Application Security- Pen Tester
2 days ago
Summary
Data has never been more valuable and vulnerable. As cybercriminals become more sophisticated and regulations more strict, organizations struggle to answer one key question: "Is my data safe?"
At Varonis, we see the world of cybersecurity differently. Instead of chasing threats, we believe the most practical approach is protecting data from the inside out. We've built the industry's first fully autonomous Data Security Platform to help our customers dramatically reduce risk with minimal human effort.
At Varonis, we move fast. We're an ultra-collaborative company with brilliant people who care deeply about the details. Together, we're solving interesting and complex puzzles to keep the world's data safe.
We work in a flexible, hybrid model, so you can choose the home-office balance that works best for you.
We are looking for an Application Security – Pen Tester to join the Application Security team responsible for Varonis' application security.
The successful candidate will be responsible for contributing to our Cloud/On-prem strategic security program.
Responsibilities:
- Conduct on-going Penetration testing activities across all Varonis platforms and services
- Identify and facilitate remediation of application and cloud security exposures and vulnerabilities
- Work to obtain the right mandate to ensure no new Varonis products or services are launched without the appropriate security controls
- Take a part in development lifecycle and integration of security features into all phases of software design and development
- Manage, aggregate, triage and track Vulnerabilities identified by external Assessors.
- Assist in implementing Security Testing tools (Dynamic, Static and Runtime) in the Varonis Testing pipeline
- Assist in defining testing scenarios for the Continuous Integration tests to cover identified vulnerabilities
- Work closely with R&D to enhance application security on all layers
Requirements:
- 3+ years of hands-on experience in Penetration Testing for application and cloud environments.
- Thorough understanding of cyber security frameworks, such as NIST CSF, CIS CSC
- Understanding of Cloud)AWS & Azure) technologies and SaaS environments
- Experience with web & application security, familiar with OWASP frameworks, solutions, and initiatives
- Experience with security solutions such Vulnerability scanners, and DAST solutions and more
- Experience with Container and K8s
- Experience conducting application penetration testing.
- Technical experience in network security technologies or security operations with a proven ability to engage and drive product and engineering priorities
- Work with the business to identify, capture, escalate, and close security vulnerabilities found in Varonis products.
- Leverage tools to deliver vulnerability information back to the development organization for remediation.
- Coordinate security risk assessments for new products & solutions through the risk assessment team.
- Maintain a risk register and risk visual with clearly defined owners for each risk.
- Contribute to product/solution security frameworks and standards to reduce development cycle of new products and services and to ensure consistency across the different products and platforms.
- Develop, institute, and maintain cloud security architecture standards
Advantages
CISSP, CISM, CCSP, CEH, OSCP is an advantage
Interfaces:
- Partner with key product & solutions development leaders to ensure security is incorporated in all customer-facing product offerings.
- Build solid working relationships with business stakeholders to maintain and improve product and application security processes.
- Partner with architecture and development leaders to develop shared software frameworks to enable consistent application of secure coding best practices across the enterprise.
- Research latest security best practices when it comes to device/instrument/IoT, staying current on new vulnerabilities and threats, and ensure these are addressed in Varonis' products and services.
We invite you to check out our Instagram Page to gain further insight into the Varonis culture
@VaronisLife
Varonis is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status, and other legally protected characteristics.
LI-HybridLI-IO
-
Application Security- Pen Tester
2 days ago
Herzliya, Tel Aviv, Israel Varonis Full timeSummaryData has never been more valuable and vulnerable. As cybercriminals become more sophisticated and regulations more strict, organizations struggle to answer one key question: "Is my data safe?"At Varonis, we see the world of cybersecurity differently. Instead of chasing threats, we believe the most practical approach is protecting data from the inside...
-
HW Security Application Engineer
4 days ago
Herzliya, Tel Aviv, Israel Ethosia Full timeJob Description:Owner of turnkey technical and compliance kits including reference software, test assets, and full conformance documentation for product HW security.Drive end-to-end technical readiness for HW security regulations across company products.Provide technical support for qualification and certification with external labs, working closely with the...
-
Head of IT Application
4 days ago
Herzliya, Tel Aviv, Israel SolarEdge Technologies Full timePower the Future with usAt SolarEdge (NASDAQ: SEDG), we're a global leader in smart energy technology, with over 3,000 employees, offices in 30 countries, and millions of installations worldwide.Our innovative solutions include solar inverters, battery storage, backup systems, EV charging, and AI-based energy management. We're committed to making clean,...
-
Security Architect
2 weeks ago
Herzliya, Tel Aviv, Israel AppsFlyer Full timeAppsFlyer's Security Engineering team is seeking a Security Architect to help design and implement solutions to secure AppsFlyer application, Infrastructure and cloud solutions. This role will have a significant impact across our engineering ecosystem. Your role will be to design and implement secure solutions with a focus on Product security, CI\CD and...
-
Security Architect
3 days ago
Herzliya, Tel Aviv, Israel AppsFlyer Full timeAppsFlyer's Security Engineering team is seeking a Security Architect to help design and implement solutions to secure AppsFlyer application, Infrastructure and cloud solutions. This role will have a significant impact across our engineering ecosystem. Your role will be to design and implement secure solutions with a focus on Product security, CI\CD and...
-
Senior Security Researcher
5 days ago
Herzliya, Tel Aviv, Israel Microsoft Full timeHelp shape the team culture and practices. Research and discover zero-day vulnerabilities in AI applications, models, and AI service ecosystems. Work closely with Red Team operators and engineering teams to address findings and strengthen resilience of AI-driven systems. Develop tools and techniques to scale and accelerate adversary emulation and...
-
Principal Security Researcher
5 days ago
Herzliya, Tel Aviv, Israel Microsoft Full timeOverviewBe a part of the team that is instrumental in constructing one of Microsoft's most exciting security solutions, and work on an innovative new product. In an era of increasingly sophisticated cyber-attacks, the Microsoft 365 Defender security suite has emerged as a vital tool for enterprises, enabling them to identify, scrutinize, counter advanced...
-
Principal Security Research
2 weeks ago
Herzliya, Tel Aviv, Israel Microsoft Full timeOverviewThe Azure Networking Security Research (ANSR) team is part of a Network Security organization within Azure Networking. Network Security organization is driving several security products and charted with Azure backend network security. As part of this mission, ANSR is charted with exposing critical security gaps in the core system of entire Azure (not...
-
Principal Security Research
2 weeks ago
Herzliya, Tel Aviv, Israel Microsoft Full timeOverviewThe Azure Networking Security Research (ANSR) team is part of a Network Security organization within Azure Networking. Network Security organization is driving several security products and charted with Azure backend network security. As part of this mission, ANSR is charted with exposing critical security gaps in the core system of entire Azure (not...
-
Security Engineer
5 days ago
Herzliya, Tel Aviv, Israel CodeValue Full timeCodeValue is looking for a skilled and experiencedSecurity Architectto join our team and take a leading role in designing, implementing, and governing the security posture of our cloud and enterprise environments. This individual will work closely with cross-functional teams to ensure security is embedded across systems, applications, and workflows, aligning...