Senior Application Security Engineer
Join a cloud-native security company in Tel Aviv as a Senior Application Security Engineer. The role is hybrid, requiring at least two days per week in the office, and focuses on embedding security throughout product development.
Responsabilidades
- Lead threat modeling and secure design activities across the software development lifecycle
- Define and enforce secure coding standards and partner with engineering teams on architecture and design
- Perform manual and tool-assisted code reviews, SAST, DAST, penetration testing, and security validation
- Identify, triage, assess, and prioritize vulnerabilities; support remediation and verify fixes
- Integrate security tools into CI/CD pipelines and automate scanning, reporting, and ticketing workflows
- Build application security tooling and use AI or machine learning to improve vulnerability detection, prioritization, and remediation
- Maintain visibility into security posture across products
- Advise developers on practical fixes and balance security with usability and delivery needs
- Deliver security training and awareness activities
- Mentor engineers and junior application security team members
- Act as a security champion across R&D and communicate risk to engineers, product managers, and leadership
Requisitos
- Bachelor’s degree in Computer Science, Security, or equivalent experience
- At least 5 years of experience in application security or software engineering with a security focus
- Strong knowledge of OWASP Top 10, secure coding, APIs, microservices, and cloud-native architectures
- Experience with threat modeling and architecture reviews
- Prior software development experience and strong coding skills, preferably in C++ and Java
- Hands-on experience with ASPM, SAST, DAST, SCA, CI/CD, and DevSecOps tools and pipelines
- Experience applying AI across secure SDLC and application security, including assessing insecure code suggestions, data leakage, and supply-chain risks
- Ability to communicate security issues clearly and collaborate with engineering, product, and leadership teams
Se valora
- Security certification such as CISSP, CSSLP, or OSCP
- Experience with cloud-native technologies and Windows internals
- Experience applying AI or automation to security workflows
- Familiarity with SOC 2 or ISO 27001 frameworks
Beneficios
- Hybrid work model with a minimum of two office days per week
- Inclusive and diverse workplace
- Equal employment opportunities and reasonable accommodations