
About Taboola
Discover engaging content with AI-driven ads
Key Highlights
- Founded in 2007, became a billion-dollar business by 2018
- Headquartered in Flatiron District, New York City
- Over 1000 employees and growing
- $160 million raised in Series E funding
Taboola, headquartered in the Flatiron District of New York City, is a leading AI-powered digital advertising agency that helps brands reach customers through engaging content recommendations. Founded in 2007, Taboola became a billion-dollar revenue-generating company by 2018, serving hundreds of bi...
🎁 Benefits
Employees enjoy a fully-stocked kitchen, gym partnerships, 401k matching, and health insurance. The company also offers flexible work-from-home opport...
🌟 Culture
Taboola's culture is driven by a commitment to innovation and data-driven decision-making, with a strong focus on R&D. The company values creativity a...
Skills & Technologies
Overview
Taboola is hiring a Senior Security Engineer to bridge high-level security governance with hands-on, automated security implementation across the Software Development Life Cycle. You'll work with DevSecOps principles and tools like SAST and DAST to enhance security practices. This role requires 5+ years of experience in a senior DevSecOps or Application/Product Security role.
Job Description
Who you are
You have 5+ years of experience in a senior DevSecOps or Application/Product Security role, demonstrating deep expertise in DevSecOps principles and a strong understanding of the modern application threat landscape, including the OWASP Top 10. Your proven ability to 'shift left' security by embedding automated security controls such as SAST, DAST, SCA, and IAST into CI/CD pipelines sets you apart. You possess hands-on experience managing and hardening open-source software dependencies, showcasing your mastery in open source security and supply chain management.
Your expertise in utilizing Software Composition Analysis (SCA) tools like Dependency-Check, Snyk, and Black Duck allows you to maintain an accurate Software Bill of Materials (SBOM) for all products. You are a vulnerability and risk management pro, with a proven ability to establish and own a continuous CVE tracking and remediation process. You excel in risk-rating vulnerabilities based on exploitability and business impact, driving engineering teams to efficiently remediate security risks using automation.
What you'll do
In this role, you will bridge high-level security governance with hands-on, automated security implementation across the Software Development Life Cycle (SDLC). You will empower teams to move swiftly while upholding the required security standards, ensuring that security practices are integrated into the development process. Your contributions will be critical in balancing rapid innovation with robust security practices, enabling the organization to deliver exceptional value to clients.
You will collaborate closely with engineering teams to embed security controls into CI/CD pipelines, ensuring that security is a fundamental aspect of the development process. Your role will involve continuous monitoring and improvement of security practices, as well as educating teams on the importance of security in their workflows. You will also be responsible for maintaining an accurate Software Bill of Materials (SBOM) and managing open-source software dependencies effectively.
What we offer
At Taboola, we offer a dynamic work environment where you can realize your potential and contribute to a leading performance-driven advertising company. We encourage you to apply even if your experience doesn't match every requirement, as we value diverse perspectives and backgrounds. Join us in our mission to empower teams and uphold security standards while driving innovation.
Interested in this role?
Apply now or save it for later. Get alerts for similar jobs at Taboola.
Similar Jobs You Might Like
Based on your interests and this role

Security Engineer
Taboola is hiring a Senior Security DevOps Engineer to bridge security governance with hands-on implementation across the SDLC. You'll work with tools like SAST, DAST, and SCA to ensure robust security practices. This role requires 5+ years of experience in DevSecOps or Application/Product Security.

Site Reliability Engineer
Woven by Toyota is hiring a Senior Site Reliability Engineer to enhance the productivity and efficiency of development teams. You'll work with cloud platforms and implement SRE best practices. This position requires a background in software engineering and DevOps.

Application Security Engineer
JFrog is hiring a Senior Application Security Engineer to drive security across the SDLC and empower developers through automation and tooling. You'll work with modern architectures and collaborate closely with various stakeholders. This role requires strong knowledge of secure coding principles and vulnerability management.

Site Reliability Engineer
Robin AI is hiring a Site Reliability Engineer to build and maintain cloud infrastructure for their Legal AI platform. You'll collaborate with engineering teams to ensure high availability and reliability of services. This position requires 3+ years of experience in DevOps or SRE roles.

Security Engineer
HoneyBook is hiring a Staff Application Security Engineer to shape and own their Secure Software Development Lifecycle. You'll work closely with engineering teams to design secure software and manage security tooling. This position requires hands-on experience in application security.