עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
In this role, you will work closely with our R&D team to empower our developers to maintain a high security posture of our products. The person should have a security-centric mindset consistent with modern approaches for incorporating security into the SDLC in a fast-moving, agile environment.
Key Responsibilities:
Establish and maintain set of security requirements and best practices in SDLC
Work closely with engineering teams to provide relevant security requirements and ensure that security considerations are integrated into software development projects:
Threat modeling of new and existing features and products.
Review the deployment of our products
Ensure the security of CI/CD.
Design and architect new security features for the Platform
Conduct security code reviews
Align our products with recognized security benchmarks and standards within the industry
Develop supporting security tools.
At least 3 years of hands-on experience in software engineering, with a subsequent focus on application security
Familiarity with Threat modeling models like STRIDE.
Proficient in software engineering, with a preference for experience in Python, JavaScript, and Bash scripting
Familiarity with Cloud architecture like AWS, Azure,GCP.
Strong understanding of Networking, Operation systems, containerization (Docker and Kubernetes).
Background in modern application security principles, especially for web applications (the OWASP Top Ten Risks and beyond)
Excellent English written and verbal communication
A proactive learner with a strong interest in adopting new technologies and methodologies in application security.
Ability to work independently with a strong sense of ownership
Advantages:
Prior experience working as Security Architect, Security Engineer or Software Architect
Experience with the following technologies: OIDC, OAuth, SAML, PKI, TLS, DNS
Professional certifications like Certified Information Systems Security Professional (CISSP) or Offensive Security Certified Professional (OSCP) are a plus
Experience with containerized and microservice application architectures
Demonstrated security research activities (e.g. participation in bug bounties or credit for reporting CVEs)
Examples of thought leadership activities in the security space (e.g. blog posts or conference talks).
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.