AppSec Architect

Posted 2 Days Ago
Be an Early Applicant
Ramat Gan, ISR
In-Office
Mid level
Design • App development
Elementor is the leading website builder for professionals on WordPress.
The Role
Partner with R&D teams to identify and remediate application vulnerabilities, conduct code and architecture reviews, and integrate SAST, DAST, and SCA into CI/CD pipelines. Own the Bug Bounty and vulnerability disclosure programs, including triage, severity assessment, researcher communication, and resolution. Build AI agents, automation workflows, and integrations to accelerate vulnerability handling and secure AI-generated code. Promote threat modeling, secure coding, and security requirements across product development.
Summary Generated by Built In
Description

Elementor's Security Team protects a platform that powers over 14% of the internet - millions of websites, apps, and businesses built by our community of creators. We combine classic security engineering with modern automation and AI-driven tooling to stay ahead of a fast-moving threat landscape, and we work hand-in-hand with R&D to build security into the product from day one.

About the Role

As an AppSec Engineer, you'll be the security partner for our R&D teams - reviewing code and architecture, closing the loop on vulnerabilities, and helping developers ship secure features faster. You'll also own our external vulnerability disclosure channels end-to-end, including leading our Bug Bounty program. This role is a great fit if you have a development background, enjoy digging into code, and want to use AI tools and agents to scale security impact across a large, fast-growing platform.

Responsibilities

Application Security & Secure SDLC

  • Partner with R&D: work directly with developers to identify, triage, and remediate application-level vulnerabilities.
  • Review code & architecture: assess security weaknesses and provide clear, actionable, developer-friendly remediation guidance both in the code and architectural levels
  • Own the scanning pipeline: run and tune SAST, DAST, and SCA tools across the codebase and CI/CD.
  • Shift security left: drive secure coding practices, threat modeling, and security requirements into the development process.
  • Review new features: support security reviews for new products, integrations, and third-party dependencies.

Vulnerability Disclosure & Bug Bounty

  • Lead the program: own the Bug Bounty program end-to-end - scoping, triage, severity assessment, payouts, and researcher communication.
  • Manage vendor integrations: run and integrate vulnerability submission and disclosure platforms including Patchstack, Bugcrowd, Wordfence and Wordpress.
  • Triage & resolve: validate inbound vulnerability reports from all channels and drive them to resolution with the relevant teams.
  • Improve the process: continuously raise the bar on intake, triage, and SLA handling for vulnerability reports.

Automation & AI Tooling

  • Build AI agents: design and build automation workflows and AI agents that cut manual triage work and speed up remediation.
  • Use AI daily: leverage AI coding tools (Claude Code, Cursor, etc.) to boost your own productivity - “agentic thinking”.
  • Design AI security Architecture: Build a security apparatus to detect and fix AI produced code and workflows.
  • Explore automation platforms: evaluate tools like n8n and Zapier for AppSec workflows.
  • Connect the stack: build scripts and integrations linking scanning tools, ticketing systems, and vendor platforms.
Requirements
  • 2-4 years of experience in Application Security, Security Engineering, or Software Development with a strong security focus.
  • Development experience is a clear advantage - a hands-on coding background in any modern language or stack.
  • Solid understanding of common web and application vulnerability classes (e.g., OWASP Top 10).
  • Experience with Application Security Testing tools (such as burp suite, CI/CD pipeline security rule configuration etc)
  • Experience with SAST/DAST/SCA tools and integrating security into CI/CD pipelines.
  • Hands-on, practical familiarity with AI tools and building AI agents for real workflows.
  • Basic coding and scripting skills (Python, Bash, JavaScript, or similar).
  • Strong communication skills and the ability to work closely with developers and cross-functional teams.

Skills & Mindset

  • Ownership mindset - comfortable leading an initiative (like the Bug Bounty program) end-to-end.
  • Ability to work independently, prioritize, and stay calm under pressure.
  • Clear communicator who can translate security findings into practical action for developers and stakeholders.
  • Curiosity for AI tooling and a drive to automate repetitive work.

Nice to Have

  • Prior experience running or participating in a Bug Bounty / responsible disclosure program.
  • Experience with vulnerability disclosure or WAF/plugin security platforms such as Patchstack, Bugcrowd, or Wordfence.
  • Familiarity with n8n, Zapier, or building custom AI agents for security automation.
  • Experience with cloud security fundamentals (AWS, Azure, or GCP)

Skills Required

  • 2-4 years of experience in Application Security, Security Engineering, or Software Development with a strong security focus
  • Development experience in a modern programming language or technology stack
  • Solid understanding of common web and application vulnerability classes, including the OWASP Top 10
  • Experience with application security testing tools such as Burp Suite and CI/CD pipeline security rule configuration
  • Experience with SAST, DAST, and SCA tools and integrating security into CI/CD pipelines
  • Hands-on familiarity with AI tools and building AI agents for real workflows
  • Basic coding and scripting skills in Python, Bash, JavaScript, or similar
  • Strong communication skills and ability to work with developers and cross-functional teams
  • Experience running or participating in a Bug Bounty or responsible disclosure program
  • Experience with vulnerability disclosure or WAF/plugin security platforms such as Patchstack, Bugcrowd, or Wordfence
  • Familiarity with n8n, Zapier, or custom AI agents for security automation
  • Experience with cloud security fundamentals in AWS, Azure, or GCP
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Ramat Gan
493 Employees
Year Founded: 2016

What We Do

Elementor is the leading website builder platform for professionals on Wordpress. Elementor serves web professionals including developers, designers and marketers and boasts a new website created every 10 seconds on its platform. Elementor is an open-source, GPLv3 licensed platform offering its platform both as free and premium.

Similar Jobs

Remitly Logo Remitly

Field Operations Representative - Russian Speaker (Southern Area)

eCommerce • Fintech • Payments • Software • Financial Services
In-Office
Tel Aviv, ISR
2800 Employees

Taboola Logo Taboola

Full-stack Engineer

AdTech • Big Data • Digital Media • Marketing Tech
Hybrid
Tel Aviv, ISR
1900 Employees

Duda, Inc. Logo Duda, Inc.

Senior Product Designer

Agency • Digital Media • eCommerce • Marketing Tech • Software • Design • App development
Hybrid
Tel Aviv, ISR
200 Employees

monday.com Logo monday.com

Customer Enablement AI Builder

Artificial Intelligence • Productivity • Sales • Software
Hybrid
Tel Aviv, ISR
3155 Employees

Similar Companies Hiring

WorkWhile Thumbnail
Artificial Intelligence • HR Tech • Information Technology • Machine Learning • Software • App development • Industrial
San Francisco, CA
100 Employees
Apryse Thumbnail
Productivity • Software • App development • Automation
Denver, CO
665 Employees
Caliola Engineering Thumbnail
Software • Machine Learning • Hardware • Defense • Data Privacy • App development • Aerospace
Colorado Springs, CO
68 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account