עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
At UpSecurity, we’re looking for an experienced, highly technical, hands-on Product Security professional to join our team and lead product security initiatives across a diverse range of clients — from technology companies to large, complex organizations.
This role sits at the intersection of Application Security, DevSecOps, Cloud Security, and Security Consulting.
You’ll work directly with developers, DevOps teams, architects, security leaders, and executives — translating security requirements and risks into practical solutions across code, infrastructure, and development processes.
Responsibilities
• Design, build, and implement Secure Software Development Lifecycle (SSDLC) processes across organizations.
• Conduct Threat Modeling, Architecture Reviews, and Security Design Reviews.
• Work closely with development and DevOps teams to design and implement secure solutions.
• Assess the security of web applications, APIs, gateways, backend services, and communication protocols.
• Implement and improve SAST, SCA, DAST, Secrets Scanning, and IaC Scanning within CI/CD pipelines.
• Define Security Gates, Branch Protection, and vulnerability remediation workflows.
• Analyze penetration testing reports, prioritize findings, and drive remediation through closure.
• Technically validate vulnerabilities, perform Root Cause Analysis, and recommend code- and architecture-level solutions.
• Lead Vulnerability Management and Continuous Exposure Management processes.
• Support the security of cloud environments, containers, and Kubernetes.
• Work with Cloudflare solutions across WAF, DNS, DDoS protection, and Zero Trust.
• Translate SOC 2 and other compliance requirements into practical technical security controls.
• Participate in security incident response, including investigation, containment, and technical remediation.
• Develop security standards, guidelines, and documentation for development and infrastructure teams.
• Independently manage security initiatives and deliverables across multiple clients, end to end.
Qualifications
• 4+ years of experience in Product Security, Application Security, or DevSecOps.
• Hands-on experience building or implementing SSDLC processes.
• Experience conducting Threat Modeling and Architecture Reviews.
• Strong knowledge of web and API security, authentication and authorization mechanisms, and OWASP principles.
• Hands-on experience with CI/CD environments and tools for scanning code, dependencies, secrets, and Infrastructure as Code.
• Ability to read code, understand application logic, and write code or scripts.
• Strong hands-on knowledge of Linux environments.
• Experience with at least one major cloud platform: AWS, Azure, or GCP.
• Ability to analyze security findings and work directly with developers on remediation at both the code and architecture levels.
• Ability to work independently and lead processes across multiple stakeholders.
• Strong communication skills and the ability to work effectively with both technical and management teams.
• Professional proficiency in Hebrew and English.
Strong Advantages
• Hands-on Penetration Testing experience.
• Previous security consulting or multi-client experience.
• Experience training developers and driving Secure Coding Practices.
• Familiarity with SOC 2, ISO 27001, or similar frameworks.
*** This role is for people who enjoy connecting security with engineering — professionals who can move seamlessly from an architecture discussion with a CTO to hands-on work with developers and DevOps teams.
We’re looking for someone who doesn’t stop at identifying vulnerabilities, but wants to understand the root cause, build the right solution, and drive its implementation through to closure.
Interested? We’d love to hear from you.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.