Senior Product Security Engineer
Work with product and development teams to strengthen application security and integrate practical security measures throughout the software development lifecycle. This is a hybrid role based in North Tel Aviv, with three office days and two work-from-home days per week.
Responsabilidades
- Partner with product and development teams on application and product security throughout the software development lifecycle
- Conduct security reviews of applications, APIs, services, and code
- Investigate, validate, and assess security vulnerabilities and findings
- Provide remediation guidance and support engineering teams through fixes
- Perform threat modeling and security analysis for new and existing product capabilities
- Use application security tools and controls, including SAST, SCA, DAST, API security, and WAF
- Improve and automate product security processes, tooling, and development lifecycle checks
- Assess security across web applications, APIs, microservices, containers, Kubernetes, and cloud-native services
- Support secure coding practices and advise development teams
- Support vulnerability disclosure and Bug Bounty activities, including validation, risk assessment, and remediation follow-up
- Improve product security practices across the engineering organization
Requisitos
- At least 5 years of hands-on experience in application security, product security, or a related software security role
- Ability to read, understand, and review application code in .NET, JavaScript/TypeScript, or comparable technologies
- Hands-on experience identifying and analyzing application and API vulnerabilities
- Experience with threat modeling and application security reviews
- Knowledge of authentication, authorization, session management, web, API, and mobile security
- Knowledge of OWASP Top 10 and practical remediation
- Hands-on experience with SAST, SCA, DAST, API security, or WAF technologies
- Experience with microservices, APIs, containers, Kubernetes, and cloud-native environments
- Knowledge of AWS and/or Azure security
- Understanding of CI/CD and modern software development environments
Se valora
- Experience developing security tools or automation
- Experience with CI/CD and software supply chain security
- Experience in fintech, payments, or security-sensitive SaaS
- Experience with vulnerability research, Bug Bounty, or vulnerability disclosure programs
- Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems
- Security research, open-source contributions, or other demonstrated hands-on security work
Beneficios
- Hybrid work model
- Shuttle services
- Employee parking
- Snacks and treats
- Career coaching