
Staff Product Security Engineer
- פתח תקווה
- משרה קבועה
- משרה מלאה
- Work on a wide range of technologies
- Work on complex architectural and technical challenges
- Participate in threat modelling activities
- Mentor and collaborate with development teams to adopt secure coding practices
- Work on strategic and highly visible security activities across the organisation
- Be an advocate for security and participate in a security champions program
- 6+ years of experience in software security (AppSec)
- 3+ years of experience in threat modelling software applications and services
- Proficient in threat modelling methodologies such as STRIDE or PASTA and their applied use in fast-moving, iterative development lifecycles
- In-depth knowledge of common web application vulnerabilities (OWASP Top 10)
- Developer-level proficiency in one or more languages - Python, Java, JavaScript, and Golang preferred
- Working knowledge of Machine Learning and taxonomies such as BIML that categorise known attacks on machine learning models
- In-depth knowledge of software design patterns and their security considerations
- In-depth knowledge of authentication and authorisation standards, including OAuth, OIDC, SAML, JWT, and PASETO
- Knowledge of symmetric and asymmetric cryptography, digital signatures, PKI, TLS, and cryptographic hash functions