset. The role partners closely with Security, IT, Engineering, Product, Procurement, Legal, Privacy, Compliance, and business stakeholders.

Key responsibilities

Security product reliability and lifecycle ownership

Own security products and platforms after implementation, from operational handover through optimization, renewal, replacement, or retirement.
Ensure security tools are correctly configured, maintained, integrated, monitored, and aligned with Nebius's risk profile and technical environment.
Define ownership, service levels, operating procedures, support models, and escalation paths for every security platform.
Monitor platform availability, data quality, control coverage, integration health, licensing, capacity, and performance.
Establish disciplined processes for upgrades, configuration changes, testing, exception management, and end-of-life planning.
Continuously assess whether security products deliver their intended outcomes, and improve utilization, coverage, automation, and return on investment.
Reduce overlapping capabilities, configuration drift, operational gaps, and underused tooling across the security stack.
Manage vendor performance, technical escalations, product-roadmap discussions, renewals, and service reviews.
Ensure newly implemented security products transition into operations with clear documentation, ownership, monitoring, and success criteria.
Security configuration and control assurance

Define and maintain secure configuration baselines for security platforms.
Establish continuous control-health monitoring to identify disabled, degraded, misconfigured, or incomplete controls.
Validate that integrations and telemetry remain complete, accurate, and reliable as environment evolves.
Coordinate remediation of control gaps with Security, IT, Engineering, and platform owners.
Maintain evidence demonstrating the operational effectiveness of security controls for audits, certifications, and customer-assurance activities.
Requirements:
Significant cybersecurity experience, including leadership responsibility in security engineering, security operations, platform security, security architecture, or technology risk.
Proven experience owning security products in production, including configuration, maintenance, integration, optimization, and lifecycle management.
Strong understanding of enterprise and cloud security technologies, architectures, and operating models.
Experience establishing or managing a Third-Party Risk Management program.
Experience performing security architecture, technology, vendor, or product reviews.
Demonstrated ability to translate technical findings into clear business risks and actionable recommendations.
Experience managing teams, budgets, vendors, service providers, and cross-functional programs.
Strong knowledge of security control frameworks and risk-management principles.
Ability to operate effectively in a complex, fast-moving, and highly technical organization.
Excellent communication and stakeholder-management skills, including presenting risks and recommendations to senior leadership.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818125
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
This role is responsible for leading the organizations security architecture across corporate networks and cloud environments, ensuring secure design and implementation of enterprise infrastructure at scale.

The ideal candidate combines deep expertise in network and cloud security with strong leadership capabilities. You will define and drive security architecture across hybrid environments, working closely with IT, Infrastructure, Network, DevOps, and Security teams to ensure robust, scalable, and resilient security controls.

Your responsibilities will include:

Lead and manage the security architecture domain, including security architects and/or senior engineers.
Define and maintain security architecture standards, guidelines, and reference designs across corporate and cloud environments.
Act as the primary authority on enterprise security architecture across networks, identity, endpoints, and cloud platforms.
Design and evolve secure enterprise network architectures, including segmentation, Zero Trust, and hybrid connectivity.
Define and enforce security controls for corporate networks, data centers, and remote access solutions (ZTNA, proxies, NAC).
Lead architecture and selection of network security technologies (e.g., firewalls, secure gateways, access control solutions).
Lead security architecture across cloud platforms and hybrid environments.
Define secure reference architectures for cloud networking, identity, and workload protection.
Ensure proper implementation of cloud security controls, including IAM, segmentation, encryption, and monitoring.
Define security architecture for endpoints and identity, including EDR/XDR, device hardening, SSO, MFA, and privileged access.
Ensure secure baseline configurations and access control mechanisms across corporate and cloud environments.
Identify architectural risks and security gaps and drive mitigation strategies across infrastructure and cloud environments.
Establish and enforce architecture review processes and governance for new systems and changes.
Collaborate with SOC, Vulnerability Management, IT, and Infrastructure teams to improve overall security posture.
Contribute to the cyber security strategy and roadmap, including adoption of modern models such as Zero Trust.
Requirements:
7+ years of experience in cyber security, with a strong focus on cloud security.
2+ years of experience leading or managing security architects or senior security engineers.
Deep expertise in enterprise network security (firewalls, segmentation, VPN, proxies, NAC, etc.).
Strong hands-on experience with cloud platforms (AWS, GCP, Azure) and cloud security best practices.
Strong understanding of identity and access management (IAM), Active Directory / Entra ID, and privileged access controls.
Experience securing hybrid environments (on-premise + cloud).
Hands-on experience with enterprise security technologies (e.g., Palo Alto, Check Point, Cisco, Zscaler, CrowdStrike, Microsoft Defender).
Strong understanding of Zero Trust architecture principles.
Experience working cross-functionally with IT, Infrastructure, Network, DevOps, and Security teams.
Excellent analytical, problem-solving, and communication skills in English.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817757
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time and Hybrid work
We are growing and are looking for a Senior Information Security Manager JD to join our mission to increase access to life-saving treatments.

The Role:

Lead and maintain all certification and compliance efforts, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, and CIS benchmarks

Serve as the primary point of contact for all security questions and concerns, internal and external

Own global security awareness strategy and programs, including annual employee training, ongoing awareness campaigns, and phishing simulations

Respond to customer and prospect security questionnaires while maintaining agreed turnaround times

Oversee SOC (Security Operations Center) operations, including log source coverage, detection rule creation and tuning, and SLA/KPI management

Build and manage the Third-Party Risk Management, Business Continuity, and Disaster Recovery programs

Run the vulnerability steering committee across corporate and production environments

Manage vendor risk and the security risk register

Monitor and manage the company's external digital footprint using third-party attack surface management tools

Act as incident commander for security incidents - analyze, escalate, coordinate response, and drive remediation

Help design and execute the annual security roadmap

Manage the company Trust Center

Lead the internal security policy lifecycle - creation, updates, approvals, and distribution

Audit onboarding and offboarding processes from a security perspective
Requirements:
5+ years of experience in information security, with meaningful time in GRC, security operations, or a hybrid role

Hands-on experience leading or supporting SOC 2, ISO 27001, HIPAA, and GDPR certifications and audits

Strong understanding of SOC operations, SIEM tooling, detection engineering concepts, and incident response

Experience building or running a Third-Party Risk Management program

Experience acting as incident commander or lead responder for security incidents

Familiarity with vulnerability management programs across cloud and corporate environments

Strong written and verbal communication skills in English, able to represent security to customers, auditors, and executives
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818572
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a Security Operations (SecOps) specialist to take ownership of our security infrastructure and operations as we scale. In this hands-on, high-impact role, youll play a crucial role in managing the infrastructure, services and service providers that help keep secure from outside attacks and insider threats, along with managing our information compliance programs.
Responsibilities:
Support and lead our security programs, both internal and with 3rd party vendors.
Lead incident response simulations and continuous vulnerability remediation efforts, optimizing our observability and alerting frameworks.
Support the design and maintenance of resilient, scalable cloud infrastructure, ensuring security is baked into the foundation.
Work closely with company leadership to ensure adoption of security best practices.
Work closely with R&D teams to help them shift security testing left into the early phases of development.
Monitor, detect, and respond to security alerts and infrastructure anomalies, optimizing our logging, tracing, and alerting frameworks.
Conduct regular reviews of security tools and infrastructure such as endpoint security, malware detection, firewall logs, and the like.
Collaborate with our CISO to implement and automate controls supporting fintech/insurtech compliance and data privacy standards (PII protection, SOC2).
Requirements:
4+ years experience working in an Incident Response/Cyber Security Operations Center (in-house or outsourced) creating, escalating, and managing security incidents and creating incident reports or 4+ years in either a SecOps or DevSecOps role.
Proficient in at least one scripting language (Python, Bash, or Node.js) to build security guardrails and automate manual processes.
3+ years working with security tools including SIEM, Analytics & Intelligence, Intrusion Detection, Malware Detection, Data Loss Protection, and Identity & Access Management.
Experience managing low to high-risk cybersecurity events, alerts, and incidents with event monitoring, analysis, and escalation.
A builders mindset: You aren't just identifying vulnerabilities; you are designing the automated fixes, guardrails, and processes that prevent them from recurring.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8841866
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
26/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a Pentest Product Associate to join our Product team and help expand our power. In this pivotal role, you will be the primary operator of our cutting-edge AI-driven Dynamic Application Security Testing (DAST) agent while simultaneously innovating detection mechanisms for cloud-native technologies. You will bridge the gap between automated AI testing and cloud infrastructure, defining the "rules of engagement" for our agents to ensure they effectively simulate sophisticated attacks and accurately classify the modern attack surface.
Responsibilities:
Develop advanced detection algorithms to classify cloud technologies while fine-tuning the attack policies that define how our agents identify and exploit vulnerabilities.
Analyze cloud services, APIs, and log payloads to review complex attack paths, reducing false positives and ensuring compliance with industry standards.
Stay at the forefront of novel attack vectors and emerging cloud/API threats, translating new techniques into executable behaviors for the DAST engine.
Collaborate directly with Research, Backend, and R&D teams to turn operational insights into feature requests, positioning us as the market leader in vulnerability management.
Requirements:
Minimum Qualifications:
2 years of hands-on experience in AppSec or penetration testing, including proficiency with enterprise tools like Burp Suite, OWASP ZAP, or Acunetix.
Hands-on experience with Linux, Windows, Docker, Kubernetes, web protocols (HTTP/S, REST, GraphQL), and authentication mechanisms (OAuth, SAML).
Proficiency in scripting languages such as Python, Bash, or Go to automate security tasks and interact with codebases.
Solid knowledge of networking concepts, the OSI model, and cloud infrastructure (AWS, Azure, or GCP).
Preferred Qualifications:
Knowledge of AI/ML and how LLMs or reinforcement learning agents operate within a cybersecurity context.
SaaS and cloud experience, with familiarity in AWS, Azure, or GCP environments and modern cloud-native architectures.
A red teaming background, with experience in simulated adversarial attacks and bypassing standard WAF or security controls.
An analytical mindset with the ability to diagnose complex logs and scans to distinguish between tool failures, configuration issues, and valid security findings.
Self-motivated with the ability to work collaboratively and communicate high-stakes security concepts effectively across teams.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798539
סגור
שירות זה פתוח ללקוחות VIP בלבד