דלג לתוכן הראשי

Senior Application Security Engineer

Peer Securityמחוז תל אביב, ישראללא צויןFull-timeדרגה: לא צוין

פורסם אתמול · 0 מועמדים

שכר לא צוין במשרה זו

שמירה, הגשה או בדיקת התאמה. פתיחת חשבון חינם לוקחת כמה שניות.

תובנת Willbi
חובה
  • 5+ years of hands-on experience in Application Security, Product Security, DevSecOps, Cloud Security, or a closely related security engineering role
  • Hands-on experience with Wiz
  • Strong hands-on experience with CI/CD pipelines and modern software development processes
  • Strong understanding of SSDLC, DevSecOps, and security integration throughout development and deployment workflows
  • Hands-on experience working with cloud environments, with strong knowledge of AWS, GCP, and/or Azure
יתרון
  • Deep hands-on experience performing web application and API penetration testing
  • Experience manually identifying and exploiting vulnerabilities rather than relying solely on automated tools
  • Experience with Burp Suite or similar Application Security testing tools
  • Experience securing Kubernetes and containerized environments
  • Experience with Infrastructure as Code technologies such as Terraform and related security tooling

חולץ מתיאור המשרה · מתעדכן אוטומטית

תיאור המשרה המלא

המשרה המקורית · נשמר לעיון

Company Description

Peer Security is a cybersecurity firm specializing in advanced penetration testing across web applications, mobile platforms, thick clients, and infrastructure. Founded by industry-leading researchers, the company focuses on identifying vulnerabilities and strengthening the digital assets of organizations in an increasingly interconnected world. Its expert team uses cutting-edge tools and methodologies to deliver tailored security assessments that address specific client needs and business objectives. Peer Security is recognized for its bespoke security strategies, high standards of professionalism, and commitment to continuous research and innovation. The company’s vision is to be a trusted global partner, safeguarding digital operations and advancing the broader cybersecurity ecosystem.

Role Description

As a Senior Application Security Engineer at Peer Security, you will work directly with customer development, DevOps, platform, cloud, and security teams to design and implement security throughout the Software Development Lifecycle (SSDLC).

This is a senior, hands-on role with a strong focus on CI/CD and modern development processes, cloud security, Application Security, Wiz, and AI-driven development environments.

You will be expected to independently assess complex environments, identify and prioritize security risks, design practical remediation strategies, and lead security initiatives across applications, APIs, CI/CD pipelines, and multi-cloud environments.

The role requires a strong understanding of how modern engineering organizations build and deploy software, including cloud-native architectures, Infrastructure as Code, automated deployment pipelines, and AI-assisted development.

Responsibilities

• Own and lead Application Security and SSDLC initiatives across customer development environments.

• Work closely with development, DevOps, Platform Engineering, Cloud, and Security teams to embed security controls throughout development and deployment workflows.

• Review, design, and improve security controls across CI/CD pipelines, including automated security testing, policy enforcement, secrets management, dependency security, and deployment controls.

• Assess modern software development environments, including Git workflows, pull requests, build pipelines, artifact management, containerized workloads, Infrastructure as Code, and cloud deployment processes.

• Work extensively with Wiz to identify, investigate, prioritize, and drive remediation of cloud security risks, vulnerabilities, misconfigurations, and exposure paths.

• Perform security assessments across AWS, GCP, and Azure environments and provide practical remediation guidance to engineering and cloud teams.

• Perform secure code reviews and identify complex security vulnerabilities in applications, APIs, and cloud-native services.

• Lead threat modeling, architecture reviews, and security design discussions for new applications, services, and infrastructure.

• Design and integrate security technologies and controls such as SAST, DAST, SCA, secrets scanning, IaC scanning, and container security into CI/CD pipelines.

• Evaluate vulnerabilities beyond automated scanner findings and determine their actual exploitability, exposure, attack paths, and business impact.

• Perform and support hands-on penetration testing of web applications, APIs, and cloud environments.

• Guide development teams through security aspects of AI-related projects, from architecture and design through implementation and production deployment.

• Assess security risks associated with LLMs, AI APIs, agents, RAG architectures, and AI-assisted software development.

• Advise engineering teams on secure usage of AI development tools such as GitHub Copilot, Cursor, Claude Code, and similar technologies.

• Review AI-generated code and development workflows to identify security weaknesses introduced through AI-assisted development.

• Drive vulnerability remediation together with engineering teams and help establish scalable processes for vulnerability management and risk prioritization.

• Identify opportunities to automate security controls and reduce security friction throughout development and deployment workflows.

• Serve as a senior technical security advisor to customer engineering and security teams.

Qualifications

• 5+ years of hands-on experience in Application Security, Product Security, DevSecOps, Cloud Security, or a closely related security engineering role.

• Hands-on experience with Wiz – mandatory.

• Strong hands-on experience with CI/CD pipelines and modern software development processes – mandatory.

• Strong understanding of SSDLC, DevSecOps, and security integration throughout development and deployment workflows.

• Hands-on experience working with cloud environments, with strong knowledge of AWS, GCP, and/or Azure.

• Strong understanding of cloud security concepts, cloud-native architectures, IAM, networking, containers, Kubernetes, Infrastructure as Code, and common cloud security risks.

• Strong understanding of Application Security and common web and API vulnerabilities, including the OWASP Top 10.

• Strong understanding of penetration testing methodologies and the ability to evaluate vulnerabilities beyond automated scanner results.

• Experience with Application Security technologies such as SAST, DAST, SCA, secrets scanning, IaC security, container security, and vulnerability management platforms.

• Strong understanding of Git-based development workflows, pull requests, code reviews, build processes, and automated deployment pipelines.

• Good understanding of AI/LLM technologies and AI-assisted software development, including their security implications.

• Ability to independently analyze complex technical environments and translate security findings into practical engineering solutions.

• Ability to lead technical security discussions with developers, DevOps engineers, architects, cloud engineers, and security teams.

• Strong communication and problem-solving skills with a pragmatic, engineering-oriented approach to security.

Nice to Have

• Deep hands-on experience performing web application and API penetration testing.

• Experience manually identifying and exploiting vulnerabilities rather than relying solely on automated tools.

• Experience with Burp Suite or similar Application Security testing tools.

• Experience securing Kubernetes and containerized environments.

• Experience with Infrastructure as Code technologies such as Terraform and related security tooling.

• Experience with GitHub Actions, GitLab CI/CD, Jenkins, Azure DevOps, or similar CI/CD platforms.

• Experience with additional CNAPP, CSPM, CWPP, vulnerability management, or cloud security technologies.

• Experience designing or implementing security guardrails across large-scale development environments.

• Familiarity with AI/LLM security risks, including prompt injection, insecure output handling, sensitive information disclosure, excessive agency, RAG-related risks, and other OWASP LLM-related threats.

• Experience conducting security reviews of AI applications, LLM integrations, AI agents, or AI development workflows.

• Hands-on experience with AI-assisted development tools such as GitHub Copilot, Cursor, or Claude Code.

• Relevant Application Security, cloud security, penetration testing, or DevSecOps certifications are an advantage.

אודות Peer Security
פרופיל החברה · בקרוב

ביקורות עובדים · בקרובעוד משרות ב-Peer Security

שאלות על המשרה

  • המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
דומות וקשורות
Peer Security
פורסם אתמול · 0 מועמדים
בדקו את ההתאמה