Back

Senior Security Engineer - AppSec & Cloud

R&D
Ramat Gan (Bursa)
Share

Sola's security team is looking for a Senior Security Engineer to own product and application security end to end, from threat modeling and secure design through deep code review, our private bug bounty program, and the security of our AI and agentic systems. Sola builds an AI platform that security teams point at their own stack, which means researchers look at us closely and customers ask hard questions.

The role is broad, and that is the appeal. One moment you are working through a bug with the developers, the next you are analyzing an incident, and the following morning you are in a design review advising on what matters for security. We are looking for someone with wide knowledge who is comfortable wearing several hats: real depth in one area, and the curiosity to get up to speed quickly on the rest.

You will work as part of Sola's security team, with the opportunity to take on wider responsibilities than a narrowly defined role would allow. We are looking for someone who collaborates easily, with the team and with R&D, and who can carry a mission end to end on their own expertise, from the first design conversation through to the fix in production.


What you'll do

  • Lead threat modeling, secure design reviews, and penetration testing for Sola products and services, from the app to cloud services, APIs, and internal platforms.
  • Perform deep code review and manual testing on high-risk systems, using AI-assisted review processes and covering the areas automated tooling cannot fully reach.
  • Build and operate security automation. Use and extend AI-assisted tooling for continuous code review, finding triage, and automated penetration testing, and step in where human judgment is required.
  • Secure Sola's AI and agentic systems. Assess AI-native products, LLM integrations, and agent workflows for the risks specific to them.
  • Partner with engineering teams to drive remediation, turning recurring findings into guardrails, secure defaults, and paved paths.
  • Run our private bug bounty program, from triage and severity through to a landed fix with R&D.
  • Own WAF rule design and tuning, balancing coverage against false positives on live traffic.
  • Investigate and respond to application security incidents, including root cause analysis and durable corrective action.
  • Contribute to Sola's secure development lifecycle and to our compliance work.



What You Bring

What you have

  • At least 5 years of hands-on experience in application security, product security, security engineering, DevSecOps, or a closely related field.
  • Strong command of secure coding and common vulnerability classes, across the OWASP Top 10 and well beyond it.
  • Hands-on secure development experience across several languages.
  • Practical penetration testing, security assessment, and vulnerability management experience with standard tooling and manual techniques alike.
  • Experience with cloud security on AWS, GCP, or Azure.
  • Working knowledge of authentication, authorization, cryptography, and secure architecture patterns.
  • Familiarity with securing AI systems: LLM integrations, agent workflows, and MCP servers and tools.
  • A track record of carrying missions end to end on your own expertise: scoping the work, driving it through engineering, and owning the result.
  • A genuine team player who is comfortable embedded in an engineering squad. You can disagree with a design, explain why, and leave the relationship intact.
  • Clear technical communication for both engineers and non-technical partners across regions. You can explain the same risk to a developer, a founder, and a customer's security team without changing what is true.

Bonus points

  • Deep cloud security knowledge across the major providers, especially AWS.
  • A security certification such as OSCP, OSWE, or an AWS or GCP security specialty.
  • Experience running a bug bounty program end to end, from triage through to the fix shipping.
  • Familiarity with SOC 2 Type 2 and ISO 27001, and with supporting audits.
  • Building and delivering security training for R&D.
  • Being introduced by someone on the Sola team.

Get a personalized demo

By pressing the submit button, you confirm that you have read, understood, and agree to the privacy policy and the Terms & Conditions.