What you will be responsible for:
Build & automate: Develop and maintain internal security tooling, automated workflows, and AI security agents. Code integrity: Execute secure code reviews and provide actionable remediation guidance to engineering teams. Vulnerability management: Lead the tracking, triaging, and reporting of security flaws across all product lines. Best practice advocacy: Drive the adoption of secure coding standards, partnering with R&D and DevOps teams to embed security early and often. Extend our D&R capabilities: Build scalable solutions to identify malicious activity, triage alerts, and investigate and remediate incidents. Document: Draft requirement documents for security products and innovative technologies.
The top candidate will also have:
* Endless curiosity and passion for emerging technology
* Ability to handle prioritize and execute multiple tasks simultaneously.
* Ability to work collaboratively across multiple departments.
* Fluent in Hebrew & English – ability to lead meetings and present.
* Strong communication and collaboration skills.
Why you should join us:
* Family-friendly environment and flexible working hours.
* Our global team is made up of awesome forward thinking, innovative go-getters.
* Learning and growth opportunities within a fast-paced tech startup environment.
* Clear career advancement path for strong performers.
* We are committed to setting each other up for success. As a member of our team, you will work within an environment that encourages growth, initiative taking and continuous mutual feedback in order to reach your full potential.
* And of course, Cibus and lots of yummy treats in the kitchen:-)
* 2-4 years experience as an Application Security Engineer or similar role from a Software Development Company
* In-depth knowledge in threat modeling, risk management, and security controls.
* Experience with AI Security and Security AI.
* Proficiency with OWASP Top 10: API, LLM, and Agentic applications.
* Hands-on competency integrating security tools such as SAST, DAST, SCA, and API security testing.
* Familiarity with CI/CD pipelines and Infrastructure as Code implementation.
* Practical background in software development and coding.
* Extensive knowledge of cloud technologies and cloud-native applications, AWS and GCP.
* Cybersecurity certifications such as OSCP, GPEN, CSSLP – big advantage!
* Fluent communication in Hebrew and English



















