Senior Application Security Engineer
Posted Updated
You will guide and mentor developers on secure coding, lead a Security Champions program, facilitate threat modeling and design reviews, and help embed secure architecture and API practices. You will integrate AppSec controls into CI/CD workflows, provide remediation guidance, produce compliance evidence, and maintain secure-development guidance and awareness content.
Responsibilities
- Mentor, coach, and educate developers on secure coding
- Lead and scale a Security Champions program
- Facilitate threat modeling sessions and design reviews
- Ensure secure architecture patterns, API security practices, and design principles are embedded early
- Integrate and tune SAST, SCA, IaC scanning, and secret scanning into CI/CD pipelines
- Translate vulnerabilities into actionable remediation guidance
- Build security awareness content, playbooks, and reusable patterns
- Produce documentation and SDLC evidence for compliance requirements
- Stay current on emerging threats and secure engineering patterns
Requirements
- Native-level English and Hebrew fluency
- 7+ years of software security engineering experience, including 4-5 years in application security or secure-development enablement
- Coding ability in JavaScript, TypeScript, Python, Go, Java, or C#
- Experience teaching, mentoring, or enabling developers
- Understanding of secure coding, vulnerability classes, API security, and secure design
- Experience with SAST, SCA, IaC scanners, secret scanning, and developer-workflow integration
- Experience with cloud-native architecture and AWS or Azure security
- Familiarity with PCI DSS, SOC 2, FFIEC, NIST, OWASP, and ASVS
Benefits
- Flexible hybrid model with three days a week in the office
- ₪1,000 net monthly wellness benefit
- Full Keren Hishtalmut
- Private health insurance
- Dental insurance
- Donation matching
- Volunteering days
- Team outings
- Mentorship programs