SlipstreamJobsFresh Startup & VC-Backed Jobs

Product Security Engineer

Tipalti - Tel Aviv, Israel - Hybrid - posted 2026-09-16

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Tipalti is an AI-powered finance automation platform serving mid-market businesses globally. The company provides comprehensive solutions for accounts payable, global payouts, procurement, employee expenses, corporate cards, supplier management, tax compliance, and treasury. Tipalti partners with leading financial institutions and enables over 5,000 global companies to securely pay millions of suppliers across 200+ countries in 120 currencies. As a Product Security Engineer on Tipalti's Product Security team, you will take a hands-on, engineering-focused approach to strengthening security across products and the software development lifecycle. You will work closely with development and product teams to identify security risks, improve application security, and implement practical security solutions. Key responsibilities include: - Performing hands-on security reviews of applications, APIs, services, and code - Identifying, investigating, validating, and assessing product security vulnerabilities - Providing practical remediation guidance and working with development teams through remediation - Performing threat modeling and security analysis for new and existing product capabilities - Working with application security tools (SAST, SCA, DAST, API Security, WAF) - Improving and automating Product Security processes and security checks across the development lifecycle - Assessing security across modern application environments (web applications, APIs, microservices, containers, Kubernetes, cloud-native services) - Supporting secure coding practices and providing security guidance to development teams - Supporting vulnerability disclosure and Bug Bounty activities - Contributing to continuous improvement of Product Security practices across the engineering organization The Tel Aviv office operates on a hybrid model: two days per week remote, three days per week in-office in North Tel Aviv. Shuttle services and parking are available. REQUIREMENTS: - 3+ years of hands-on experience in Application Security, Product Security, or closely related software security role - Strong understanding of software development and ability to read, understand, and review application code with .NET, JavaScript/TypeScript, or comparable modern technologies - Hands-on experience identifying and analyzing application and API security vulnerabilities - Experience performing threat modeling and application security reviews - Strong understanding of authentication, authorization, session management, web security, API security, and mobile security - Strong knowledge of OWASP Top 10s and their practical remediation - Hands-on experience with application security technologies (SAST, SCA, DAST, API Security, WAF) - Experience with microservices, APIs, containers, Kubernetes, and cloud-native environments - Knowledge of AWS security and/or Azure security - Understanding of modern CI/CD and software development environments - Strong analytical and problem-solving skills with ability to turn security findings into practical technical recommendations - Strong communication and collaboration skills ADVANTAGES: - Experience developing security tooling or automation - Experience with CI/CD and software supply chain security - Experience with fintech, payments, or security-sensitive SaaS products - Experience with vulnerability research, Bug Bounty, or vulnerability disclosure programs - Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems - Security research, open-source contributions, or other demonstrated hands-on security work

Similar roles