Varonis
Cyber Security Architect
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Varonis
Varonis Systems, Inc. is a cybersecurity company founded in 2005, specializing in data security and analytics solutions. Headquartered in Miami, with research and development based in Israel, Varonis provides visibility, control, and automated protection for unstructured data across on-premises, cloud, and hybrid environments. The company was inspired by a data loss incident in 2003 and launched its first product, DatAdvantage, in 2006. Varonis went public in 2014 and has since shifted to a subscription model, recently achieving record revenues of $488.7 million in FY2023. Varonis offers a comprehensive platform designed for data protection, utilizing machine learning and AI to analyze data in various environments. Its core offerings include data visibility, classification, access control, threat detection, and remediation. The company focuses on addressing insider threats, ransomware protection, data loss prevention, and regulatory compliance. With over 2,400 customers in more than 14 countries, Varonis serves industries such as financial services, healthcare, manufacturing, and government, positioning itself as a trusted partner in data-centric cybersecurity.
Security at Varonis
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“Stated SSDLC and embedding security into development: "Secure Software Development Cycle (SSDLC)." – Varonis SOC3 (varonis-saas-data-security-platform-soc3.pdf), SOC3 . "SSDLC's proven approach focuses on adding security to the standard SDLC" – Varonis blog (Varonis' Scalable Cloud-Native Architecture), 2026-??-??, Blog . Developer-focused protections: "end-to-end protection for AI app development" – Varonis blog (Securing AI Application Development), Blog . Approach to developer tooling and secrets: "Secure secrets, credentials, and PII data in dev tools." – Varonis site, 2026-??-??, Website . Risk-philosophy phrasing (e.g., explicit "risk-based approach") not found in public corpus: Information not publicly available.”
Security Team
Evidence of an AppSec team and role-level hiring: "join the AppSec Security team" – Senior Application Security Architect (Outscal job listing), 2026-??-??, Job Post . "Prior to Forcepoint, he served as CISO at Varonis" ⚠️ – Forcepoint press release (BusinessWire), Press Release. Stated responsibilities in postings: "embedding security into the software development lifecycle" – Senior Application Security Architect (Outscal job listing), 2026-??-??, Job Post . Key public-facing leaders: Information not publicly available (no authoritative Varonis org-chart or named current AppSec leader found). Team size estimate: Information not publicly available. Active AppSec job postings (as-of): evidence of multiple AppSec/security architecture roles found (job listings cited above).
Key Initiatives
Security Champions program: Information not publicly available. Shift-left / SSDLC practices: "embedding security into the software development lifecycle" – Senior Application Security Architect (Outscal job listing), 2026-??-??, Job Post . "SSDLC's proven approach focuses on adding security to the standard SDLC" – Varonis blog (Varonis' Scalable Cloud-Native Architecture), 2026-??-??, Blog . Threat modeling and secure design reviews in role descriptions: "Conduct and facilitate threat modeling and secure design reviews" – Application Security Architect (SecretHunter job listing), 2026-??-??, Job Post . Vulnerability management process (triage, SLAs, ticketing): Information not publicly available. Recent initiatives (last 6 months): "end-to-end protection for AI app development" – Varonis blog, Blog .
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.