Application Security Engineer
Sunbit Tel-Aviv, Tel-Aviv District, Israel
Financial Services · 501-1,000 employees
About the role
You will identify security gaps across Sunbit's products and development lifecycle to design and implement scalable security controls. You will also collaborate with R&D and engineering teams to integrate security into architectures, CI/CD pipelines, and AI-powered features.
What they look for
Requirements
Candidates must have at least 5 years of hands-on experience in application security, product security, or a related field. Strong proficiency in securing cloud-native workloads, APIs, and modern CI/CD workflows is required.
Full description
At Sunbit, we're building financial technology that puts people first. By combining intelligent decisioning with a personalized, transparent approach, we help consumers access the payment options that are right for them while empowering merchants to build stronger customer relationships.
Engineering is at the heart of how we make that happen. We build scalable distributed systems, cloud-native services, intelligent data platforms, and AI-powered solutions that enable real-time financial decisions at scale. By leveraging modern engineering practices and integrating AI into both our products and development workflows, we solve complex technical challenges, accelerate innovation, and continuously improve the way we build software. Every service, model, and architectural decision we make directly impacts our products, our customers, and the future of financial technology.
About the Role
We are looking for an Application Security Engineer to join our Security Engineering team.
You will take ownership of strengthening security across Sunbit’s products, services, and development lifecycle. This includes identifying and addressing security gaps in application architecture and code, APIs and service-to-service communication, authentication and authorization flows, open source dependencies and third-party libraries, CI/CD pipelines and build systems, secrets handling, and AI-powered product features.
As a Security Engineer at Sunbit, you will dig into how our systems actually work, understand where the real risk is, and decide what needs to be built to close it. Some problems are solved by changing an architecture or a design pattern, others by implementing a new control, embedding a security gate into the pipeline, integrating and tailoring a security platform, or writing something from scratch. You will own that decision and the implementation that follows.
The Security Engineering team works as a group of all-rounders. Alongside your core focus, you will contribute to cloud and infrastructure security, corporate IT security, detection engineering, incident response, and our growing AI security work, both securing AI workloads and using AI to make our own security capabilities better.
What You Will Work On
- Identify security gaps across Sunbit’s applications, services, and development lifecycle, then translate them into practical technical solutions.
- Design and implement scalable security controls that address root causes and fit our architecture and engineering practices.
- Review architectures and designs, run threat modeling, and guide R&D teams toward secure patterns before code is written.
- Secure APIs, authentication and authorization flows, service-to-service trust, data handling, and multi-tenant boundaries.
- Own the secure development lifecycle end to end, including security gates in GitHub Actions, SAST, SCA, secrets scanning, and dependency and supply chain risk.
- Build reusable security capabilities, libraries, paved-road patterns, and developer-facing tooling that make the secure path the default path.
- Build custom AI agents and AI-powered capabilities that improve our security tools, workflows, visibility, and control.
- Understand and secure AI-powered product features, including their data access, identities, permissions, integrations, and runtime behavior.
- Partner with R&D, DevOps, Infrastructure, Data, AI, and IT teams from initial analysis through implementation, adoption, and validation.
Requirements
- At least 5 years of hands-on experience in application security, product security, security engineering, DevSecOps, or a related field.
- Strong experience securing production applications and services, including APIs, microservices, and cloud-native workloads on AWS and Kubernetes.
- Proven ability to identify security gaps, design appropriate controls, and take solutions through implementation.
- Hands-on experience with secure code review, threat modeling, API security, and common vulnerability classes in modern application stacks.
- Practical experience embedding security into CI/CD and GitOps workflows, including GitHub Actions, SAST, DAST, SCA, and secrets scanning.
- Strong understanding of authentication and authorization, session management, secrets management, cryptography in practice, TLS, SSO, SAML, and OIDC.
- Ability to read and write code in at least one modern language, and enough engineering depth to work as a peer to developers.
- A broad security mindset, strong engineering judgment, and the ability to collaborate effectively with technical teams.
Nice to Have
- Experience building AI agents, LLM-based tools, or AI-powered security capabilities.
- Experience assessing or securing AI workloads, including data exposure, prompt injection, agent permissions, and third-party integrations.
- Experience with ASPM platforms, WAF, bot and abuse prevention, or runtime application protection.
- Familiarity with cloud and infrastructure security, Terraform, policy as code, and container security.
- Offensive security background, such as penetration testing, bug bounty, or exploit development.
- Experience working in a regulated fintech or financial services environment.
Recruitment Fraud Disclaimer
We’ve been made aware of fraudsters impersonating Sunbit employees during the hiring process. Please note that all official communication will come from an @sunbit.com email address, through our applicant tracking platform @sunbit.comeet-notifications.com or directly via LinkedIn. We will never ask for your age, Social Security number, bank account details, payment of any kind, or other unrelated personal information during the application process. Our hiring process always includes interviews, either by phone, zoom, or in person, before any offer is made. If something feels suspicious, please contact us at HR to confirm. We ask that you contact HR only about potential instances of fraud. HR does not reach our recruiting team directly. Your application directly through the posting is the best way to ensure that your candidacy is reviewed by our team. Due to the volume of applications, we will not respond to nor forward emails about your candidacy that are sent to HR directly, and your email about your application will be deleted from our systems.
Similar roles
-
Cloud Security Engineer
Gifthealth Inc Columbus, Ohio, United States · $115K–$150K/yr
-
Senior Cybersecurity Engineer (Identity and Access Management)
Open Dealer Exchange Southfield, Michigan, United States
-
Cybersecurity Engineer
Open Dealer Exchange Southfield, Michigan, United States
-
Senior Information Security Engineer
Zscaler United States · $134K–$168K/yr
-
Cybersecurity Analyst
Smiths Group Pune, Maharashtra, India
-
Staff Product Security Engineer
Affirm Canada · CA$181K–CA$241K/yr