4 дня назад
Senior Penetration Testing Researcher
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Penetration Testing Researcher (Cybersecurity/AI): Leading penetration testing and vulnerability research across cloud, web, mobile, and AI-enabled systems with an accent on secure code review, automated discovery, and AI security evaluation. Focus on threat modeling, exploit development, assessing LLM and agent security, and validating remediation with engineering teams.
Location: Petach Tikva, Israel; primarily office-based
Company
Cybersecurity product development focused on protecting digital systems and strengthening the security of Idira products.
What you will do
- Lead penetration testing and vulnerability research across cloud, web, mobile, and AI-enabled products and architectures.
- Discover, validate, and demonstrate complex vulnerabilities through manual research, secure code review, dynamic analysis, and automated techniques.
- Evaluate AI architectures, LLM-powered applications, agentic frameworks, tool integrations, and AI-assisted application pipelines.
- Own research initiatives from threat modeling and attack-surface analysis through exploitation, reporting, and remediation validation.
- Build scripts, tools, proof-of-concept exploits, and automation to improve research coverage and repeatability.
- Partner with engineering and architecture teams to develop mitigations, secure design patterns, and product improvements.
Requirements
- 5+ years of hands-on experience in security research, penetration testing, offensive security, or product security.
- Experience assessing cloud, web, and mobile applications, with strong secure code-review skills.
- Hands-on experience with offensive security tools, SAST, DAST, and automated vulnerability-discovery frameworks.
- Experience using AI coding assistants or AI-assisted security tools, with familiarity with AI threat modeling, LLM security, agent security, prompt injection, and AI safety evaluation.
- Ability to independently drive complex research projects and develop custom scripts, tools, or proof-of-concept exploits.
- Excellent written and verbal communication skills in English and Hebrew.
Nice to have
- Offensive Security certifications such as OSCP, OSWE, OSEP, OSCE3, or equivalent.
- Bachelor’s degree in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
- Experience in a leading military technology or intelligence unit or equivalent advanced industry experience.
- Security publications, open-source tools, conference presentations, CVE disclosures, or bug-bounty findings.
Culture & Benefits
- Most teams work from the office full time, with flexibility when needed.
- Work in a collaborative product-focused security research environment.
- Opportunity to contribute insights to the broader security community.
- Immigration sponsorship and work visa sponsorship are not available for this position.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →