Application Security Lead
Administration · Full-time
Tel Aviv-Yafo, Israel
Application Security Lead
- R&D
- Tel Aviv
- Full-time
Description
Come join the company building the security operating model for the age of AI. AI has changed how data is used — and security must change with it. Cyera's mission is to empower businesses to accelerate AI Adoption by defining a holistic approach to securing AI - from data to access to model. Instead of perimeter controls and static policies, Cyera provides a unified control plane that understands relationships between data, access, and behaviors across humans, systems, and AI. Backed by the world's leading investors and working with a large and growing list of Fortune 1000 companies, we are looking for world-class talent to join us as we usher in the new era of data and AI security.
About the Role
Our customers trust Cyera with their most sensitive data, and we hold our own platform to the standard we set for the industry. We meet and exceed industry security standards, and we treat that as the baseline rather than the finish line.
We're looking for an Application Security Lead to own product security inside R&D and be the focal point at Cyera for validating how secure our platform is. Your mandate is continuous assurance: proving, through hands-on adversarial testing and architecture-level review, that no gaps exist across our code, infrastructure, and architecture — and keeping it that way as we ship fast.
You'll map our most sensitive areas, lead research and red team exercises against our own systems, run an internal bug bounty, define how R&D reasons about risk in development and production, and keep the engineering organization exercised and ready. This is a technical leadership role under Infrastructure, serving all of R&D and partnering closely with the Security organization, Product, and Engineering leadership. You'll start hands-on, with the mandate to build the function — and the team — around you.
Key Responsibilities:
Own product security end to end and be the trusted authority on Cyera's security posture for R&D leadership, the Security organization, and our customers — able to answer "how secure is our product?" with evidence.
Lead continuous adversarial validation of our code, infrastructure, and architecture, confirming the strength of authorization, tenant isolation, business logic, and every path to sensitive data.
Maintain a living map of Cyera's attack surface and sensitive data flows, and use it to focus assurance effort where the stakes are highest.
Run threat modeling and security architecture review for new services, integrations, cloud connectors, and multi-tenant components — early enough to shape the design.
Own multi-tenancy and customer data boundaries: tenant isolation, authorization logic, secrets and key handling, and the controls that keep every customer's data unreachable from any other.
Secure our AI and agentic surfaces — prompt injection, tool and agent authorization, and model and data boundaries for autonomous systems acting on customer data.
Lead red team exercises across production and pre-production, and run an internal bug bounty that puts Cyera engineers to work on our own code with real incentives and real follow-through.
Define risk management for our development and production environments: standards, severity models, security gates, and an exception process practical enough that teams follow it — and drive findings to verified, structural resolution.
Build the paved road for secure development: secure-by-default patterns and guardrails, SAST/DAST/SCA and secrets detection tuned so signal beats noise, and a security champions network across R&D. Scale assurance through automation and self-service rather than headcount.
Keep the engineering organization exercised and incident-ready — tabletop drills, detection and forensic coverage in our own environments, escalation paths, and runbooks.
Represent product security externally, supporting customer security reviews, questionnaires, third-party penetration tests, and CISO-level conversations alongside the Security organization.
Requirements
8+ years in application security or product security, including hands-on ownership of a security program.
Deep, current expertise in authentication and authorization, multi-tenant isolation, API and web security, cryptography and secrets management, software supply chain risk, and business logic vulnerabilities.
An attacker's mindset applied to systems you didn't build. You can read unfamiliar code, form a hypothesis about how it breaks, and prove it — and you can scope and direct red team work against your own organization.
Threat modeling and security architecture review as a practiced discipline, ideally at a scale serving many engineering teams at once.
Strong engineering background: you write code (Python, Go, TypeScript, Java, or similar), understand distributed systems, and hold credible design discussions with senior engineers.
Cloud-native security depth in AWS, GCP, or Azure — IAM, network boundaries, Kubernetes, containers, CI/CD security, and infrastructure-as-code — and comfort working shoulder-to-shoulder with DevOps and Infrastructure engineers.
Experience embedding security across the development lifecycle from design through deployment, including secure SDLC processes and developer-facing tooling.
Technical leadership without authority: driving security outcomes across engineering teams through credibility, clarity, and prioritization.
Fluency in SOC 2, ISO 27001, or similar — enough to satisfy them efficiently, and the judgment to know where they stop.
The judgment to separate real risk from theoretical risk, and to say so plainly to engineers and executives alike.
Nice to have:
Experience at a cybersecurity startup, especially one where the product itself was the trust boundary.
Experience at a cloud-native SaaS company operating a multi-tenant platform at scale.
Experience in high-consequence data environments — payments, financial services, crypto, or healthcare.
Offensive security background: penetration testing, vulnerability research, exploit development, published CVEs, or service in an elite technology unit.
Experience building or running a bug bounty program.
Security experience with AI/ML systems, LLM applications, or agentic architectures — including using AI to scale security review itself.
Experience securing data platforms or pipelines processing large volumes of sensitive data.
Experience hiring, mentoring, and growing security engineers.
Contributions to the security community: research, open-source tooling, writing, or talks.