Security Architect & Engineer
- תל אביב
- משרה קבועה
- משרה מלאה
- Security Architecture & Engineering: Design, develop, and maintain secure systems, ensuring compliance with best practices in application, cloud, and infrastructure security.
- Threat Modeling & Risk Assessment: Identify potential vulnerabilities and risks across the system, applications, and services. Conduct threat modeling, security reviews, and risk assessments.
- Secure Development Practices: Define and promote secure coding standards (OWASP, SANS, etc.) across engineering teams, including code review with a security-first mindset.
- Security Tooling & Automation: Develop and integrate security tools for static analysis, vulnerability scanning, and threat detection in CI/CD pipelines.
- Incident Response & Mitigation: Lead investigations and incident response for security breaches. Collaborate with relevant teams to resolve issues and document findings.
- Mentorship & Leadership: Mentor engineers on security best practices, conduct security training, and promote security awareness throughout the organization.
- Cross-Functional Collaboration: Work closely with engineering, DevOps, compliance, and product teams to ensure security is embedded in every phase of the SDLC.
- Agile Participation: Participate in Agile ceremonies while championing secure software delivery within sprints and releases.
- Experience: 5+ years in application, cloud, or infrastructure security, preferably with a background in software engineering.
- Security Expertise: In-depth knowledge of application security, cloud security (AWS, Azure, GCP), network security, and container security.
- Programming Languages: Proficiency in one or more languages such as Golang or .NET.
- Security Standards: Deep familiarity with frameworks and standards such as OWASP, NIST, ISO 27001, CIS Benchmarks.
- Security Tools: Experience with tools like Snyk, Checkmarx, Nessus, Burp Suite, or equivalent vulnerability scanning and penetration testing tools.
- DevSecOps & Automation: Experience integrating security into CI/CD pipelines (e.g., GitLab, GitHub Actions, Jenkins).
- Cloud Platforms: Hands-on experience securing services and infrastructure in AWS, Azure, or GCP.
- Compliance Knowledge (Advantage): Understanding of data privacy regulations such as GDPR, CCPA, and industry-specific compliance (e.g., SOC 2, HIPAA).
- Education: Bachelor's or Master's degree in Computer Science, Cybersecurity, Software Engineering, or equivalent military/certification training.
- Experience with container orchestration security (Kubernetes, Docker).
- Familiarity with identity and access management (IAM), SSO, and federated authentication (OAuth2, SAML).
- Hands-on experience implementing SIEM and monitoring tools (e.g., Splunk, Datadog, Sentinel).
- Knowledge of secrets management solutions (Vault, AWS Secrets Manager).
- Experience in security incident simulation and red/blue team exercises.
- Contributions to security-related open-source projects or research.
- Published CVEs or security advisories (Advantage).
- Strong analytical and problem-solving skills with a security-oriented mindset.
- Excellent communication and stakeholder management.
- Ability to educate and influence engineers on secure development.
- Passion for cybersecurity and proactive learning of emerging threats and mitigation strategies.
Mploy