12 hours ago
Tel Aviv-Yafo, IsraelSenior
Responsibilities
- Perform penetration testing, vulnerability scanning, and code reviews to identify application security weaknesses.
- Collaborate with development teams on vulnerability remediation and secure coding practices.
- Define and implement SAST, DAST, and SCA testing strategies.
- Use LLMs, agents, and MCP-based tooling to improve AppSec workflows and establish safe usage practices.
- Build security tooling, CI/CD integrations, internal services, and AI-assisted workflows.
- Maintain application security policies, standards, and procedures.
- Research and evaluate application security tools and technologies.
- Monitor application security metrics and report on application security posture.
- Participate in application security incident response activities.
- Promote a security-first culture across the engineering organization.
Requirements
- At least 4 years of experience as an Application Security Engineer or in a similar role.
- Strong understanding of OWASP Top 10, CWE Top 25, and SANS Critical Security Controls.
- Experience with application security testing tools and techniques, including SAST, DAST, and SCA.
- Proficiency in at least one scripting language such as Python, JavaScript, or Ruby.
- Experience with secure coding practices and vulnerability remediation.
- Familiarity with CI/CD pipelines and DevOps practices.
- Experience with cloud platforms; AWS experience is an advantage.
- A bachelor's degree in Computer Science or a related field is a plus.
- Strong communication and collaboration skills, with the ability to work independently and as part of a team.
Benefits
- Competitive compensation package including base salary and equity.
- Health insurance with a discount for family members.
- Hybrid work at Via's office in Midtown, TLV, near the light rail and train station.
- Career development and growth opportunities.
- Freefit and other sports lessons, 10bis/Cibus, happy hours, team events, communities, and other perks.