עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
What You Will Do
As an Application Security Engineer, you will act as a bridge between offensive security and engineering teams. You will leverage your penetration-testing mindset to proactively improve the security of applications throughout their lifecycles. This includes partnering with developers to identify and remediate vulnerabilities, contributing to secure design decisions, participating in threat modeling, and conducting security reviews. You will help build scalable, repeatable security practices that reduce risk across the product.
Responsibilities
- Validating and prioritizing vulnerabilities from PTs, bug bounties, and tools
- Collaborating with engineering teams on remediation
- Participating in application security reviews
- Supporting Secure Software Development Lifecycle (SSDLC)
- Managing and using SAST, DAST, and SCA tools
- Developing security standards and best practices.
Requirements:
- 3–5 years of hands-on experience as a Penetration Tester (Web and API)
- Strong expertise in performing manual penetration testing (not tool-only)
- Deep understanding of OWASP Top 10 and OWASP Top 10 for LLM
- Ability to read and understand code in C#, JavaScript
- Knowledge of OWASP ASVS (Application Security Verification Standard)
- Strong communication skills with developers
- Strong English proficiency (written and spoken)
- Familiarity with cloud environments (AWS, Azure, or GCP)
- Experience with bug bounty programs or Red Team activities (advantage)
- Experience performing Application Security Reviews (advantage)
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
שאלות ותשובות עבור משרת Application Security Engineer
מהנדס אבטחת יישומים ב-SeeHR Cyber & Tech Recruiting משמש כגשר בין צוותי אבטחת התקפה לצוותי הנדסה. התפקיד כולל שימוש בחשיבה חודרנית לשיפור אבטחת היישומים לאורך מחזור חייהם, שיתוף פעולה עם מפתחים לזיהוי ותיקון פגיעויות, תרומה להחלטות עיצוב מאובטחות, השתתפות במידול איומים וביצוע סקירות אבטחה. המטרה היא לבנות שיטות אבטחה ניתנות להרחבה וחוזרות על עצמן המפחיתות סיכונים במוצר.
משרות נוספות מומלצות עבורך
-
Senior Application Security Engineer
-
ירושלים
RYB Technologies
-
-
מנחה ומבקר/ת אבטחת מידע אפליקטיבי
-
תל אביב - יפו
פרוסיד
-
-
Application Security Architect
-
תל אביב - יפו
Moveo Source
-
-
Senior/Staff Application Security Engineer
-
תל אביב - יפו
Nebius
-
-
מנחה ומבקר.ת אבטחת מידע אפליקטיב
-
תל אביב - יפו
Mertens - Malam Team
-
-
AI Security Engineer
-
ירושלים
Cross River
-