Senior Product Security Engineer
A healthcare AI company is seeking a Senior Product Security Engineer to secure production products, cloud platforms, clinical workflows, healthcare integrations, and AI/ML systems. The role is hands-on, hybrid, and based in Tel Aviv.
Responsabilidades
- Identify, prioritize, and remediate security risks across services, APIs, medical imaging workflows, AI outputs, data flows, and product features.
- Provide secure-by-design guidance on authentication, authorization, tenant isolation, encryption, secrets management, service communication, audit logging, and data handling.
- Improve security across cloud environments, Kubernetes, containers, IAM, network segmentation, workload identity, infrastructure as code, logging, monitoring, and cloud security posture management.
- Integrate and operate security tooling across CI/CD pipelines, including code, dependency, infrastructure, container, and secrets scanning.
- Own vulnerability management, drive remediation with engineering teams, and reduce recurring issues through root-cause improvements.
- Secure AI/ML features and data pipelines, including training and inference data, model inputs and outputs, sensitive datasets, pipeline integrity, and production monitoring.
- Strengthen software supply-chain security across dependencies, third-party components, build systems, artifacts, release pipelines, and deployments.
- Mentor engineers on security risks and secure design decisions.
- Communicate technical security risks, business impact, and trade-offs to engineering, product, leadership, quality, regulatory, and customer-facing stakeholders.
Requisitos
- At least 5 years of experience in product security, application security, cloud security, or a similar hands-on security engineering role.
- Hands-on experience securing production systems.
- Strong knowledge of secure design, threat modeling, and architecture risk analysis.
- Expertise in application security, OWASP Top 10, API security, authentication, authorization, access control, session security, and input validation.
- Experience securing distributed systems, APIs, web applications, backend services, and cloud-native architectures.
- Experience with AWS and/or Azure, including IAM, network security, encryption, logging, monitoring, and workload security.
- Experience with Kubernetes, containers, infrastructure as code, CI/CD, and DevOps workflows.
- Practical experience with SAST, SCA, IaC scanning, container scanning, secrets detection, SBOM, vulnerability scanning, and cloud security tools.
- Experience with vulnerability management, risk prioritization, remediation planning, and software supply-chain security.
- Familiarity with Python, Java, JavaScript/TypeScript, React, microservices, APIs, and cloud-native services.
- Ability to influence engineering teams through practical technical guidance.
- Strong communication skills for explaining security risks to technical and non-technical stakeholders.
Beneficios
- Hybrid work model
- Employee gym and fitness classes
- Daily breakfasts and lunches
- Meal card and stocked kitchen
- Attractive compensation and benefits
- Inclusive and collaborative workplace