10 hours ago
Tel Aviv-Yafo, IsraelMid Level
Responsibilities
- Partner with development and product teams on application and product security throughout the software development lifecycle.
- Perform hands-on security reviews of applications, APIs, services, and code.
- Identify, investigate, validate, and assess product security vulnerabilities and findings.
- Provide remediation guidance and work with development teams through remediation.
- Perform threat modeling and security analysis for new and existing product capabilities.
- Use and improve application security technologies and controls, including SAST, SCA, DAST, API Security, and WAF.
- Assess security across web applications, APIs, microservices, containers, Kubernetes, and cloud-native services.
- Support secure coding practices and provide practical security guidance to development teams.
- Support vulnerability disclosure and Bug Bounty activities, including technical validation, risk assessment, and remediation follow-up.
- Improve and automate Product Security processes, tooling, and security checks across the development lifecycle.
Requirements
- At least 3 years of hands-on experience in Application Security, Product Security, or a closely related software security role.
- Ability to read, understand, and review application code using .NET, JavaScript/TypeScript, or comparable modern technologies.
- Hands-on experience identifying and analyzing application and API security vulnerabilities.
- Experience performing threat modeling and application security reviews.
- Strong understanding of authentication, authorization, session management, web security, API security, and mobile security.
- Strong knowledge of OWASP Top 10 and practical remediation techniques.
- Hands-on experience with SAST, SCA, DAST, API Security, and WAF technologies.
- Experience with microservices, APIs, containers, Kubernetes, and cloud-native environments.
- Knowledge of AWS security and/or Azure security.
- Understanding of modern CI/CD and software development environments.
- Strong analytical, problem-solving, communication, and collaboration skills.
- Experience developing security tooling or automation, CI/CD and software supply chain security, fintech or payments, vulnerability research, Bug Bounty, vulnerability disclosure programs, or security research is advantageous.
- Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems is advantageous.
Benefits
- Hybrid work model with two days per week working from home and three days per week in the North Tel Aviv office.
- Shuttle services are available from the nearest train station and across Tel Aviv.
- Parking is available for all employees.
- Snacks and treats are available on every floor.
- Competitive benefits, flexible workplace, career coaching, and an inclusive work environment.
Tech Stack
Categories
About Tipalti
Tipalti builds a cloud platform for finance automation, used by mid-market companies to manage accounts payable, global payouts, procurement, expenses, supplier onboarding, tax compliance, and treasury. It sells its software as a SaaS subscription and partners with Citi, Wells Fargo, J.P. Morgan, and Visa for payments and card capabilities. Founded in 2010, the privately held company is headquartered in Foster City, California, and supports supplier payments across 200+ countries and multiple currencies.