Application Security Architect
Tel AvivFull Time
About the position
Lead secure application design and support development teams throughout the SDLC. Integrate and optimize security controls such as SAST, DAST, SCA and secrets scanning within CI/CD pipelines, review security findings, perform threat modeling, and work with engineering teams to prioritize and implement effective mitigations.
Responsibilities
- •Design and review secure application architectures across web, API, microservices, and AI-enabled environments.
- •Perform threat modeling and hands-on security reviews focused on OWASP Top 10, API risks, business logic flaws, and data exposure.
- •Review application code, architecture, and security controls to identify practical risks and remediation paths.
- •Help engineering teams embed security into the SDLC, including SAST, DAST, SCA, and CI/CD security controls.
- •Translate technical vulnerabilities into clear business risks for product, engineering, and executive stakeholders.
Qualifications
- •4+ years in cybersecurity, with strong application security or secure software development experience.
- •Proven experience designing secure application architectures and reviewing complex application ecosystems.
- •Ability to audit code in at least one programming language.
- •Hands-on experience with threat modeling, such as STRIDE.
- •Experience with SAST, DAST, SCA, findings triage, and guiding engineers through remediation.
- •Strong understanding of modern application stacks, including APIs, microservices, cloud-native applications, and AI/LLM integrations.
- •Excellent communication skills with engineers, product teams, and leadership.