jobify_logo ×
  • מִשׁתַמֵשׁ
  • התחברות/הרשמה
  • עמוד הבית
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות
קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service work_office המקום
jobify_logo
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
דילוג לתוכן

עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!

במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

Application Security Engineer

Pontera

Pontera Pontera

  • הרצליה
  • LinkedIn
LinkedIn

Application Security Engineer

Pontera

Pontera Pontera

  • הרצליה
  • bag_icon מלאה
  • LinkedIn
LinkedIn


Pontera is a FinTech SaaS company on a mission to help millions of Americans retire better by enabling financial advisors to manage, rebalance, and report on 401(k) and other retirement plan accounts. Pontera customers range from Fortune 100 financial services firms and large independent broker dealers to small independent RIA’s and advisory firms.

At Pontera, we are proud of our people-first mentality and culture. You will have the unique and exciting opportunity to be part of a team whose mission is to scale Pontera into one of the largest FinTech companies in the world. We have significant funding from some of the most notable venture capital investors, led by Lightspeed Venture Partners, and are in a period of hyper-growth. The next critical step in our trajectory is adding to our world-class team, and that’s where you come in.

We are seeking a skilled Application Security Engineer to join our security team at Pontera, a rapidly growing fintech company, pioneering innovative solutions in the financial technology space. This role encompasses a comprehensive scope of application security responsibilities, with a significant focus on web application and API security.

Responsibilities

  • Managing vulnerabilities across our application, including identification, triaging, validation and mitigation, in collaboration with developers, product owners, and QA
  • Configuring and maintaining security testing tools integrated within the CI/CD pipeline
  • Facilitating pentests and bug bounty programs in partnership with external firms
  • Conducting secure development training to enhance team awareness and skills in security best practices
  • Collaborating with product teams to ensure security is integrated throughout the SDLC, focusing on product security from conception to deployment
  • Ensuring the security of web applications and APIs against common attack techniques
  • Developing strategies for the mitigation of potential security threats

Requirements

  • 3-5 years of proven experience in application security
  • A collaborative team player with excellent problem-solving skills, able to work effectively across various teams and independently tackle challenges
  • Passionate about security, continuously seeking knowledge in the latest industry trends, and driven to handle complex issues with creative solutions and leadership
  • Profound knowledge and experience with OWASP guidelines are essential. The candidate must be well-versed in identifying, analyzing, and mitigating vulnerabilities in web application and API security.
  • Strong understanding and practical experience in defending against common attack vectors such as Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), SQL Injection, and others. The ability to not only recognize but effectively mitigate these threats is critical.
  • In-depth experience with SCA, SAST, Secrets scanning, DAST.
  • Familiarity with vulnerability rating techniques and models like CVSS, CWE, OWASP Risk Rating, and DREAD.
  • Strong understanding of Java, Angular, and SQL. While not required to write code, should be able to understand and review code for security vulnerabilities.
  • Proficiency in GitHub, Jira, and IntelliJ IDEA (or similar IDEs).
  • Experience with microservices architecture and container technologies like Docker and Kubernetes.
  • Strong proficiency in English, both written and verbal, is essential.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. In lieu of a formal degree, substantial experience in application security or a related area will be considered.
  • Preferred Certifications: Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), GIAC Web Application Penetration Tester (GWAPT), GIAC Secure Software Programmer - .NET/Java (GSSP) or Other relevant certifications in the field of cybersecurity and ethical hacking.
  • Valuable Experience: Demonstrated experience in identifying and resolving security vulnerabilities. This can include a proven track record of filing CVEs, active participation in bug bounty programs, or achievements in CTF competitions.

What We Offer

  • Opportunity: Have a major impact at a fast-growing startup that is revolutionizing the FinTech industry
  • Team Culture: A collegial, collaborative, fun work environment with frequent team events
  • Equity: All new hires are eligible for equity grant participation
  • Professional Development: Sponsored learning & development program
  • Work Flexibility: A hybrid office work model (In-Office Mon/Tues/Weds and WFH Sun//Thurs)


במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

משרות נוספות מומלצות עבורך
  • רשימת משאלות

    Senior Security Engineer

    • map_icon תל אביב - יפו
    Lemonade

    Lemonade

  • רשימת משאלות

    Senior Application Security Engineer

    • map_icon ירושלים
    RYB Technologies

    RYB Technologies

  • רשימת משאלות

    מנחה ומבקר/ת אבטחת מידע אפליקטיבי

    • map_icon תל אביב - יפו
    פרוסיד

    פרוסיד

  • רשימת משאלות

    Application Security Architect

    • map_icon תל אביב - יפו
    Moveo Source

    Moveo Source

  • רשימת משאלות

    מנחה ומבקר.ת אבטחת מידע אפליקטיב

    • map_icon תל אביב - יפו
    Mertens - Malam Team

    Mertens - Malam Team

  • רשימת משאלות

    Senior/Staff Application Security Engineer

    • map_icon תל אביב - יפו
    Nebius

    Nebius

לכל המשרות של מהנדס אבטחת יישומים

ניתן לצפות במשרות שסימנת בכל שלב תחת התפריט הראשי בקטגוריית 'משרות שאהבתי'

המקום קרן עזריאלי טקסט בעברית עם סמל אינסוף
  • מי אנחנו
  • מעסיקים מובילים
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות

2026 Ⓒ ג'וביפיי - כל הזכויות שמורות

קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service israel_innovation_authority work_office המקום
המערכת בונה את הפרופיל התעסוקתי שלך

עוד רגע...

המערכת זיהתה ששינית את הנתונים באזור האישי ומעדכנת את ההמלצות על תפקידים ומשרות בהתאם.

מצטערים, לא הצלחנו לנתח בהצלחה את הנתונים שהזנת.
אתם מוזמנים לנסות להזין שוב או להעלות קובץ קורות חיים במידה ויש לכם.
בהצלחה

הגעת להגבלה היומית של שלושה עדכונים בפרופיל האישי ביום

loader

הבקשה שלך נשלחה בהצלחה!

יש באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות מיועצת קריירה.

באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות

  • בעיה טכנית

  • סיוע בכתיבת קורות חיים או בהכנה לראיון עבודה

  • התאמה של משרות

  • אחר:

פנייתך נשלחה בהצלחה. נציג מטעם ארגון נכי צהל ייצור איתך קשר בהקדם