Product Security Engineer
Product Security Engineer We are looking for a Product Security Engineer to join Tipalti’s Product Security team and help strengthen security across our products and software development lifecycle. The role is hands-on and engineering-focused, working closely with development and product teams to identify security risks, improve application security, and implement practical security solutions throughout the development lifecycle. Why join Tipalti? Tipalti is the AI-powered platform for finance automation, elevating how finance teams operate in the global economy. We empower our customers to scale faster and smarter by removing the complexities of doing global business and accelerating their finance operations efficiency. Our platform provides a comprehensive suite of finance automation solutions designed for mid-market businesses across accounts payable, global payouts, procurement, employee expenses, corporate cards, supplier management, tax compliance, and treasury. Tipalti partners with leading financial institutions such as Citi, Wells Fargo, J.P. Morgan, and Visa, enabling over 5,000 global companies to efficiently and securely pay millions of suppliers and payees across 200+ countries and territories, in 120 currencies. At Tipalti, we pride ourselves on our collaborative culture, the quality of our product, and the capabilities of our people. Tipalti offers competitive benefits, a flexible workplace, career coaching, and an environment where diverse individuals can thrive and make an impact. Founded in Israel in 2010, Tipalti is a global business headquartered in the San Francisco Bay Area (Foster City), with offices in Tel Aviv, Plano, Toronto, Vancouver, London, Amsterdam, Tbilisi, and Medellin. In this role, you will be responsible for: Work closely with development and product teams on application and product security throughout the software development lifecycle. Perform hands-on security reviews of applications, APIs, services, and code. Identify, investigate, validate, and assess product security vulnerabilities and security findings. Provide practical remediation guidance and work with development teams through remediation. Perform threat modeling and security analysis for new and existing product capabilities. Work with application security tools and technologies including SAST, SCA, DAST, API Security, WAF, and related security controls. Improve and automate Product Security processes, tooling, and security checks across the development lifecycle. Assess security across modern application environments including web applications, APIs, microservices, containers, Kubernetes, and cloud-native services. Support secure coding practices and provide practical security guidance to development teams. Support vulnerability disclosure and Bug Bounty activities, including technical validation, risk assessment, and remediation follow-up. Contribute to the continuous improvement of Product Security practices and capabilities across Tipalti’s engineering organization. About you 3+ years of hands-on experience in Application Security, Product Security, or a closely related software security role. Strong understanding of software development and the ability to read, understand, and review application code with .NET, JavaScript/TypeScript, or comparable modern technologies. Hands-on experience identifying and analyzing application and API security vulnerabilities. Experience performing threat modeling and application security reviews. Strong understanding of authentication, authorization, session management, web security, API security and mobile security. Strong knowledge of OWASP Top 10s and their practical remediation. Hands-on experience with application security technologies such as SAST, SCA, DAST, API Security, WAF. Experience with microservices, APIs, containers, Kubernetes, and cloud-native environments. Knowledge of AWS security and/or Azure security. Understanding of modern CI/CD and software development environments. Strong analytical and problem-solving skills with the ability to turn security findings into practical technical recommendations. Strong communication and collaboration skills and the ability to work effectively with engineering, product, and security teams. Advantage Experience developing security tooling or automation. Experience with CI/CD and software supply chain security. Experience with fintech, payments, or security-sensitive SaaS products. Experience with vulnerability research, Bug Bounty, or vulnerability disclosure programs. Familiarity with AI/LLM application security, AI coding tools, MCP, or agentic systems. Security research, open-source contributions, or other demonstrated hands-on security work. Our tech teams retain a fast-paced, start-up vibe that encourages innovation and critical thinking. At Tipalti, you’ll have the opportunity to work with a diverse, global team of engineers, developers, and product leaders who are collectively building the future of our best-in
Find your next role on Israel's job board.
Browse all jobs