About this role
Description
At ONE ZERO, Israel’s first fully digital bank, we’re building secure and innovative financial products that redefine the banking experience.
We are looking for a hands-on Application Security Engineer with a strong understanding of software development and application security across Web and Native Mobile applications . In this role, you will work closely with development teams to embed security throughout the SDLC, identify and mitigate risks, and help build secure-by-design solutions across our products and services.
Your Day-to-Day
- Embed security into the SDLC / SSDLC and work closely with development teams.
- Perform application security reviews, threat modeling, and security assessments.
- Identify vulnerabilities across Web, Android, iOS, APIs, CI/CD pipelines, and software supply-chain processes .
- Analyze business logic flaws, authorization issues, insecure workflows, and abuse scenarios.
- Help developers remediate vulnerabilities and design secure solutions.
- Improve and automate security controls across the development lifecycle.
- Build internal security tools for testing, detection, and prevention.
- Develop and integrate AI-powered security solutions , including LLM-based tools, agents, and automated code/security analysis.
Requirements
- 3–5 years of experience in Application Security, Product Security, Security Engineering , or software development with strong security experience.
- Strong understanding of software development and the ability to read and understand code.
- Hands-on knowledge of Web application security and Native Mobile security for Android and iOS .
- Good knowledge of OWASP, OWASP Mobile, API Security, authentication, authorization, and secure coding .
- Experience with CI/CD security, SAST, DAST, SCA, secrets management, and dependency risks .
- Ability to understand both technical vulnerabilities and business-logic security risks .
- Development or scripting experience in languages such as Python, Java, Kotlin, JavaScript/TypeScript, or similar.
- Hands-on familiarity with AI/LLM technologies and the ability to build security-focused tools or automations.
Advantages
- Previous experience as a software developer.
- Experience with Kotlin and/or Swift.
- Experience with mobile application internals and mobile security testing.
- Experience with cloud, Kubernetes, containers, or IaC.
- Experience with LLM APIs, AI agents, RAG, or AI-assisted code analysis.
- Understanding of AI security risks such as prompt injection, data leakage, and excessive permissions.