About the job
Welcome to the forefront of cloud networking and security!
Cato Networks is pioneering the convergence of enterprise networking and security into a unified global service delivered via the cloud. Founded by industry leaders including Shlomo Kramer (Check Point, Imperva) and early investors from companies like Palo Alto Networks and Trusteer, Cato's innovative technology has catalyzed the creation of a new product category known as 'SASE' as recognized by Gartner. This market is projected to reach $28.5 billion by 2028.
Join us on this exciting journey as we develop a state-of-the-art enterprise network and secure cloud platform, rapidly advancing towards global market leadership – don't let this chance slip away!
We are seeking a proactive Application Security leader with a wealth of experience in establishing and expanding AppSec programs within fast-paced software environments. The ideal candidate will excel in balancing strategic initiatives with tactical execution, integrating security into engineering workflows, and collaborating effectively with R&D teams to ensure significant risk mitigation without hindering development timelines.
Your responsibilities will include:
- Enhancing and expanding our Application Security function across R&D, defining ownership, processes, and engagement frameworks with engineering teams.
- Integrating application security into CI/CD pipelines and daily development practices to foster secure-by-default engineering.
- Applying hands-on expertise in penetration testing and code reviews across various programming languages.
- Leading the implementation, configuration, and continuous improvement of AppSec tools (e.g., Semgrep, Oligo, Escape DAST) and managing the Cato Bug Bounty program to ensure effective detection and actionable remediation.
- Developing and maintaining application security standards, policies, and secure development frameworks that align with business objectives and engineering requirements.
- Conducting and leading threat modeling sessions, architecture risk assessments, and secure design evaluations for both new and existing services.
- Collaborating closely with Engineering Managers, Tech Leads, and Architects to advocate for secure coding practices and pragmatic security solutions.
- Contributing to the Cato research initiative, CATO CTRL, with a focus on discovering new vulnerabilities.
- Establishing and monitoring key AppSec performance indicators (KPIs) such as vulnerability trends, remediation timelines, pipeline coverage, and overall risk posture.

