עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
Role Description
As an Application Security Engineer at Peer Security, you will work closely with customer development, engineering, and security teams to embed security throughout the Software Development Lifecycle (SSDLC).
The role combines hands-on Application Security, cloud security, vulnerability management, and penetration testing, with a strong focus on modern development environments, including AI-assisted development and AI-powered applications.
You will help customers identify security risks, understand their real-world impact, prioritize remediation, and implement practical security controls across applications, APIs, cloud environments, and CI/CD pipelines.
Responsibilities
- Support and implement Secure Software Development Lifecycle (SSDLC) practices across customer environments.
- Perform secure code reviews and identify security vulnerabilities in applications and APIs.
- Work hands-on with Wiz to identify, investigate, prioritize, and remediate cloud security risks and vulnerabilities.
- Analyze Wiz findings and help development and security teams understand the actual attack paths, exposure, and business impact behind identified risks.
- Work closely with developers to promote secure coding practices across traditional and AI-powered applications.
- Participate in penetration testing activities for web applications and APIs, and support the validation and remediation of identified vulnerabilities.
- Apply practical understanding of manual penetration testing techniques, including authentication and authorization testing, business logic vulnerabilities, injection flaws, API security issues, and other OWASP Top 10 risks.
- Participate in threat modeling, architecture reviews, and security design discussions for new features and services.
- Help integrate security testing tools such as SAST, DAST, and SCA into CI/CD pipelines.
- Guide development teams through AI-related projects, from architecture and design through implementation and deployment.
- Advise teams on secure usage of LLMs, AI APIs, and AI-assisted coding tools such as GitHub Copilot, Cursor, and Claude Code.
- Review AI-generated code and help identify security weaknesses introduced through AI-assisted development.
- Work with engineering teams to prioritize vulnerabilities based on exploitability, exposure, and business impact.
- Support automation of security controls and security checks throughout development and deployment workflows.
Qualifications
- Minimum 3 years of hands-on experience in Application Security, secure software development, cloud security, or a closely related cybersecurity role.
- Hands-on experience with Wiz – mandatory.
- Strong understanding of penetration testing methodologies and techniques – mandatory.
- Good understanding of common web application and API vulnerabilities, including the OWASP Top 10.
- Ability to understand vulnerability findings beyond automated scanner results and evaluate their exploitability and real-world impact.
- Solid familiarity with modern software development processes, including Git workflows, pull requests, code reviews, and CI/CD environments.
- Understanding of cloud security concepts and modern cloud architectures.
- Basic hands-on familiarity with security testing tools and Application Security methodologies.
- Strong problem-solving and communication skills, with the ability to work directly with development and engineering teams.
Nice to Have
- Hands-on experience performing web application and API penetration testing.
- Experience manually identifying and exploiting vulnerabilities rather than relying solely on automated tools.
- Experience with Burp Suite or similar application security testing tools.
- Experience identifying and exploiting OWASP Top 10 vulnerabilities in real-world environments.
- Experience testing applications and infrastructure in AWS, GCP, or Azure.
- Experience with additional CNAPP, CSPM, vulnerability management, or cloud security technologies.
- Familiarity with AI/LLM security risks, including prompt injection, insecure output handling, sensitive information disclosure, excessive agency, and other OWASP LLM-related risks.
- Experience guiding development teams through AI feature or LLM integration projects.
- Hands-on experience with AI-assisted development tools such as GitHub Copilot, Cursor, or Claude Code.
- Familiarity with threat modeling and secure architecture reviews.
- Relevant Application Security, penetration testing, or cloud security certifications are an advantage.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
שאלות ותשובות עבור משרת Application Security Engineer
כמהנדס אבטחת יישומים ב-Peer Security, תפקידך המרכזי הוא לשלב אבטחה לאורך כל מחזור חיי פיתוח התוכנה (SSDLC) של הלקוחות. זה כולל עבודה צמודה עם צוותי פיתוח, הנדסה ואבטחה של הלקוחות כדי לזהות סיכוני אבטחה, להבין את השפעתם בעולם האמיתי, לתעדף תיקונים וליישם בקרות אבטחה מעשיות ביישומים, ממשקי API, סביבות ענן וצינורות CI/CD.
משרות נוספות מומלצות עבורך
-
Senior AppSec Engineer
-
תל אביב - יפו
Dream
-
-
Senior Security Engineer
-
תל אביב - יפו
Lemonade
-
-
Senior Application Security Engineer
-
ירושלים
RYB Technologies
-
-
מנחה ומבקר/ת אבטחת מידע אפליקטיבי
-
תל אביב - יפו
פרוסיד
-
-
Senior Product Security Engineer
-
תל אביב - יפו
Zenity
-
-
Senior/Staff Application Security Engineer
-
תל אביב - יפו
Nebius
-