RefolkCandidates
9 min read

Snyk Cut 90 in Tel Aviv. The 24.6:1 Ratio AppSec Engineers Should Read.

Snyk closed its Israel R&D center on June 24, 2026. Here is how AppSec, SAST, and DevSecOps engineers should rewrite their resumes before the next cut.

On June 24, 2026, Snyk emailed roughly 90 employees that their jobs were gone, effectively shutting the entire Israel development center. It is the fourth round in four years, and it lands the same summer Rapid7 cut again and Claude Code kept eating the "find-vulnerabilities-in-code" category whole. If your resume still leads with SAST tuning and false-positive triage, you have weeks, not quarters, to fix it.

Why Snyk's Israel cut matters more than the headcount

The 90-person cut is small, but it is a category signal: general-purpose LLMs are absorbing standalone SAST, and the vendors know it. Snyk employs about 1,550 people worldwide and only about 90 in Israel, so this round is not a trim, it is the closure of an R&D footprint that shipped some of the company's original scanner IP.

The chain of events is public and pointed:

  • February 2026: Claude Code ships a code-scanning update that finds vulnerabilities inline.
  • April 2026: CEO Peter McKay steps down after six years, saying Snyk needs "a visionary, AI-immersed leader." CFO Ken MacAskill becomes interim CEO.
  • June 24, 2026: The fourth layoff round hits, concentrated in Israel.
  • July 2026: Rapid7 follows with another round, echoing its 2023 cut of 18% of its 2,623-person staff.

Globes named Snyk, Checkmarx, and GitHub as the code scanners whose "reputation was damaged" by Claude Code's launch. That is not a marketing problem. That is a product-category problem, and it flows straight into hiring plans.

570+
Snyk layoffs since 2022

Three rounds in 2022 and 2023 totaling 350+, then 128 in June 2025, then 90 in June 2026.

The 24.6 to 1 ratio nobody is pricing correctly

In Refolk's index of U.S. professional profiles, 1,650 people currently hold Application Security, SAST, or DevSecOps titles, versus just 67 who hold AI Security, AI Red Team, ML Security, or LLM Security titles. That is a 24.6 to 1 gap between the pool being disrupted and the pool being built.

SegmentCountTop employer signalWhat it means
U.S. AppSec / SAST / DevSecOps1,650AWS, Meta, U.S. Bank, FINRA, Tempus AIPool being disrupted
U.S. AI Security / ML Security / LLM Security677AI, Cranium, Wraithwatch, Google, eBayPool being built
Ratio~24.6 : 1DerivedSupply gap in the new taxonomy
Israel AppSec / DevSecOps68WalkMe, Fireblocks, Varonis, ElementorAbsorbing pool for ex-Snyk Israel
Tel Aviv District subset8 of 68 (~12%)Tel Aviv-Yafo, Ramat Gan, HerzliyaGeographic re-employment market

The obvious read is that AI security is hard. The correct read is that the constraint is language, not capability. Most of those 1,650 AppSec engineers already do the underlying work: threat modeling, secure code review, runtime detection, and adversarial testing. What they do not do is describe it in the vocabulary hiring managers now search for. That gap closes on the resume, not in a certification.

The constraint is language, not capability. Fix the vocabulary and you are already in the top 5% of the new title.

The resume lines to delete today

Cut anything a Claude Code subagent can now do in one prompt. Rule-based static analysis, off-the-shelf scanner tuning, and false-positive triage are the three lines that read as "manages a commoditized tool" in 2026.

Delete or rewrite:

  • "Tuned Snyk / Checkmarx / SonarQube rulesets to reduce false positives by X%."
  • "Triaged N vulnerabilities per quarter across the SAST backlog."
  • "Owned SAST rollout for M repositories."
  • "Ran quarterly OWASP Top 10 training for engineers."
  • "Sales engineer / solutions architect for AppSec product."

That last one is not a typo. In Snyk's 2026 cut, go-to-market roles (sales, marketing, customer success) absorbed the largest share while core engineering was more protected. Sales-engineer AppSec resumes are now the riskiest posture in the category, not the safest. Reposition toward hands-on code, detection engineering, and adversarial work.

If you are staring at a resume built out of exactly those bullets, that is the exact work Refolk takes off you: paste your history and the target job posting, and Refolk rewrites your resume around the language the posting actually rewards, then scores how well you fit before you send it.

The resume lines to promote, straight from Snyk's own memo

Mirror the acquirer vocabulary. Interim CEO Ken MacAskill named four priorities in his internal memo: AI-written code, autonomous agents in production, vulnerabilities that chain into real attacks, and adversaries that never sleep. Those are the literal phrases hiring managers at Snyk, Rapid7, and their competitors are now typing into search bars.

Snyk's acquisition trail says the same thing in dollars. The company bought Invariant Labs in June 2025 for AI workflow and MCP security, and Probely in November 2024 for API security. When a buyer signals with capital what it wants, every resume in the category should follow.

Rewrite around these:

  • AI-written code review: "Reviewed Copilot- and Claude-generated PRs for injection, secrets exposure, and insecure deserialization at repo scale."
  • Agent security / MCP: "Hardened MCP servers and tool-calling agents against prompt injection, context poisoning, and tool exfiltration."
  • Vulnerability chaining: "Built exploit chains across CVEs to prove real blast radius, not CVSS theater."
  • Adversarial ML / LLM red team: "Ran prompt-injection, jailbreak, and data-extraction campaigns against production LLM endpoints."
  • Autonomous agents in production: "Instrumented runtime guardrails and kill switches for agent workflows deployed to customer environments."
  • API runtime security: "Detected and blocked BOLA and broken-auth patterns at the gateway layer, not just at build time."

Notice what is not on that list: certifications. Nobody at 7AI or Cranium is filtering for a new badge. They are filtering for the six phrases above.

Where the 90 laid-off Snyk Israel engineers actually land

In Israel, the realistic landing pool is small and named. Refolk's index shows only 68 AppSec and DevSecOps engineers currently based in Israel, with 8 of them concentrated in the Tel Aviv District (Tel Aviv-Yafo, Ramat Gan, Herzliya). Dumping ~90 ex-Snyk engineers into a pool of 68 is a supply shock greater than 100% in a matter of weeks.

The top current employers of Israeli AppSec engineers in Refolk's index are the shortlist:

  1. Fireblocks (crypto custody, heavy runtime security work)
  2. Varonis (data security, well-funded, recently public)
  3. WalkMe (post-acquisition by SAP, integration security)
  4. Elementor (WordPress ecosystem, huge attack surface)
  5. Viz.ai (healthcare AI, HIPAA-adjacent AppSec)
  6. LinearB (dev tooling, natural adjacency to code security)

If you are one of the 90, your resume is competing with 89 near-clones. The differentiator is not the Snyk logo, which every applicant will have. It is which of the six MacAskill-flavored bullets you can defend in an interview. That reordering is the entire game in July.

24.6x
Traditional AppSec engineers per AI Security engineer in the U.S.

1,650 AppSec/SAST/DevSecOps profiles versus 67 AI/ML/LLM Security profiles in Refolk's index.

The Rapid7 template: what the July cuts are copying

Rapid7's 2023 restructuring cut 470+ positions, roughly 18% of its 2,623-person staff, to reduce role overlap and rebalance the onshore/offshore mix. The July 2026 round is running the same playbook. That is useful because it tells you which roles at any listed cyber vendor are next.

The pattern:

  • Duplicate managers get cut before individual contributors. If your resume reads "managed a team of managers," fix that.
  • Onshore senior ICs without a clear detection or AI angle get pushed to offshore backfills.
  • Product marketing and sales engineering in commoditized categories shrink first.
  • Detection engineering, red team, and AI security are protected or expanded.

Deidre Diamond of CyberSN, the Boston cybersecurity recruiter, has called this the sector's "slow bleed." It is slow because the category is still generating revenue. It is a bleed because every quarter the AI-native tier absorbs more of the work.

David Hunt, a former Rapid7 engineer, left to found Pink Duck in Reading to research AI attack and defense. That is the archetype: senior AppSec engineer, mid-career, pivots into AI-native security research. You do not need to start a company to run the same play on paper.

A 30-minute resume rewrite for AppSec engineers

Do it in one sitting. The goal is not a new resume, it is a resume that reads correctly for the 67-person title pool, not the 1,650-person one.

  1. Retitle your current role. "Application Security Engineer" becomes "Application Security Engineer, LLM and Agent Security" if you have touched any AI code review, MCP work, or prompt-injection testing. If you have not, do a weekend project and then retitle honestly.
  2. Rewrite the top three bullets. Use the MacAskill vocabulary: AI-written code, autonomous agents, vulnerability chaining, adversaries that never sleep. One bullet per phrase.
  3. Delete the SAST tuning bullet. Replace with a detection-engineering or exploit-chaining bullet.
  4. Name the tools. Claude Code, Copilot, MCP servers, LangChain, specific LLM endpoints. Named tools beat abstract nouns in keyword search.
  5. Add one adversarial ML project. A public repo, a CTF write-up, or an internal red team memo you can describe without breaking NDA.
  6. Tailor per posting. Every job description in this category uses slightly different vocabulary. Match theirs.

Step six is the one that burns evenings, which is the specific friction Refolk is built for: paste the posting, get your own resume back rewritten for it, plus a cover letter and a fit score that tells you whether it is worth applying at all.

What to apply to this week

Aim for the small, named AI-security-native employers before the pool grows. In Refolk's index, the concentrated hiring signal in the 67-person AI Security pool sits at 7AI, Cranium, Wraithwatch, Google, and eBay. Of those, the first three are startup-scale and moving fastest; the last two are enterprise teams with more headcount but slower loops.

A realistic ladder for a mid-senior AppSec engineer:

  • Reach: 7AI, Cranium, Wraithwatch, Pink Duck. Small, fast, will hire on portfolio and vocabulary fit.
  • Match: Google AI security, eBay trust and safety, Snyk's own remaining engineering team, Rapid7's detection group.
  • Safety: Fireblocks, Varonis, WalkMe, U.S. Bank, FINRA. Larger AppSec orgs that will not disappear, but where growth is slower.

Whichever tier you target, the resume you send matters more than the network you use. In a category shrinking on one side and multiplying on the other, the applicants who name Claude Code, MCP, and agent security in the first 200 words of their resume are the ones who get the reply.

FAQ

Is AppSec as a career actually dying?

No, but the shape is changing. The category being commoditized is standalone SAST and rule-based scanning, which is where Claude Code and rival agents are strongest. The categories growing are agent security, LLM red teaming, exploit chaining, and runtime detection for AI-written code. If your resume still reads like a 2021 SAST rollout plan, the market will read that as declining. If it reads like MacAskill's June 2026 memo, the same experience becomes an asset.

Should I get an AI security certification before rewriting my resume?

No. There is no dominant certification in a 67-person U.S. title pool, and the small AI-native employers (7AI, Cranium, Wraithwatch) filter for demonstrated work, not credentials. Rewrite the resume first, ship one public adversarial ML project or MCP hardening write-up, and apply. Certifications become useful later, once the category standardizes, which will not happen in 2026.

I am one of the 90 Snyk Israel engineers. What is the fastest move?

Apply to Fireblocks, Varonis, WalkMe, Elementor, Viz.ai, and LinearB this week, in that order. Refolk's index shows those are the top current employers of Israeli AppSec and DevSecOps engineers, and they are the realistic absorbers of the supply shock. Lead every application with agent security, MCP, and AI-written code review bullets rather than Snyk-product bullets, because the interviewer already knows what Snyk shipped and wants to know what you personally did.

How much of this applies to DevSecOps engineers, not just AppSec?

Most of it. DevSecOps layoffs in 2026 are tracking the same pattern: pipeline-glue and scanner-integration work is commoditizing, while agent runtime security, CI/CD supply-chain defense against AI-generated code, and secrets management for LLM apps are expanding. The resume rewrite is the same rewrite, with two additions: name your CI/CD platform explicitly (GitHub Actions, GitLab, Buildkite) and add one bullet about securing agent-driven deployments.

Put this to work

Reading about the job search is not the job search.

Paste your career in once. I write the resume, then every week I rank the live openings against your history, tailor a resume and a cover letter to the best of them, and keep going until you land. You press send, and that is the whole of your part.

  • 140+ curated roles a week, found, written, and scored for you.
  • Every bullet stays inside what your history actually supports.
  • Queued, submitted, interviewing, offer, all in one place instead of a spreadsheet.

500 free credits on sign-up. No card.

Keep reading