3d ago

avatar

Fireblocks

Director Application Security

$180K - $250K

Tel Aviv-Yafo, Tel Aviv District, Israel

Senior (10+ years)

SaaS

Large (501–1000)

[object Object],[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object], ,[object Object],[object Object],[object Object]

Questions about the Director Application Security role at Fireblocks

What key metrics define success for an AppSec lead in this industry?

Success for an Application Security lead at Fireblocks—a high-stakes digital asset firm—is defined by metrics that balance development velocity with robust risk mitigation. Key performance indicators include:

  • Vulnerability Remediation Speed: Tracking the Mean Time to Remediate (MTTR) for critical vulnerabilities, ensuring swift responses to emerging threats.
  • Security Coverage: Percentage of the CI/CD pipeline integrated with automated testing (SAST/IaC) and cloud-native security controls (CSPM/CWPP).
  • Security Debt Reduction: The frequency and severity of vulnerabilities discovered in production versus pre-deployment.
  • Engineering Adoption: Engagement levels in threat modeling and secure coding practices.
  • Risk Resilience: Demonstrated effectiveness of red teaming and penetration testing exercises in identifying systemic weaknesses within cloud-native and cryptographic architectures.

How are teams balancing rapid feature delivery with robust security controls?

Fireblocks balances rapid innovation with robust security by embedding a "security-by-design" philosophy directly into their development and operations pipeline. As a Director of Product Security, the leader acts as a bridge between engineering and security, ensuring that threat modeling, secure design reviews, and automated security testing (SAST, IaC scanning) occur throughout the software development lifecycle. By utilizing cloud-native security tools and infrastructure-as-code practices, the team proactively identifies vulnerabilities without stifling deployment speed. Furthermore, the company fosters a culture of collaboration, where security experts partner with product teams to implement identity management and encryption, ensuring that security controls evolve alongside the rapid scale of their blockchain-based financial platform.

What evolving threat landscapes are most critical for AppSec to address now?

For the Director of Application Security at Fireblocks, the most critical evolving threats involve the intersection of cloud-native complexity and high-stakes digital asset management. Given the company’s reliance on blockchain, addressing supply chain vulnerabilities and IaC misconfigurations is paramount, as these can lead to systemic breaches in multi-cloud environments (AWS/GCP/Azure). Furthermore, the role must prioritize advanced cryptographic implementation failures and secrets management lapses, which directly jeopardize digital wallet integrity. Additionally, the proliferation of sophisticated automated CI/CD injection attacks and identity-based exploits in Kubernetes environments necessitates a proactive, offensive-security-led defense. Strategically, this role must shift from traditional perimeter security to a "security-by-design" posture that effectively mitigates threats across the entire cloud-native development lifecycle.

How does Fireblocks integrate security into its unique blockchain architecture?

Fireblocks integrates security into its blockchain architecture through a comprehensive, multi-layered "Product Security" strategy. As a Director of Product Security, the role focuses on embedding robust security controls directly into the development pipeline and cloud infrastructure. The company leverages advanced cryptographic principles, including encryption, hashing, and digital signatures, to protect digital assets. They utilize modern security methodologies such as threat modeling, red teaming, and offensive security techniques to proactively identify vulnerabilities. By employing cloud-native security tools like CSPM, IaC, SAST, and rigorous secrets management across AWS, GCP, and Azure, Fireblocks ensures that security is not an afterthought but a foundational component of its scalable, high-performance blockchain platform.

How will this role shape the security culture within Fireblocks' R&D teams?

The Director of Product Security will fundamentally shift Fireblocks' R&D security culture from reactive to proactive by embedding security directly into the development lifecycle. By spearheading threat modeling, secure design reviews, and continuous security assessments, the role ensures that engineers treat security as a core architectural principle rather than an afterthought. Through hands-on collaboration, the Director will foster a "security-first" mindset across engineering units, promoting the adoption of automated tools like SAST and IaC scanning. Ultimately, by bridging the gap between security teams and developers, this leader will establish a culture of shared responsibility, where security best practices are integrated into every stage of the cloud-native development and operations pipeline.