
DevSecOps Engineer
- הרצליה
- משרה קבועה
- משרה מלאה
- Develop security testing plans and integrate into the software development lifecycle
- Perform and oversee security testing and manage remediation of identified vulnerabilities
- Promote cybersecurity awareness
- Work closely with DevOps, Dev and leaders to implement security controls
- Test new security systems and applications
- Design, develop, and implement secure software development and deployment pipelines, incorporating security best practices, automation, and continuous integration/continuous deployment (CI/CD) methodologies.
- Implement and manage security tools and technologies such as SCA, SAST, IaC Security, etc.
- Develop and enforce security policies, standards, and guidelines to ensure compliance with regulatory requirements and industry best practices.
- Analyze code generated via copilots and VIBE workflows to spot insecure patterns or misuse of libraries. Provide remediation advice or push automated security feedback into the dev process.
- Create secure coding guides and "secure prompt" playbooks for developers using copilots, ChatGPT, or other GenAI tools.
- Track how AI is influencing the codebase - e.g., increase in dependency usage, insecure AI patterns, or hallucinated code. Generate reports to influence tooling or policy updates
- At least 3+ years in software development, DevSecOps or a similar role
- Strong knowledge of software development methodologies, tools, and frameworks
- Experience with DevOps and CI/CD practices, including GitHub, Jenkins etc.
- Familiarity with cloud platforms (e.g., AWS, Azure, GCP)
- Proficiency in scripting and programming languages (e.g., Python, NodeJS, C)
- Strong problem-solving and analytical skills, with the ability to identify and mitigate security risks
- Demonstrated experience securing applications that involve AI components (e.g., LLMs, ML models, AI APIs).
- Ability to analyze and assess code generated by AI copilots and VIBE environments for security issues.
- Understanding of AI-specific attack vectors (ex. prompt injection/ AI manipulation, model abuse, data leakage, overreliance on AI-generated code).
- Excellent communication and collaboration skills, with the ability to work effectively in cross-functional teams
- Strong written and verbal communication skills, both in Hebrew and English
- Bachelor's degree in computer science
- Cyber Certification
- In-depth understanding of security principles, best practices, and industry standards (e.g., OWASP, NIST, ISO 27001)
- Experience in Dockers & K8
- Experience in Harness
- Familiarity with tools like GitHub Copilot, CodeWhisperer, ChatGPT, HuggingFace, LangChain, or internal AI copilots.