← Back to jobs
T

Senior Product Security Engineer

Tipalti·Tel Aviv, Israel·en
HybridFull-timeSecurity EngineeringFinTechEnterprise Software

Work with product and development teams to strengthen application security and integrate practical security measures throughout the software development lifecycle. This is a hybrid role based in North Tel Aviv, with three office days and two work-from-home days per week.

Responsibilities

  • Partner with product and development teams on application and product security throughout the software development lifecycle
  • Conduct security reviews of applications, APIs, services, and code
  • Investigate, validate, and assess security vulnerabilities and findings
  • Provide remediation guidance and support engineering teams through fixes
  • Perform threat modeling and security analysis for new and existing product capabilities
  • Use application security tools and controls, including SAST, SCA, DAST, API security, and WAF
  • Improve and automate product security processes, tooling, and development lifecycle checks
  • Assess security across web applications, APIs, microservices, containers, Kubernetes, and cloud-native services
  • Support secure coding practices and advise development teams
  • Support vulnerability disclosure and Bug Bounty activities, including validation, risk assessment, and remediation follow-up
  • Improve product security practices across the engineering organization

Requirements

  • At least 5 years of hands-on experience in application security, product security, or a related software security role
  • Ability to read, understand, and review application code in .NET, JavaScript/TypeScript, or comparable technologies
  • Hands-on experience identifying and analyzing application and API vulnerabilities
  • Experience with threat modeling and application security reviews
  • Knowledge of authentication, authorization, session management, web, API, and mobile security
  • Knowledge of OWASP Top 10 and practical remediation
  • Hands-on experience with SAST, SCA, DAST, API security, or WAF technologies
  • Experience with microservices, APIs, containers, Kubernetes, and cloud-native environments
  • Knowledge of AWS and/or Azure security
  • Understanding of CI/CD and modern software development environments

Nice to have

  • Experience developing security tools or automation
  • Experience with CI/CD and software supply chain security
  • Experience in fintech, payments, or security-sensitive SaaS
  • Experience with vulnerability research, Bug Bounty, or vulnerability disclosure programs
  • Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems
  • Security research, open-source contributions, or other demonstrated hands-on security work

Benefits

  • Hybrid work model
  • Shuttle services
  • Employee parking
  • Snacks and treats
  • Career coaching

Relevance

More opportunities

Similar jobs

The newest open roles in Security Engineering.

Questions, answered

Frequently asked questions

Senior Product Security Engineer | Hybrid, Full-Time | CVZilla