{"id":1823123,"url":"https://alion.io/job/cyera-application-security-lead","title":"Application Security Lead","company":{"id":17615,"name":"Cyera","domain":"cyera.com","url":"https://alion.io/company/cyera-com","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Comeet","truth_index":{"grade":"B","score":75,"open_postings":6,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":34,"computed_at":"2026-10-06T05:45:30Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Tel Aviv, Israel"],"countries":["IL"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":169000,"max_usd":432000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":504},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"GCP","optional":false},{"name":"Go","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Java","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"SOC 2","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"LLM","optional":true}],"status":"live","first_seen_at":"2026-10-04T07:10:02Z","employer_posted_date":"2026-10-04","last_verified_at":"2026-10-06T20:35:25Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Description\nCome join the company building the security operating model for the age of AI. AI has changed how data is used - and security must change with it. Cyera's mission is to empower businesses to accelerate AI Adoption by defining a holistic approach to securing AI - from data to access to model. Instead of perimeter controls and static policies, Cyera provides a unified control plane that understands relationships between data, access, and behaviors across humans, systems, and AI. Backed by the world's leading investors and working with a large and growing list of Fortune 1000 companies, we are looking for world-class talent to join us as we usher in the new era of data and AI security.\nAbout the Role\nOur customers trust Cyera with their most sensitive data, and we hold our own platform to the standard we set for the industry. We meet and exceed industry security standards, and we treat that as the baseline rather than the finish line.\nWe're looking for an Application Security Lead to own product security inside R&D and be the focal point at Cyera for validating how secure our platform is. Your mandate is continuous assurance: proving, through hands-on adversarial testing and architecture-level review, that no gaps exist across our code, infrastructure, and architecture - and keeping it that way as we ship fast.\nYou'll map our most sensitive areas, lead research and red team exercises against our own systems, run an internal bug bounty, define how R&D reasons about risk in development and production, and keep the engineering organization exercised and ready. This is a technical leadership role under Infrastructure, serving all of R&D and partnering closely with the Security organization, Product, and Engineering leadership. You'll start hands-on, with the mandate to build the function - and the team - around you.\nKey Responsibilities:\nOwn product security end to end and be the trusted authority on Cyera's security posture for R&D leadership, the Security organization, and our customers - able to answer \"how secure is our product?\" with evidence.\nLead continuous adversarial validation of our code, infrastructure, and architecture, confirming the strength of authorization, tenant isolation, business logic, and every path to sensitive data.\nMaintain a living map of Cyera's attack surface and sensitive data flows, and use it to focus assurance effort where the stakes are highest.\nRun threat modeling and security architecture review for new services, integrations, cloud connectors, and multi-tenant components - early enough to shape the design.\nOwn multi-tenancy and customer data boundaries: tenant isolation, authorization logic, secrets and key handling, and the controls that keep every customer's data unreachable from any other.\nSecure our AI and agentic surfaces - prompt injection, tool and agent authorization, and model and data boundaries for autonomous systems acting on customer data.\nLead red team exercises across production and pre-production, and run an internal bug bounty that puts Cyera engineers to work on our own code with real incentives and real follow-through.\nDefine risk management for our development and production environments: standards, severity models, security gates, and an exception process practical enough that teams follow it - and drive findings to verified, structural resolution.\nBuild the paved road for secure development: secure-by-default patterns and guardrails, SAST/DAST/SCA and secrets detection tuned so signal beats noise, and a security champions network across R&D. Scale assurance through automation and self-service rather than headcount.\nKeep the engineering organization exercised and incident-ready - tabletop drills, detection and forensic coverage in our own environments, escalation paths, and runbooks.\nRepresent product security externally, supporting customer security reviews, questionnaires, third-party penetration tests, and CISO-level conversations alongside the Security organization.\nRequirements\n8+ years in application security or product security, including hands-on ownership of a security program.\nDeep, current expertise in authentication and authorization, multi-tenant isolation, API and web security, cryptography and secrets management, software supply chain risk, and business logic vulnerabilities.\nAn attacker's mindset applied to systems you didn't build. You can read unfamiliar code, form a hypothesis about how it breaks, and prove it - and you can scope and direct red team work against your own organization.\nThreat modeling and security architecture review as a practiced discipline, ideally at a scale serving many engineering teams at once.\nStrong engineering background: you write code (Python, Go, TypeScript, Java, or similar), understand distributed systems, and hold credible design discussions with senior engineers.\nCloud-native security depth in AWS, GCP, or Azure - IAM, network boundaries, Kubernetes, containers, CI/CD security, and infrastructure-as-code - and comfort working shoulder-to-shoulder with DevOps and Infrastructure engineers.\nExperience embedding security across the development lifecycle from design through deployment, including secure SDLC processes and developer-facing tooling.\nTechnical leadership without authority: driving security outcomes across engineering teams through credibility, clarity, and prioritization.\nFluency in SOC 2, ISO 27001, or similar - enough to satisfy them efficiently, and the judgment to know where they stop.\nThe judgment to separate real risk from theoretical risk, and to say so plainly to engineers and executives alike.\nNice to have:\nExperience at a cybersecurity startup, especially one where the product itself was the trust boundary.\nExperience at a cloud-native SaaS company operating a multi-tenant platform at scale.\nExperience in high-consequence data environments - payments, financial services, crypto, or healthcare.\nOffensive security background: penetration testing, vulnerability research, exploit development, published CVEs, or service in an elite technology unit.\nExperience building or running a bug bounty program.\nSecurity experience with AI/ML systems, LLM applications, or agentic architectures - including using AI to scale security review itself.\nExperience securing data platforms or pipelines processing large volumes of sensitive data.\nExperience hiring, mentoring, and growing security engineers.\nContributions to the security community: research, open-source tooling, writing, or talks.","description_format":"text","description_chars":6523,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Cybersecurity","Information Security","Email Security"],"lifecycle":[{"event":"open","at":"2026-10-04T07:55:31Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":34,"reasons":["conf:1","velocity","win:early","comp:brand"],"computed_at":"2026-10-06T05:45:30Z"},"pay":null,"html_url":"https://alion.io/job/cyera-application-security-lead","json_url":"https://alion.io/job/cyera-application-security-lead.json","meta":{"generated_at":"2026-10-06T21:25:22Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":928,"day_limit":5000,"remaining_today":4072,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":17615},"rest":"https://alion.io/mcp/rest/get_company?id=17615"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fcyera-application-security-lead"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fcyera-application-security-lead"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fcyera-application-security-lead"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/cyera-application-security-lead\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fcyera-application-security-lead"}]}