התפקיד במילים פשוטות
התפקיד כולל שילוב אבטחת מידע בתהליכי הפיתוח וה-CI/CD, ביצוע מידול איומים ותכנון אבטחה בשיתוף צוותי המוצר והפיתוח. בנוסף, העבודה כוללת אבטחת תשתיות ענן ב-AWS וב-GCP, הגנה על אתרים ו-WAF, וכן טיפול באירועי אבטחה ואבטחת מערכות AI ו-LLM.
- 4+ years in DevSecOps, AppSec, or Security Engineering, owning production systems
- Track record embedding security into product design, not just reviewing after the fact
- Hands-on GCP/AWS security experience
- Practical AI/LLM security knowledge — model access, data leakage, prompt injection
- Hands-on WAF and site protection experience
- Experience securing generative AI or ML product features in production
- Familiarity with AI gateways (LiteLLM, OpenRouter, Bedrock) and LLM observability tools
- Relevant certifications (CISSP, GCP/AWS security)
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים למהנדסי DevSecOps או AppSec מנוסים עם לפחות 4 שנות ניסיון, ידע באבטחת ענן, מיומנויות סקריפטינג והבנה באבטחת AI. התפקיד פחות יתאים למי שמחפש תחזוקה שוטפת בלבד ללא מעורבות ישירה בארכיטקטורה ובשלבי התכנון של המוצר.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןArtlist is a leading creative technology company on a mission to empower creators and brands to bring their vision to life with video. Offering cutting-edge AI tools and models for image, video, and voiceover creation, alongside high-quality creative assets and powerful editing tools, Artlist enables creators to stay on trend, and achieve their creative goals. Trusted by over 30 million creators worldwide and top brands including Google, Amazon, Microsoft, and Versace, Artlist provides a seamless, subscription-based platform with a global license, giving creators everything they need to produce professional video content efficiently. For more information, visit artlist.io . We're looking for a Senior DevSecOps Engineer - an all-arounder covering product security, AI security, and cyber systems, who wants to shape how security gets done, not just maintain it. Responsibilities ● Handle threat modeling and secure design review from the design stage, working directly with Product and R&D. ● Embed security into CI/CD, Product, and Tech (SAST,CNAP,WAF, EDR, PTs). ● Set guardrails and rules- access, data exposure, injection, Rate limiting, custom rules, and more. ● Secure cloud infrastructure (AWS/GCP/Azure) ● Own WAF and site protection - rules, rate limiting, bot and DDoS mitigation. ● Lead detection, response, and incident handling across endpoints, cloud, and app layers. ● Support SOC 2 / ISO 27001.
Requirements: ● 4+ years in DevSecOps, AppSec, or Security Engineering, owning production systems. ● Track record embedding security into product design, not just reviewing after the fact. ● Hands-on GCP/AWS security experience. ● Practical AI/LLM security knowledge — model access, data leakage, prompt injection. ● Hands-on WAF and site protection experience. ● Scripting/automation skills (Python, Go, or Bash). ● Fluent English. Nice to Have ● Experience securing generative AI or ML product features in production. ● Familiarity with AI gateways (LiteLLM, OpenRouter, Bedrock) and LLM observability tools. ● Relevant certifications (CISSP, GCP/AWS security).
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 4+ years in DevSecOps, AppSec, or Security Engineering, owning production systems, Track record embedding security into product design, not just reviewing after the fact, Hands-on GCP/AWS security experience, Practical AI/LLM security knowledge — model access, data leakage, prompt injection, Hands-on WAF and site protection experience