AppSec Architect

Israel - Ramat-Gan · Full time · Senior

About The Position

Elementor's Security Team protects a platform that powers over 14% of the internet - millions of websites, apps, and businesses built by our community of creators. We combine classic security engineering with modern automation and AI-driven tooling to stay ahead of a fast-moving threat landscape, and we work hand-in-hand with R&D to build security into the product from day one.

About the Role

As an AppSec Engineer, you'll be the security partner for our R&D teams - reviewing code and architecture, closing the loop on vulnerabilities, and helping developers ship secure features faster. You'll also own our external vulnerability disclosure channels end-to-end, including leading our Bug Bounty program. This role is a great fit if you have a development background, enjoy digging into code, and want to use AI tools and agents to scale security impact across a large, fast-growing platform.

Responsibilities

Application Security & Secure SDLC

  • Partner with R&D: work directly with developers to identify, triage, and remediate application-level vulnerabilities.
  • Review code & architecture: assess security weaknesses and provide clear, actionable, developer-friendly remediation guidance both in the code and architectural levels
  • Own the scanning pipeline: run and tune SAST, DAST, and SCA tools across the codebase and CI/CD.
  • Shift security left: drive secure coding practices, threat modeling, and security requirements into the development process.
  • Review new features: support security reviews for new products, integrations, and third-party dependencies.


Vulnerability Disclosure & Bug Bounty

  • Lead the program: own the Bug Bounty program end-to-end - scoping, triage, severity assessment, payouts, and researcher communication.
  • Manage vendor integrations: run and integrate vulnerability submission and disclosure platforms including Patchstack, Bugcrowd, Wordfence and Wordpress.
  • Triage & resolve: validate inbound vulnerability reports from all channels and drive them to resolution with the relevant teams.
  • Improve the process: continuously raise the bar on intake, triage, and SLA handling for vulnerability reports.


Automation & AI Tooling

  • Build AI agents: design and build automation workflows and AI agents that cut manual triage work and speed up remediation.
  • Use AI daily: leverage AI coding tools (Claude Code, Cursor, etc.) to boost your own productivity - “agentic thinking”.
  • Design AI security Architecture: Build a security apparatus to detect and fix AI produced code and workflows.
  • Explore automation platforms: evaluate tools like n8n and Zapier for AppSec workflows.
  • Connect the stack: build scripts and integrations linking scanning tools, ticketing systems, and vendor platforms.

Requirements

  • 2-4 years of experience in Application Security, Security Engineering, or Software Development with a strong security focus.
  • Development experience is a clear advantage - a hands-on coding background in any modern language or stack.
  • Solid understanding of common web and application vulnerability classes (e.g., OWASP Top 10).
  • Experience with Application Security Testing tools (such as burp suite, CI/CD pipeline security rule configuration etc)
  • Experience with SAST/DAST/SCA tools and integrating security into CI/CD pipelines.
  • Hands-on, practical familiarity with AI tools and building AI agents for real workflows.
  • Basic coding and scripting skills (Python, Bash, JavaScript, or similar).
  • Strong communication skills and the ability to work closely with developers and cross-functional teams.

Skills & Mindset

  • Ownership mindset - comfortable leading an initiative (like the Bug Bounty program) end-to-end.
  • Ability to work independently, prioritize, and stay calm under pressure.
  • Clear communicator who can translate security findings into practical action for developers and stakeholders.
  • Curiosity for AI tooling and a drive to automate repetitive work.

Nice to Have

  • Prior experience running or participating in a Bug Bounty / responsible disclosure program.
  • Experience with vulnerability disclosure or WAF/plugin security platforms such as Patchstack, Bugcrowd, or Wordfence.
  • Familiarity with n8n, Zapier, or building custom AI agents for security automation.
  • Experience with cloud security fundamentals (AWS, Azure, or GCP)

Apply for this position