AI Security Engineer

ירושלים |
5-6 שנים |
משרה מלאה ועוד
| 10/02/2026
תיאור משרה

We're building the financial infrastructure that powers global innovation. With our cutting-edge suite of embedded payments, cards, and lending solutions, we enable millions of businesses and consumers to transact seamlessly and securely.

The Role
As AI capabilities accelerate across the bank, we need an engineer to design and enforce safe AI usage—protecting customer data, preserving model integrity, and meeting our regulatory obligations. You'll be the architect of guardrails, tooling, and policies that make AI both secure and useful for product and internal teams. This isn't about slowing things down; it's about building the trust layer that lets innovation move fast without breaking things.
Who You Are
You're a security engineer who's excited about the AI wave—someone who sees GenAI and LLMs as fascinating puzzles to secure, not just threats to mitigate. You've spent 5+ years in Security Engineering, AppSec, or Cloud Security, and at least 1–2 of those years have been spent getting your hands dirty with AI/ML or data-intensive systems.
You're equally comfortable dissecting a prompt injection attack as you are writing a Terraform module or shipping a Python library. You know your way around AWS and/or Azure, modern app stacks (Python/TypeScript, REST/gRPC, containers/Kubernetes), and can translate security requirements into developer-friendly tooling—not just PDF policies that gather dust.
You communicate clearly in English and Hebrew, thrive in regulated environments, and understand that security in financial services means mapping controls to frameworks like FFIEC, SOC 2, and PCI DSS—and actually having the evidence to prove it.

דרישות התפקיד

What You Bring to the Table
5+ years in Security Engineering/AppSec/Cloud Security (or similar), including 1–2+ years securing AI/ML or data?intensive systems (GenAI preferred).
Hands?on experience with AWS and/or Azure and modern app stacks (Python/TypeScript, REST/gRPC, containers/Kubernetes, IaC such as Terraform).
Practical understanding of LLM attack surfaces (prompt injection, data leakage via tools, training/fine?tune poisoning, model supply chain) and mitigation patterns.
Familiarity with identity and access for AI workloads (OAuth2/OIDC, service principals, role tokens, PIM), and secure secret management/KMS.
Experience implementing observability/telemetry and routing findings to SIEM; comfort balancing privacy with traceability.
Ability to translate controls into developer-friendly libraries, docs, and CI/CD checks; strong written communication in English and Hebrew.
Comfort working in a regulated environment and mapping controls to frameworks (FFIEC, SOC 2, PCI DSS).
Nice to have
Financial services background or other high?assurance domains.
Exposure to Duende IdentityServer, SSO/SCIM, and enterprise authorization patterns.
Experience with vector databases (e.g., OpenSearch, pgvector, Pinecone) and secure RAG architectures.
Familiarity with guardrail tooling (e.g., Azure AI Safety features, Amazon Bedrock Guardrails) and policy engines (OPA/Rego).
Prior work in AI red?teaming or safety evaluation harnesses; contributions to OSS or published talks.

Flexible hybrid work model: three days a week at our Jerusalem office

* משרה זו פונה לנשים וגברים כאחד.