SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tipalti is an AI-powered finance automation platform serving mid-market businesses globally. The company provides comprehensive solutions across accounts payable, global payouts, procurement, employee expenses, corporate cards, supplier management, tax compliance, and treasury. Tipalti partners with leading financial institutions and serves over 5,000 global companies, enabling secure payments to millions of suppliers across 200+ countries in 120 currencies.
As a Senior Product Security Engineer, you will join Tipalti's Product Security team to strengthen security across products and the software development lifecycle. This is a hands-on, engineering-focused role working closely with development and product teams.
Key responsibilities include:
- Perform hands-on security reviews of applications, APIs, services, and code
- Identify, investigate, validate, and assess product security vulnerabilities
- Provide practical remediation guidance and work with development teams through remediation
- Perform threat modeling and security analysis for new and existing product capabilities
- Work with application security tools including SAST, SCA, DAST, API Security, and WAF
- Improve and automate Product Security processes and security checks across the development lifecycle
- Assess security across modern application environments including web applications, APIs, microservices, containers, Kubernetes, and cloud-native services
- Support secure coding practices and provide security guidance to development teams
- Support vulnerability disclosure and Bug Bounty activities
- Contribute to continuous improvement of Product Security practices across the engineering organization
The Tel Aviv office operates on a hybrid model with two days per week working from home and three days from the North Tel Aviv office. Shuttle services and parking are available.
Requirements:
- 5+ years of hands-on experience in Application Security, Product Security, or closely related software security role
- Strong understanding of software development and ability to read, understand, and review application code with .NET, JavaScript/TypeScript, or comparable modern technologies
- Hands-on experience identifying and analyzing application and API security vulnerabilities
- Experience performing threat modeling and application security reviews
- Strong understanding of authentication, authorization, session management, web security, API security, and mobile security
- Strong knowledge of OWASP Top 10s and their practical remediation
- Hands-on experience with application security technologies such as SAST, SCA, DAST, API Security, WAF
- Experience with microservices, APIs, containers, Kubernetes, and cloud-native environments
- Knowledge of AWS security and/or Azure security
- Understanding of modern CI/CD and software development environments
- Strong analytical and problem-solving skills with ability to turn security findings into practical technical recommendations
- Strong communication and collaboration skills
Advantages:
- Experience developing security tooling or automation
- Experience with CI/CD and software supply chain security
- Experience with fintech, payments, or security-sensitive SaaS products
- Experience with vulnerability research, Bug Bounty, or vulnerability disclosure programs
- Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems
- Security research, open-source contributions, or other demonstrated hands-on security work