Application Security Engineer
Cybersecurity company seeking an Application Security Engineer to embed security across application development and support engineering, product, and leadership teams.
תחומי אחריות
- Design and review secure architectures for web applications, APIs, microservices, and AI-enabled environments.
- Perform threat modeling and hands-on security reviews focused on OWASP Top 10 risks, API vulnerabilities, business logic flaws, and data exposure.
- Review application code, architecture, and security controls to identify risks and recommend remediation.
- Help engineering teams integrate security into the SDLC through SAST, DAST, SCA, secrets scanning, and CI/CD controls.
- Prioritize security findings and guide development teams through remediation.
- Explain technical vulnerabilities as business risks to engineering, product, and executive stakeholders.
דרישות
- At least 3 years of experience in application security or secure software development.
- Experience designing secure application architectures and reviewing complex application ecosystems.
- Ability to audit and review code in at least one programming language.
- Hands-on experience with threat modeling methodologies such as STRIDE.
- Experience with SAST, DAST, SCA, findings triage, and remediation guidance.
- Strong understanding of APIs, microservices, cloud-native applications, and AI/LLM integrations.
- Excellent communication skills and ability to work with engineering teams, product stakeholders, and senior leadership.