Application Security Engineer
Rishon Lezion
ControlUp
ControlUp digital employee experience (DEX) platform unburdens IT teams so they can proactively deliver a superior digital experience across the enterprise powered by true real-time visibility, actionable insights, and automated remediation...
About ControlUpControlUp is a Digital Experience Monitoring and Optimization platform that transforms the way IT admins manage their environment and troubleshoot issues. Our product suite enables IT Admins to be more proactive and have greater visibility into the digital experience of their users. Most of our customers utilize Citrix, VMware, Nutanix, and/or Microsoft for their virtualization layer. Additionally, we have many customers who utilize IGEL thin clients.
Our CultureWe have a fun and energetic company culture. We fly team members to fun locations across the globe. We value a culture of transparency and curiosity. This is a company with a sense of humor, where we all are hard workers, but we balance that with lots of hilarity interspersed with that hard work.
The RoleWe are seeking an Application Security Engineer with a strong technical background in identifying and mitigating security vulnerabilities in web applications. This role goes beyond traditional security assessments - you will play a key part in strengthening our security posture by performing vulnerability research, developing automation tools, collaborating closely with development teams, and fostering a security-first mindset across the organization.
Our CultureWe have a fun and energetic company culture. We fly team members to fun locations across the globe. We value a culture of transparency and curiosity. This is a company with a sense of humor, where we all are hard workers, but we balance that with lots of hilarity interspersed with that hard work.
The RoleWe are seeking an Application Security Engineer with a strong technical background in identifying and mitigating security vulnerabilities in web applications. This role goes beyond traditional security assessments - you will play a key part in strengthening our security posture by performing vulnerability research, developing automation tools, collaborating closely with development teams, and fostering a security-first mindset across the organization.
Who we’re looking for:
- A skilled and pragmatic security expert – You focus on meaningful improvements rather than chasing perfection
- A collaborative problem-solver – You work with developers, product managers, and other teams to integrate security seamlessly, understanding that patience and teamwork drive real change.
- An adaptable and proactive mindset – you’re open to contributing in various ways to enhance security, whether that’s automating processes, educating teams, or helping shape a strong security culture beyond just running pentests
Responsibilities:
- Continuously assess and challenge Controlup’s overall security posture to ensure it's free from vulnerabilities.
- Participate in design reviews and threat modeling sessions.
- Work closely with development, devops and product teams to ensure vulnerabilities are avoided at an early stage.
- Review and prioritize findings of code scanning tools (SAST, SCA)
- Build automations to assist with detecting vulnerabilities.
- Educate Developers and Devops engineer about
- Answer on technical questions raised by customers
Requirements:
- 3+ years of experience in web application security/penetration testing.
- A Deep understanding of web and cloud security threats, exploits, prevention.
- Ability and willingness to write scripts/tools to automate security tasks.
- Ability to communicate complex security concepts to both technical and non-technical audiences clearly and effectively.
- A team player with an “in it together” approach.
- A proactive and creative mindset
Nice to have's
- Previous experience in an Application Security role within a SaaS company.
- Application security certificates such as OSWE, eWPTX, GWEB, GWAPT.
- Previous experience with security pitfalls of Hybrid SAAS products (on-premise agents talking with cloud services)
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
3
1
0
Categories:
AppSec Jobs
Security Engineering Jobs
Tags: Application security Automation Citrix Cloud DevOps eWPTx Exploits GWAPT Monitoring OSWE Pentesting SaaS SAST Security assessment VMware Vulnerabilities
Perks/benefits: Startup environment
Region:
Middle East
Country:
Israel
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsInformation System Security Officer jobsInformation Security Officer jobsSenior Cybersecurity Engineer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsCyber Security Specialist jobsIT Security Engineer jobsSystems Engineer jobsSenior Network Security Engineer jobsSystems Administrator jobsSenior Information Security Analyst jobsSecurity Consultant jobsSenior Cyber Security Engineer jobsSecurity Specialist jobsIT Security Analyst jobsChief Information Security Officer jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsThreat Intelligence Analyst jobsSenior Penetration Tester jobsCyber Security Architect jobsSecurity Operations Analyst jobsSenior Information Security Engineer jobsCyber Threat Intelligence Analyst jobs
Encryption jobsTop Secret jobsGDPR jobsSaaS jobsSplunk jobsMalware jobsEDR jobsRMF jobsSDLC jobsBash jobsSQL jobsForensics jobsIDS jobsThreat detection jobsIPS jobsActive Directory jobsFinance jobsDoDD 8570 jobsIntrusion detection jobsITIL jobsCompTIA jobsCRISC jobsDocker jobsTerraform jobsGIAC jobs
OWASP jobsHIPAA jobsSOC 2 jobsClearance Required jobsSANS jobsUNIX jobsCCSP jobsIndustrial jobsSAP jobsOSCP jobsJavaScript jobsVPN jobsTCP/IP jobsAnsible jobsBanking jobsDNS jobsPolygraph jobsSOX jobsData Analytics jobsMachine Learning jobsIT infrastructure jobsJira jobsCISO jobsVMware jobsNIST 800-53 jobs