Product Security Engineer
- Lead security in the R&D organization by professionalism and cooperation across Check Point
- Maintain and develop the Secure Development Life Cycle of all Check Point’s Products Organization, work with R&D, QA, Sales, Support, external researchers, and customers to make the cyber landscape a safer place.
- Conduct architectural security reviews and threat modeling for R&D
- Full triage for Check Point's VDP and BBP reports, including analyzing reports, calculating severities and communications with reporters.
- Define and develop security training to implement cross organization
- Be a first responder in security incidents, including leading and defining actions to resolution
- Manage and monitor Check Point's SCA, SAST, DAST tools
- Proven ability to lead and influence leaders across the organization.
- In-depth knowledge of Secure Development Life Cycle (SDLC) processes, secure architecture, third-party tools, and security policies.
- Threat modeling & secure design - Ability to review architectures, identify abuse cases, and guide developers on secure design decisions early in the lifecycle.
- Expertise in identifying, analyzing, and mitigating security vulnerabilities, including familiarity with Common Vulnerabilities and Exposures (CVE) and the Common Vulnerability Scoring System (CVSS).
- Hands-on experience with AppSec tooling - SAST, DAST, SCA (e.g., SonarQube, Snyk, JFrog Xray), including tuning, triaging results, and integrating into CI/CD pipelines.
- Experience with vulnerability management and the ability to interpret and apply security standards, guidelines, and regulations.
- Proficiency in secure coding practices and the ability to conduct code reviews for security vulnerabilities.
- Familiarity with incident response processes, security monitoring, and threat intelligence.
- Offensive mindset - Ability to think like an attacker (manual testing, basic exploitation techniques) to validate real impact and reduce false positives.
Advantage:
- Prior experience in software development.