Application Security and SDLC Team Leader
Herzliya, Israel
CYE
CYE's optimized cyber risk management helps you gain visibility, quantify cyber risk, prioritize mitigation, and effectively communicate with stakeholders.
CYE is looking for a talented Application Security and Security Development Lifecycle Expert to be a part of our elite security researchers team. As an Application Security Leader, you will take an active role in leading various services including penetration testing and security development lifecycle activities that will help evaluate our customers’ security level and improve it. A typical job could be breaking into a segmented secure system at a Fortune 500 organization or perform a threat modeling process for a critical enterprise system.
Responsibilities
- Lead the application security team based on current/future tasks
- Identify, communicate, and drive the resolution of vulnerabilities
- Escort, evaluate and improve the application security development lifecycle of our customers
- Research and advocate for new application security solutions and technologies
- Continue to drive security evaluation earlier in the cycles through iterative security testing
- Ensure customers’ security by hands-on penetration testing, hypothesizing threats, helping development teams remediate risks upfront, and execute secure implementation efforts
- Improve secure coding and Secure-SDLC practices, application security requirements, automation, training, and metrics
- Lead the internal Secure-SDLC process of the R&D department in CYE.
Qualifications
- 5+ years of experience in Application Security Research including penetration testing, deep understanding of major Application Security attacks, vulnerabilities, and mitigations including XSS, CSRF, SQL Injection, Deserialization, RCE, etc.
- Experienced with Secure-SDLC methodologies and standards such as Microsoft SDL, OWASP SAMM, and OWASP ASVS
- Experienced with threat analysis processes
- Experienced with web & mobile application security, API analysis and unique client/ server architectures
- Experienced in code auditing and best practices
- Deep understanding of OWASP Top 10 and CWE 25; with proven track record and experience in implementing and integrating remediation strategies
- Managerial experience
- Relevant certifications such as CEH and EWPTX – an advantage
- Familiarity with a wide range of high-level programming languages (Java, JS, Python, etc.) – an advantage
- Familiarity with cloud environments – an advantage
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Categories:
AppSec Jobs
Leadership Jobs
Tags: APIs Application security Audits Automation CEH Cloud CSRF eWPTx Java OWASP Pentesting Python R&D SAMM SDLC SQL SQL injection Vulnerabilities XSS
Region:
Middle East
Country:
Israel
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsInformation System Security Officer jobsInformation Security Officer jobsSenior Cybersecurity Engineer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsCyber Security Specialist jobsIT Security Engineer jobsSystems Engineer jobsSenior Network Security Engineer jobsSystems Administrator jobsSenior Information Security Analyst jobsSecurity Consultant jobsSenior Cyber Security Engineer jobsSecurity Specialist jobsIT Security Analyst jobsChief Information Security Officer jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsThreat Intelligence Analyst jobsSenior Penetration Tester jobsCyber Security Architect jobsSecurity Operations Analyst jobsSenior Information Security Engineer jobsCyber Threat Intelligence Analyst jobs
Encryption jobsTop Secret jobsGDPR jobsSaaS jobsSplunk jobsMalware jobsEDR jobsRMF jobsSDLC jobsBash jobsSQL jobsForensics jobsIDS jobsThreat detection jobsIPS jobsActive Directory jobsFinance jobsDoDD 8570 jobsIntrusion detection jobsITIL jobsCompTIA jobsCRISC jobsDocker jobsTerraform jobsGIAC jobs
OWASP jobsHIPAA jobsSOC 2 jobsClearance Required jobsSANS jobsUNIX jobsCCSP jobsIndustrial jobsSAP jobsOSCP jobsJavaScript jobsVPN jobsTCP/IP jobsAnsible jobsBanking jobsDNS jobsPolygraph jobsSOX jobsData Analytics jobsMachine Learning jobsIT infrastructure jobsJira jobsCISO jobsVMware jobsNIST 800-53 jobs