
Senior Application Security Engineer
Forcepoint4 months ago
Tel Aviv-Yafo, IsraelSenior
Responsibilities
- Lead threat modeling, secure design, and architecture-review activities.
- Define and enforce secure coding standards, including OWASP Top 10 practices.
- Perform manual and tool-assisted code reviews, SAST, DAST, and penetration testing.
- Identify, triage, validate, and support remediation of vulnerabilities.
- Integrate security tools into CI/CD and DevSecOps pipelines and automate scanning, reporting, and ticketing workflows.
- Build tooling to scale application security across products.
- Apply AI/ML capabilities to vulnerability detection, prioritization, remediation, and secure SDLC risk management.
- Assess vulnerability risk, exploitability, and impact; prioritize remediation and maintain security-posture visibility.
- Partner with developers, product managers, and leadership to communicate risks and recommend practical fixes.
- Deliver security training and awareness and mentor engineers and junior AppSec team members.
- Act as a security champion across R&D and communicate security risks clearly.
Requirements
- Bachelor’s degree in Computer Science, Security, or equivalent experience.
- At least 5 years of experience in application security or software engineering with a security focus.
- Strong knowledge of web and application vulnerabilities, OWASP Top 10, secure coding, APIs, microservices, and cloud-native architectures.
- Hands-on experience with threat modeling and architecture reviews.
- Prior software development experience and strong coding skills, preferably in C++ and Java.
- Hands-on experience with ASPM, SAST, DAST, SCA, CI/CD, and DevSecOps pipelines.
- Advanced experience applying AI to secure SDLC and AppSec practices, including evaluating risks such as insecure code suggestions, data leakage, and supply-chain exposure.
- Strong communication, collaboration, and ability to explain security issues to technical and non-technical audiences.
- Preferred: CISSP, CSSLP, or OSCP certification.
- Preferred: experience with cloud-native stacks, Windows internals, AI or security automation workflows, and SOC2 or ISO27001 compliance frameworks.
Benefits
- Hybrid work model in the Forcepoint Tel Aviv office with a minimum of two days per week onsite.
- Applicants must have the right to work in the location to which they apply.
- Equal employment opportunity and reasonable accommodation support are provided.