Application Security Engineer
ONE ZERO Digital Bank Tel-Aviv, Tel-Aviv District, Israel
Financial Services · 201-500 employees
About the role
You will embed security into the SDLC by performing threat modeling, security assessments, and vulnerability identification across web and mobile platforms. Additionally, you will develop internal security tools and integrate AI-powered solutions to automate security controls and remediate risks.
What they look for
Requirements
Candidates must have 3-5 years of experience in application security or software development with a strong understanding of secure coding practices. Proficiency in programming languages such as Python, Java, or Kotlin and hands-on experience with mobile and web security testing are required.
Full description
At ONE ZERO, Israel’s first fully digital bank, we’re building secure and innovative financial products that redefine the banking experience.
We are looking for a hands-on Application Security Engineer with a strong understanding of software development and application security across Web and Native Mobile applications. In this role, you will work closely with development teams to embed security throughout the SDLC, identify and mitigate risks, and help build secure-by-design solutions across our products and services.
מי אנחנו?
null
Your Day-to-Day
- Embed security into the SDLC / SSDLC and work closely with development teams.
- Perform application security reviews, threat modeling, and security assessments.
- Identify vulnerabilities across Web, Android, iOS, APIs, CI/CD pipelines, and software supply-chain processes.
- Analyze business logic flaws, authorization issues, insecure workflows, and abuse scenarios.
- Help developers remediate vulnerabilities and design secure solutions.
- Improve and automate security controls across the development lifecycle.
- Build internal security tools for testing, detection, and prevention.
- Develop and integrate AI-powered security solutions, including LLM-based tools, agents, and automated code/security analysis.
מה מחכה לך?
null
Requirements
- 3–5 years of experience in Application Security, Product Security, Security Engineering, or software development with strong security experience.
- Strong understanding of software development and the ability to read and understand code.
- Hands-on knowledge of Web application security and Native Mobile security for Android and iOS.
- Good knowledge of OWASP, OWASP Mobile, API Security, authentication, authorization, and secure coding.
- Experience with CI/CD security, SAST, DAST, SCA, secrets management, and dependency risks.
- Ability to understand both technical vulnerabilities and business-logic security risks.
- Development or scripting experience in languages such as Python, Java, Kotlin, JavaScript/TypeScript, or similar.
- Hands-on familiarity with AI/LLM technologies and the ability to build security-focused tools or automations.
למי זה מתאים?
null
Advantages
- Previous experience as a software developer.
- Experience with Kotlin and/or Swift.
- Experience with mobile application internals and mobile security testing.
- Experience with cloud, Kubernetes, containers, or IaC.
- Experience with LLM APIs, AI agents, RAG, or AI-assisted code analysis.
- Understanding of AI security risks such as prompt injection, data leakage, and excessive permissions.
מה כולל התפקיד?
null
Similar roles
-
Forward Deployed Security Engineer
Stripe Dublin, Leinster, Ireland
-
Senior Consultant - Cybersecurity
Malomatia Doha, Qatar
-
Application Security
Malomatia Doha, Qatar
-
Consultant - Cybersecurity
Malomatia Doha, Qatar
-
Senior Security Engineer
MyHeritage Or Yehuda, Tel-Aviv District, Israel
-
ETIC, Cybersecurity IAM/IDAM - Manager
PwC Cairo, Cairo, Egypt