Application Security Engineer
Seeking an Application Security Engineer to perform penetration testing, code reviews, and security assessments for software applications. The role involves configuring automated security tools, analyzing vulnerabilities, and collaborating with development teams. The company is a global financial services firm offering a hybrid work model in Tel Aviv.
Responsibilities
- Configure and manage automated security testing tools for regular codebase scans, including static, dynamic, and API tests.
- Perform penetration tests on web applications, mobile apps, APIs, thick clients, networks, cloud, and AI systems.
- Analyze security scan results and identify true positive findings.
- Collaborate with development teams to provide detailed feedback and remediation recommendations.
- Document and report security findings, including mitigation strategies.
- Handle the bug bounty program, assisting with analysis and triage.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Experience in application security, code review, and security testing.
- Basic knowledge of static and dynamic code analysis tools and techniques.
- Familiarity with software composition analysis tools and methodologies.
- Experience with automated security testing tools and their configuration.
- Familiarity with Java, C, C++, or .Net.
- Strong understanding of Object-Oriented Programming.
- Proficient in reading SQL statements.
- Knowledgeable about ADO pipelines.
- Familiarity with coding agent AI tools like Claude, Devin, Codex.
- Strong analytical and problem-solving skills.
- Good communication and collaboration skills.
Nice to have
- Relevant certifications such as CISSP, CEH, or OSCP.
Benefits
- Retirement investment and tools for financial future.
- Education reimbursement.
- Comprehensive physical and emotional well-being resources.
- Family support programs.
- Flexible Time Off (FTO).
- Hybrid work model with 4 days in office, 1 day remote.