Forcepoint
SeniorApplicationSecurityEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Application Security Engineer at Forcepoint. Skills: Application security, Secure SDLC, DevSecOps, Threat modeling, Vulnerability management, AI/ML in security. Lead threat modeling and secure design (SxD) activities. Define and enforce secure coding standards”
Industry & Context.
Identify, triage, and validate vulnerabilities; Support remediation and verify fixes; Recommend practical and effective fixes; Evaluate and mitigate security risks such as insecure code suggestions, data leakage, and supply chain exposure
Minimum of two days per week working from the office, Applicants must have the right to work in the location to which you have applied.
What They're Looking For.
Must Have
Bachelor's degree in Computer Science, Security, or equivalent experience, 5+ years in Application security, 5+ years in Software engineering with a security focus, knowledge of Web/application vulnerabilities (OWASP Top 10), knowledge of Secure coding practices, knowledge of APIs, microservices, and cloud-native architectures, Hands-on experience in threat modeling and architecture reviews, Prior software development experience, coding skills, preferably, C++ and Java, ability to read, write, and review code effectively, Hands-on experience with ASPM, SAST, DAST, and SCA tools, Hands-on experience with CI/CD and DevSecOps pipelines, Advanced experience applying AI (e.g., code generation, analysis and exploitation) across secure SDLC and AppSec practices, including evaluating and mitigating security risks such as insecure code suggestions, data leakage, and supply chain exposure, ability to explain security issues in developer-friendly terms, ability to influence engineering decisions, ability to collaborate cross-functionally across R&D and product teams, Applicants must have the right to work in the location to which you have applied.
Nice to Have
Security certifications (e.g., CISSP, CSSLP, OSCP), Experience with cloud-native stack and Windows internal, Experience applying AI/automation in security workflows, Familiarity with regulatory and compliance frameworks (e.g., SOC2, ISO27001)
What You'll Do.
Lead threat modeling and secure design (SxD) activities
Define and enforce secure coding standards
Partner with engineering during architecture and design phases
Perform Static analysis (SAST)
Perform Dynamic testing (DAST)
Perform Penetration testing
and validate vulnerabilities
Support remediation and verify fixes
Integrate security tools into CI/CD pipelines
and ticketing workflows
Build tooling to scale AppSec across products
Leverage AI/ML capabilities to enhance vulnerability detection
and remediation workflows
Prioritize vulnerabilities and track remediation
Maintain security posture visibility across products
Work closely with developers to explain security findings
Work closely with developers to recommend practical and effective fixes
Work closely with developers to provide security guidance balancing usability and security
without impacting delivery
Deliver training and security awareness
Provide technical mentorship to engineers and junior AppSec team members
Act as a security champion across R&D
Communicate risk clearly to engineers
How You'll Work.
Team & Collaboration
Partner closely with engineering and product teams to embed security into the software development lifecycle (SDLC); Partner with engineering during architecture and design phases; Collaborate cross-functionally across R&D and product teams; Work closely with developers; Communicate risk clearly to engineers, product managers, and leadership
Communication Scope
Explain security findings to both technical and non-technical audience; Explain security issues in developer-friendly terms; Communicate risk clearly to engineers, product managers, and leadership
Full Job Description
**Who is Forcepoint?** Forcepoint simplifies security for global businesses and governments. Forcepoint’s all-in-one, truly cloud-native platform makes it easy to adopt Zero Trust and prevent the theft or loss of sensitive data and intellectual property no matter where people are working. 20+ years in business. 2.7k employees. 150 countries. 11k+ customers. 300+ patents. If our mission excites you, you’re in the right place; we want you to bring your own energy to help us create a safer world. All we’re missing is you! A Senior AppSec Engineer partners closely with engineering and product teams to embed security into the software development lifecycle (SDLC), proactively identify risks, and ensure secure design, development, and deployment of products. This role is based in the Forcepoint Israel office in Tel Aviv and follows a hybrid work model, with a minimum of two days per week working from the office. Key Responsibilities 1\. Secure SDLC & Design (Shift-left) * Lead threat modeling and secure design (SxD) activities * Define and enforce secure coding standards (e.g., OWASP Top 10) * Partner with engineering during architecture and design phases 2\. Security Testing & Validation * Perform: * Code reviews (manual and tool-assisted) * Static analysis (SAST) * Dynamic testing (DAST) * Penetration testing * Identify, triage, and validate vulnerabilities * Support remediation and verify fixes 3\. DevSecOps, Automation & AI Enablement * Integrate security tools into CI/CD pipelines * Automate scanning, reporting, and ticketing workflows * Build tooling to scale AppSec across products * Leverage AI/ML capabilities to enhance vulnerability detection, prioritization, and remediation workflows 4\. Risk Assessment & Vulnerability Management * Assess risk, exploitability, and impact * Prioritize vulnerabilities and track remediation * Maintain security posture visibility across products 5\. Engineering Partnership, Mentorship & Enablement * Work closely with developers to:
Applying for this Senior Application Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Forcepoint?
Real rants from real employees. Read before you apply.