{"id":1347762,"url":"https://alion.io/job/tipalti-senior-product-security-engineer","title":"Senior Product Security Engineer","company":{"id":7347,"name":"Tipalti","domain":"tipalti.com","url":"https://alion.io/company/tipalti","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Tel Aviv, Israel"],"countries":["IL"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":93000,"max_usd":211000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1261},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"JavaScript","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM","optional":false},{"name":"Model Context Protocol","optional":false},{"name":"OWASP","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"WordPress","optional":false},{"name":"PHP","optional":true}],"status":"live","first_seen_at":"2026-09-16T13:59:55Z","employer_posted_date":"2026-09-27","last_verified_at":"2026-10-01T02:26:50Z","board_verified":true,"closed_at":null,"days_open":14,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":14},"description":"Senior Product Security Engineer\nWe are looking for a Senior Product Security Engineer to join Tipalti’s Product Security team and help strengthen security across our products and software development lifecycle.\nThe role is hands-on and engineering-focused, working closely with development and product teams to identify security risks, improve application security, and implement practical security solutions throughout the development lifecycle.\nWhy join Tipalti?\nTipalti is the AI-powered platform for finance automation, elevating how finance teams operate in the global economy. We empower our customers to scale faster and smarter by removing the complexities of doing global business and accelerating their finance operations efficiency.\nOur platform provides a comprehensive suite of finance automation solutions designed for mid-market businesses across accounts payable, global payouts, procurement, employee expenses, corporate cards, supplier management, tax compliance, and treasury. Tipalti partners with leading financial institutions such as Citi, Wells Fargo, J.P. Morgan, and Visa, enabling over 5,000 global companies to efficiently and securely pay millions of suppliers and payees across 200+ countries and territories, in 120 currencies.\nAt Tipalti, we pride ourselves on our collaborative culture, the quality of our product, and the capabilities of our people. Tipalti offers competitive benefits, a flexible workplace, career coaching, and an environment where diverse individuals can thrive and make an impact.\nFounded in Israel in 2010, Tipalti is a global business headquartered in the San Francisco Bay Area (Foster City), with offices in Tel Aviv, Plano, Toronto, Vancouver, London, Amsterdam, Tbilisi, and Medellin.\nIn this role, you will be responsible for:\nWork closely with development and product teams on application and product security throughout the software development lifecycle.\nPerform hands-on security reviews of applications, APIs, services, and code.\nIdentify, investigate, validate, and assess product security vulnerabilities and security findings.\nProvide practical remediation guidance and work with development teams through remediation.\nPerform threat modeling and security analysis for new and existing product capabilities.\nWork with application security tools and technologies including SAST, SCA, DAST, API Security, WAF, and related security controls.\nImprove and automate Product Security processes, tooling, and security checks across the development lifecycle.\nAssess security across modern application environments including web applications, APIs, microservices, containers, Kubernetes, and cloud-native services.\nSupport secure coding practices and provide practical security guidance to development teams.\nSupport vulnerability disclosure and Bug Bounty activities, including technical validation, risk assessment, and remediation follow-up.\nContribute to the continuous improvement of Product Security practices and capabilities across Tipalti’s engineering organization.\nAbout you\n5+ years of hands-on experience in Application Security, Product Security, or a closely related software security role.\nStrong understanding of software development and the ability to read, understand, and review application code with .NET, JavaScript/TypeScript, or comparable modern technologies.\nHands-on experience identifying and analyzing application and API security vulnerabilities.\nExperience performing threat modeling and application security reviews.\nStrong understanding of authentication, authorization, session management, web security, API security and mobile security.\nStrong knowledge of OWASP Top 10s and their practical remediation.\nHands-on experience with application security technologies such as SAST, SCA, DAST, API Security, WAF.\nExperience with microservices, APIs, containers, Kubernetes, and cloud-native environments.\nKnowledge of AWS security and/or Azure security.\nUnderstanding of modern CI/CD and software development environments.\nStrong analytical and problem-solving skills with the ability to turn security findings into practical technical recommendations.\nStrong communication and collaboration skills and the ability to work effectively with engineering, product, and security teams.\nAdvantage\nExperience developing security tooling or automation.\nExperience with CI/CD and software supply chain security.\nExperience with fintech, payments, or security-sensitive SaaS products.\nExperience with vulnerability research, Bug Bounty, or vulnerability disclosure programs.\nFamiliarity with AI/LLM application security, AI coding tools, MCP, or agentic systems.\nSecurity research, open-source contributions, or other demonstrated hands-on security work.\nOur tech teams retain a fast-paced, start-up vibe that encourages innovation and critical thinking. At Tipalti, you’ll have the opportunity to work with a diverse, global team of engineers, developers, and product leaders who are collectively building the future of our best-in-class product suite as we transform financial operations for the future.\nAbout Our Tel Aviv Offices:\nHybrid Work Model - Tipalti offers a hybrid work model, with two days per week working from home and three days per week from our beautiful offices in North Tel Aviv.\nShuttle Services - Shuttle services are available from the nearest train station and across Tel Aviv to the office.\nParking - Parking is available for all employees.\nSnacks & Treats - Enjoy a selection of snacks and treats available on every floor.\nOur Mission\nOur mission is to elevate how finance teams operate in the global economy. We empower our customers to scale faster and smarter by removing the complexities of doing global business and accelerating their finance operations efficiency. We are the AI-powered platform that automates finance.\nTipalti is fueled by a commitment to our customers and a desire to build lasting connections. Our client portfolio includes high-velocity businesses such as Amazon Twitch, GoDaddy, Roku, WordPress.com, and ZipRecruiter. We work hard for our 99% customer retention rate which is built on trust, reliability and innovation. Tipalti means we handled it\" - a mission to which we are constantly committed.\nAccommodations\n Tipalti champions inclusive teams, in which every voice counts. We are committed to recruiting diverse candidates with varied personal experiences and abilities. We welcome applications from candidates belonging to historically underrepresented or disadvantaged groups, and maintain an equitable Talent Acquisition process that is free from discrimination.\nAs an equal opportunities employer, Tipalti complies with employment and human rights laws across the various jurisdictions in which we operate. Should you require reasonable adjustments or accommodations during the recruitment process, including access to alternate formats of materials, meeting spaces, or other accommodations that could better enable your full participation, please reach out to  for assistance.\nAI Use \n We may use artificial intelligence and automated systems (collectively \"AI\") to screen, assess, and select candidates during our recruitment process. This includes resume screening, skills assessment, and candidate matching. You have the right to request human review of any automated decision. For more information about how we collect and use personal data and information during recruitment, please refer to our Job Candidate Privacy Notice. For additional questions about our use of AI during our recruitment process, you can contact .\nPrivacy\n We are committed to protecting the privacy interests of job applicants and candidates. For more information about our privacy practices during our Talent Acquisition process, please refer to our Job Candidate Privacy Notice below:\n\nJob Candidate Privacy Notice | Tipalti\nwww.tipalti.com/privacy/job-candidate-privacy-notice/","description_format":"text","description_chars":7935,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Flexible schedule","Hybrid work"],"hiring_locations":[{"name":"Israel","iso":"IL","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Payment Processing & Gateways","Procurement & Spend Management"],"lifecycle":[{"event":"open","at":"2026-09-27T17:30:25Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.857,"p_room":1,"age_days":14,"expected_fill_days":42,"reasons":["conf:3","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/tipalti-senior-product-security-engineer","json_url":"https://alion.io/job/tipalti-senior-product-security-engineer.json","meta":{"generated_at":"2026-10-01T09:47:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":546,"day_limit":5000,"remaining_today":4454,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}