AppSec Architect

Senior
CompanyElementor
LocationIsrael - Ramat-Gan
CategorySecurity
DepartmentR&D
SenioritySenior
Workplace-
Posted2026-09-17
Estimated salary₪35K–48K (a market estimate, not the employer's figure)
Viacomeet

Description

Elementor's Security Team protects a platform that powers over 14% of the internet - millions of websites, apps, and businesses built by our community of creators. We combine classic security engineering with modern automation and AI-driven tooling to stay ahead of a fast-moving threat landscape, and we work hand-in-hand with R&D to build security into the product from day one.

About the Role

As an AppSec Engineer, you'll be the security partner for our R&D teams - reviewing code and architecture, closing the loop on vulnerabilities, and helping developers ship secure features faster. You'll also own our external vulnerability disclosure channels end-to-end, including leading our Bug Bounty program. This role is a great fit if you have a development background, enjoy digging into code, and want to use AI tools and agents to scale security impact across a large, fast-growing platform.

  • 2-4 years of experience in Application Security, Security Engineering, or Software Development with a strong security focus.
  • Development experience is a clear advantage - a hands-on coding background in any modern language or stack.
  • Solid understanding of common web and application vulnerability classes (e.g., OWASP Top 10).
  • Experience with Application Security Testing tools (such as burp suite, CI/CD pipeline security rule configuration etc)
  • Experience with SAST/DAST/SCA tools and integrating security into CI/CD pipelines.
  • Hands-on, practical familiarity with AI tools and building AI agents for real workflows.
  • Basic coding and scripting skills (Python, Bash, JavaScript, or similar).
  • Strong communication skills and the ability to work closely with developers and cross-functional teams.

Skills & Mindset

  • Ownership mindset - comfortable leading an initiative (like the Bug Bounty program) end-to-end.
  • Ability to work independently, prioritize, and stay calm under pressure.
  • Clear communicator who can translate security findings into practical action for developers and stakeholders.
  • Curiosity for AI tooling and a drive to automate repetitive work.

Nice to Have

  • Prior experience running or participating in a Bug Bounty / responsible disclosure program.
  • Experience with vulnerability disclosure or WAF/plugin security platforms such as Patchstack, Bugcrowd, or Wordfence.
  • Familiarity with n8n, Zapier, or building custom AI agents for security automation.
  • Experience with cloud security fundamentals (AWS, Azure, or GCP)