{"id":1308667,"url":"https://alion.io/job/cyesec-ltd-application-security-specialist","title":"Application Security Specialist","company":{"id":2196214,"name":"Cyesec Ltd.","domain":"cyesec.com","url":"https://alion.io/company/cyesec","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Lever","truth_index":{"grade":"C","score":58,"open_postings":10,"ghost_share":0.7,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-28T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Herzliya, Israel"],"countries":["IL"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":61000,"max_usd":148000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":227},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Java","optional":false},{"name":"LLM","optional":false},{"name":"Model Context Protocol","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"SDL","optional":false},{"name":"Threat Modeling","optional":false},{"name":"C","optional":true}],"status":"live","first_seen_at":"2026-06-30T14:31:40Z","employer_posted_date":"2026-06-30","last_verified_at":"2026-09-27T13:18:59Z","board_verified":true,"closed_at":null,"days_open":89,"trust":{"level":"ok","repost_count":0,"flags":["company_stale"],"days_open":89},"description":"CYEis looking for a talented Application Security Specialist to join our team. In this role, you will take an active part in application penetration testing, threat modeling, Secure SDLCactivities, and AppSec initiatives that help evaluate and improve security posture. The position includes hands-on security testing of web, mobile, API, thick client, AI/LLM integrations, and MCP-based application components, identifying and validating vulnerabilities, assessing real business impact, supporting customers with clear remediation guidance, and contributing to application security processes, tools, and best practices.\nResponsibilities\nPerform hands-on application penetration testing across web, mobile, API, thick client, AI/LLM integrations, and MCP-enabled application components.\n\nPerform threat modeling and secure design reviews to identify risks early in the development lifecycle.\n\nSupport development teams with practical remediation guidance and secure implementation recommendations.\n\nPerform Secure Software Development Lifecycle and secure coding training for developers.\n\nEvaluate and improve customers’ application security development lifecycle, including secure coding practices, vulnerability management, remediation workflows, and security gates.\n\nParticipate in client-facing discussions, including assessment scoping, finding walkthroughs, remediation alignment, and retest updates.\n\nQualifications\n2+ years of hands-on experience in application penetration testing.\n\nStrong understanding of OWASPTop 10 and CWETop 25, with proven experience identifying vulnerabilities and supporting practical remediation strategies.\n\nFamiliarity with high-level programming languages (Java, JS, Python, etc.).\n\nRelevant App PT training and certifications such as EWPTX, OSWE, etc.\n\nStrong English communication skills, with the ability to communicate technical topics clearly in client-facing discussions.\n\nAdvantage: Deep understanding of the LLM Top 10, AI security risks, MCPsecurity risks, and AI/LLM hacking techniques.\n\nAdvantage: Proven experience in secure code review or high-level code auditing.\n\nAdvantage: Knowledge of Secure SDLCpractices, and methodologies, including Microsoft SDL, OWASPSAMM, and OWASPASVS.","description_format":"text","description_chars":2232,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"Upper-Intermediate (B2)","optional":false}]},"benefits":[],"hiring_locations":[{"name":"Israel","iso":"IL","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Artificial Intelligence","Cybersecurity","AI Agents"],"lifecycle":[{"event":"open","at":"2026-09-26T15:15:14Z"}],"liveness":{"score":6,"band":"cold","label":"Long shot","p_open":1,"p_active":0.199,"p_room":0.28,"age_days":89,"expected_fill_days":15,"reasons":["conf:16","stale_co","win:tail","crowd:junior"],"computed_at":"2026-09-28T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/cyesec-ltd-application-security-specialist","json_url":"https://alion.io/job/cyesec-ltd-application-security-specialist.json","meta":{"generated_at":"2026-09-28T05:46:30Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3968,"day_limit":5000,"remaining_today":1032,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}