4 Π΄Π½Ρ Π½Π°Π·Π°Π΄
Vulnerability Researcher
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Vulnerability Researcher (Offensive Security): Investigating modern systems, protocols, and architectures to uncover novel vulnerabilities and exploitation techniques with an accent on reverse engineering, first-principles analysis, and exploitability. Focus on developing proof-of-concept exploits, owning research from hypotheses through disclosure or publication, and advancing identity security through original research and CVEs.
Location: Tel Aviv, Israel; on-site
Company
is building an AI-native Identity Operating System for enterprise identity and access management, combining AI connectors, a live identity graph, and AI agents for identity lifecycle governance.
What you will do
- Research flawed assumptions, implementation gaps, novel vulnerability classes, and exploitation techniques in modern systems.
- Reverse-engineer systems, protocols, and architectures to understand their implementation-level behavior.
- Develop hypotheses into working proof-of-concept exploits that demonstrate real-world risk.
- Own research threads end-to-end, from exploration and experimentation through responsible disclosure or publication.
- Connect relevant findings to βs understanding of identity attack surfaces across human and non-human identities.
- Advance the security community through original research, CVEs, disclosures, and technical thought leadership.
Requirements
- 6+ years of hands-on experience in vulnerability research, reverse engineering, or offensive security.
- Proven ability to find non-trivial flaws and understand the underlying systems, protocols, and architectures.
- First-principles approach focused on actual system behavior rather than documentation or intended design.
- Ability to identify overlooked assumptions, untested edge cases, and implementation failure modes.
- Strong hands-on expertise turning research and theories into working exploit chains and proof-of-concept demonstrations.
- Track record of significant original discoveries, such as published CVEs, novel vulnerability classes, or new exploitation techniques.
Nice to have
- Original research presented at Black Hat, DEF CON, OffensiveCon, Hexacon, or a comparable security conference.
- Significant CVEs rated High or Critical by CVSS.
Culture & Benefits
- Freedom to pursue research directions wherever the evidence leads.
- Access to tools and resources supporting deep technical investigation.
- Opportunities to publish research and build technical authority in the security community.
- Research can contribute directly to βs platform or stand as independent original discovery.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β
ΠΠΎΡ ΠΎΠΆΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
5 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
Vulnerability Researcher (AI Security)
4 Π΄Π½Ρ Π½Π°Π·Π°Π΄
Application Security Researcher (AI)
5 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
Senior Product Security Researcher (Browser Security)
7 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
AI Red Team Researcher
4 Π΄Π½Ρ Π½Π°Π·Π°Π΄
Application Security Researcher (AI)
Wiz
5 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄