Back to jobs
New

Senior Product Security Engineer

Tel Aviv

Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system that observes, guides, and acts alongside the world’s most successful revenue teams. Powered by the Gong Revenue Graph, AI-powered intelligence, specialized agents, and trusted applications, Gong helps more than 5,000 companies around the world deeply understand their teams and customers, automate critical sales workflows, and close more deals with less effort. For more information, visit www.gong.io.

At Gong, you will join a company built on innovative products, ambitious goals, and passionate people. We are shaping the future of revenue intelligence and we want people who are excited to build what comes next. You will work with a team that dreams big, moves fast, and cares deeply about the craft and about each other. Here, transparency and trust are core to how we operate, and every person has the opportunity to make a visible impact. If you want to grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.

About Gong

At Gong, we’re transforming customer-facing teams with our AI-powered platform that understands conversations, guides sales professionals, and drives better business outcomes. Security and trust are foundational to everything we build.

As a Senior Product Security Engineer, you will help shape how security is built, not just how it is tested or reviewed. You’ll work closely with engineering teams to secure real systems in production, influencing how services, APIs, and data flows are implemented from the ground up.

This is a hands-on role, focused on solving real security problems across cloud-native architectures and AI-driven features. You’ll work directly with developers and DevOps, dive into systems when needed, and apply strong technical judgment to ensure security is built into the product, not added later.

What Makes This Role Unique at Gong

  • A product where data sensitivity is real, not theoretical
    Gong processes and analyzes customer conversations at scale, creating unique challenges around data protection, privacy, and access control.
  • AI is deeply embedded in the product
    Security challenges extend beyond traditional AppSec into data handling, model behavior, and misuse scenarios.
  • Security is part of how we build, not a layer on top
    The role operates within engineering workflows, focusing on building secure systems rather than enforcing external controls.
  • Meaningful scale and real production impact
    You’ll work on systems that handle large volumes of data and traffic, where security decisions directly affect reliability and trust.
  • A culture that values practical, engineering-driven security
    The focus is on solving real problems and enabling teams, not on process-heavy or compliance-driven approaches.
  • High ownership with room to grow
    You’ll have the autonomy to take initiative, drive improvements, and expand your impact as the platform evolves.

What You’ll Do

  • Secure real product flows end-to-end - Work directly with engineers to identify and fix vulnerabilities across services, APIs, and data paths in production systems
  • Drive secure-by-design practices in engineering - provide practical guidance on authentication, authorization, data protection, and service-to-service communication
  • Secure cloud-native environments - strengthen identity (IAM), isolation, and access control across Kubernetes, containers, and cloud infrastructure
  • Build and scale security in the development lifecycle - integrate and tune security tooling (SAST, SCA, IaC scanning, secrets detection) into CI/CD pipelines to improve signal and developer adoption
  • Own vulnerability management as a system - prioritize risks, drive remediation with engineering teams, and eliminate recurring issues through root-cause fixes
  • Strengthen software supply chain security - reduce risk across dependencies, third-party components, and build/release pipelines
  • Secure AI/ML-driven features - partner with data and AI teams to mitigate risks such as data exposure, misuse, and model-related vulnerabilities
  • Raise the security bar across engineering - mentor developers and help teams take ownership of security in their code and services
  • Enable fast, informed decisions - clearly communicate risks and trade-offs to support product and engineering velocity

What You Bring

  • 5+ years of experience in Product Security, Application Security, or a similar hands-on security engineering role
  • Proven experience working closely with engineering teams on real systems in production, not just assessments
  • Strong understanding of secure design and threat modeling, with the ability to influence architecture decisions
  • Deep knowledge of application security principles (OWASP Top 10 and beyond), including modern attack vectors
  • Hands-on experience securing web applications, APIs, and distributed systems
  • Strong experience with cloud environments (AWS, GCP, and/or Azure), including identity and access management (IAM)
  • Familiarity with Kubernetes, containers, and cloud-native architectures
  • Experience integrating security into CI/CD pipelines and improving developer workflows
  • Practical experience with security tooling (SAST, SCA, IaC scanning, secrets detection), including tuning and operationalizing
  • Experience working with modern development stacks (e.g., Java, Python, JavaScript/TypeScript, React or similar)
  • Strong problem-solving skills and the ability to analyze complex systems and prioritize meaningful risks
  • Ability to influence developers through technical credibility and practical guidance
  • Experience mentoring engineers and improving security practices across teams

Additional strengths:

  • Experience securing AI/ML or LLM-based systems
  • Background in offensive security/penetration testing
#LI-TD1

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Gong will collect and use your personal data (e.g. - name, email, resume info) to evaluate your application for employment. Gong will save your personal data for up to 2 years in order to consider you for other, future potential job opportunities. We are happy to delete your data upon request. 

For a list of personal data categories, how Gong uses your personal data, and rights you have to your personal data, please visit Gong’s Job Candidates Privacy Notice, available at https://www.gong.io/gong-io-job-candidates-privacy-notice/

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Gong.io’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.