חזרה

Senior Application Security Engineer

Dream Security
שכר לא צויןTel Aviv, Tel Aviv-Jaffa, Israel, מרחוקסניורמשרה מלאה
משרה חיצונית, ההגשה באתר החברהאושר שהמשרה פתוחה לפני 13 שעות

Plan, build, and support security efforts across the software development lifecycle and the cloud and platform environment. Own application security and help teams build secure-by-default systems and reduce risk across the organization.

מה תעשו

  • Own application security across the SDLC, from security requirements and threat modeling through secure design, code reviews, testing, and production hardening.
  • Strengthen cloud and platform security with scalable controls, identity guardrails, and secure-by-default practices.
  • Define, track, and report security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance.
  • Partner with Security, Engineering, Platform, DevOps, and IT teams to reduce security risk and improve security practices.
  • Design controls for multi-account or multi-cloud environments using Terraform, policy-as-code technologies, or automated remediation workflows.
  • Translate technical risk into clear remediation guidance for engineering and leadership stakeholders.

דרישות

  • 6+ years of relevant experience across security engineering, application/product security, cloud/platform security, software engineering, or infrastructure engineering, including substantial hands-on security ownership.
  • Deep expertise in application/product security or cloud/platform security, with hands-on capability across the other domain.
  • Proficiency in Python and practical CI/CD and infrastructure-as-code experience.
  • Experience embedding security into the SDLC, including threat modeling, secure design and code review, application/API testing, and CI/CD controls.
  • Hands-on experience securing at least one major public cloud platform, including IAM, workloads, networks, logging, organization-level guardrails, containers/Kubernetes, and secrets and key management.

יתרון

  • Go or Bash.
  • Experience with Terraform and policy-as-code technologies such as OPA or Sentinel.
  • Experience running a Security Champions, bug bounty, or responsible disclosure program, or delivering hands-on secure engineering training.
  • Experience securing AI-assisted development workflows, enterprise AI tools, agent-based integrations, or MCP-connected systems.

תנאי סף

  • 6+ years of relevant experience
  • Proficiency in Python
  • Hands-on experience securing at least one major public cloud platform
Application SecurityCloud SecurityPythonCI/CDTerraformKubernetesThreat ModelingOWASP