1,229,538open jobs
69,967companies
213,807added this week
Browse all
Salary
≈ $154k – $408k per year (Estimated)
Location
In office (Tel Aviv)
Seniority
Staff · 8+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Oct 4, 2026. Cyera scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Cyera is a cybersecurity company headquartered in New York City, New York, and founded in 2021. The company provides an AI-native data security platform that enables enterprises to discover, classify, and protect sensitive information across cloud, SaaS, on-premises, and artificial intelligence environments. It serves global enterprises in sectors such as financial services, healthcare, and manufacturing, operating through a software-as-a-service model with support from major venture capital firms.

Description

Come join the company building the security operating model for the age of AI. AI has changed how data is used - and security must change with it. Cyera's mission is to empower businesses to accelerate AI Adoption by defining a holistic approach to securing AI - from data to access to model. Instead of perimeter controls and static policies, Cyera provides a unified control plane that understands relationships between data, access, and behaviors across humans, systems, and AI. Backed by the world's leading investors and working with a large and growing list of Fortune 1000 companies, we are looking for world-class talent to join us as we usher in the new era of data and AI security.

About the Role

Our customers trust Cyera with their most sensitive data, and we hold our own platform to the standard we set for the industry. We meet and exceed industry security standards, and we treat that as the baseline rather than the finish line.

We're looking for an Application Security Lead to own product security inside R&D and be the focal point at Cyera for validating how secure our platform is. Your mandate is continuous assurance: proving, through hands-on adversarial testing and architecture-level review, that no gaps exist across our code, infrastructure, and architecture - and keeping it that way as we ship fast.

You'll map our most sensitive areas, lead research and red team exercises against our own systems, run an internal bug bounty, define how R&D reasons about risk in development and production, and keep the engineering organization exercised and ready. This is a technical leadership role under Infrastructure, serving all of R&D and partnering closely with the Security organization, Product, and Engineering leadership. You'll start hands-on, with the mandate to build the function - and the team - around you.

Key Responsibilities:

Own product security end to end and be the trusted authority on Cyera's security posture for R&D leadership, the Security organization, and our customers - able to answer "how secure is our product?" with evidence.

Lead continuous adversarial validation of our code, infrastructure, and architecture, confirming the strength of authorization, tenant isolation, business logic, and every path to sensitive data.

Maintain a living map of Cyera's attack surface and sensitive data flows, and use it to focus assurance effort where the stakes are highest.

Run threat modeling and security architecture review for new services, integrations, cloud connectors, and multi-tenant components - early enough to shape the design.

Own multi-tenancy and customer data boundaries: tenant isolation, authorization logic, secrets and key handling, and the controls that keep every customer's data unreachable from any other.

Secure our AI and agentic surfaces - prompt injection, tool and agent authorization, and model and data boundaries for autonomous systems acting on customer data.

Lead red team exercises across production and pre-production, and run an internal bug bounty that puts Cyera engineers to work on our own code with real incentives and real follow-through.

Define risk management for our development and production environments: standards, severity models, security gates, and an exception process practical enough that teams follow it - and drive findings to verified, structural resolution.

Build the paved road for secure development: secure-by-default patterns and guardrails, SAST/DAST/SCA and secrets detection tuned so signal beats noise, and a security champions network across R&D. Scale assurance through automation and self-service rather than headcount.

Keep the engineering organization exercised and incident-ready - tabletop drills, detection and forensic coverage in our own environments, escalation paths, and runbooks.

Represent product security externally, supporting customer security reviews, questionnaires, third-party penetration tests, and CISO-level conversations alongside the Security organization.

Requirements

8+ years in application security or product security, including hands-on ownership of a security program.

Deep, current expertise in authentication and authorization, multi-tenant isolation, API and web security, cryptography and secrets management, software supply chain risk, and business logic vulnerabilities.

An attacker's mindset applied to systems you didn't build. You can read unfamiliar code, form a hypothesis about how it breaks, and prove it - and you can scope and direct red team work against your own organization.

Threat modeling and security architecture review as a practiced discipline, ideally at a scale serving many engineering teams at once.

Strong engineering background: you write code (Python, Go, TypeScript, Java, or similar), understand distributed systems, and hold credible design discussions with senior engineers.

Cloud-native security depth in AWS, GCP, or Azure - IAM, network boundaries, Kubernetes, containers, CI/CD security, and infrastructure-as-code - and comfort working shoulder-to-shoulder with DevOps and Infrastructure engineers.

Experience embedding security across the development lifecycle from design through deployment, including secure SDLC processes and developer-facing tooling.

Technical leadership without authority: driving security outcomes across engineering teams through credibility, clarity, and prioritization.

Fluency in SOC 2, ISO 27001, or similar - enough to satisfy them efficiently, and the judgment to know where they stop.

The judgment to separate real risk from theoretical risk, and to say so plainly to engineers and executives alike.

Nice to have:

Experience at a cybersecurity startup, especially one where the product itself was the trust boundary.

Experience at a cloud-native SaaS company operating a multi-tenant platform at scale.

Experience in high-consequence data environments - payments, financial services, crypto, or healthcare.

Offensive security background: penetration testing, vulnerability research, exploit development, published CVEs, or service in an elite technology unit.

Experience building or running a bug bounty program.

Security experience with AI/ML systems, LLM applications, or agentic architectures - including using AI to scale security review itself.

Experience securing data platforms or pipelines processing large volumes of sensitive data.

Experience hiring, mentoring, and growing security engineers.

Contributions to the security community: research, open-source tooling, writing, or talks.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,229,538 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Tel Aviv
≈ $105k – $237k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Tel Aviv
AI/ML
Cursor
Claude Code
Multimodal AI
LLM
OpenAI Codex
DevOps
Terraform
CI/CD
AWS
Docker
Kubernetes
IAM
Cybersecurity
CIS Benchmarks
Least Privilege
SIEM
OWASP
Apply
≈ $110k – $249k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Tel Aviv
Python
JavaScript
SQL
AI/ML
AI Agents
LLM
Apply
≈ $95k – $215k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Tel Aviv
AI/ML
Computer Vision
Machine Learning
DevOps
Splunk
GCP
Azure
CI/CD
AWS
IAM
Cybersecurity
ISO 27001
SentinelOne
SOC 2
GDPR
IBM QRadar
SIEM
Apply
≈ $76k – $211k per year (Estimated) • Hybrid • Herzliya
Apply
≈ $66k – $154k per year (Estimated) • In office • Full-Time • Düsseldorf
Cybersecurity
SIEM
Apply
≈ $13k – $35k per year (Estimated) • Remote (India) • 2+ years exp • Delhi • Gurgaon
Python
JavaScript
TypeScript
Node JS
DevOps
Rest API
GCP
GitHub Actions
CI/CD
AWS
IAM
Cybersecurity
Burp Suite
Snyk
SonarQube
ISO 27001
OWASP Top 10
SOC 2
Threat Modeling
Apply
$21k – $35k per year (gross) • Remote (India) • 3+ years exp • Gurgaon
Python
Go
Bash
AI/ML
Machine Learning
DevOps
Terraform
GCP
GitHub Actions
Istio
Terragrunt
Linkerd
CI/CD
ArgoCD
AWS
Docker
Kubernetes
Immutable Infrastructure
Platform Engineering
Atlantis
GitHub
IAM
Apply
Technical Lead 1 day ago
$31k – $47k per year (gross) • In office • 8+ years exp • Noida
JavaScript
Java
TypeScript
Groovy
Java
Spring Framework
Spring Boot
Hibernate
Hazelcast
Databases
MySQL
Redis
Oracle
Apache Kafka
AI/ML
Copilot
Cursor
Claude
Claude Code
Edge AI
Frontend
Angular
Bootstrap
JQuery
DevOps
Jenkins
Git
AWS
Nginx
Management
Confluence
Jira
Agile
Apply
$23k – $40k per year (gross) • Remote (India) • 3+ years exp • Gurgaon
Python
Go
Rust
Databases
PostgreSQL
CockroachDB
Cassandra
RabbitMQ
Apache Kafka
DevOps
gRPC
Apply
Hybrid • 3+ years exp • Bengaluru • Hyderabad • Gurgaon
Python
TypeScript
SQL
Python
FastAPI
Databases
Redis
DevOps
CI/CD
AWS
Docker
Kubernetes
Apply
Security Engineer 17 days ago
$80k – $150k per year • Hybrid • Full-Time • 2+ years exp • New York
Python
SQL
YARA
AI/ML
AI Agents
Agentic Workflows
DevOps
Terraform
CloudFormation
AWS
IAM
Cybersecurity
YARA
SIEM
Management
Agile
Apply
$200k – $250k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • New York
DevOps
GCP
Azure
AWS
IAM
Cybersecurity
SIEM
Apply
$300k – $360k per year • Hybrid • Full-Time • 8+ years exp • Minneapolis
DevOps
GCP
Azure
AWS
Apply
$120k – $160k per year • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • New York
SQL
DevOps
GCP
Azure
AWS
Apply
$250k – $275k per year • Equity • Remote (United States) • Full-Time • Los Angeles
DevOps
Azure
AWS
IAM
Cybersecurity
DLP
Apply
≈ $110k – $249k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Tel Aviv
Python
JavaScript
SQL
AI/ML
AI Agents
LLM
Apply
In office • 2+ years exp • Bachelor's Degree • Tel Aviv
DevOps
GCP
Apply
Hybrid • Tel Aviv
AI/ML
AutoGen
LangChain
Prompt Engineering
Chain-of-Thought
AI Agents
NLP
LLM
RAG
Sentiment Analysis
Agentic Workflows
Multi-Agent Systems
Apply
≈ $104k – $228k per year (Estimated) • Hybrid • 5+ years exp • Tel Aviv
AI/ML
AI Agents
Machine Learning
Cybersecurity
SIEM
Apply
≈ $88k – $217k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Tel Aviv
DevOps
GCP
Azure
AWS
Kubernetes
IAM
Apply
See all jobs
This is one of many
1,229,538 more open roles from verified company boards, updated every day.