דרושים » אבטחת מידע וסייבר » Penetration testing specialist- 2579

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
משרה זו סומנה ע"י המעסיק כלא אקטואלית יותר
מיקום המשרה:מרכז
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a talented Penetration Tester & Researcher to lead complex offensive security engagements and groundbreaking research. You will execute sophisticated attack simulations, identify high-value vulnerabilities, and collaborate with clients to enhance their security posture.

This role offers a balance between hands-on technical assessments and original research that shapes the broader cybersecurity community.

Roles and Responsibilities:
Conduct advanced penetration tests across web, mobile, and thick-client applications.
Contribute to internal tools, scripts, and methodologies that enhance efficiency.
Design and simulate real-world attack chains reflecting modern threat actors.
Perform vulnerability research, exploit development, and threat modeling.
Research, develop, and implement offensive security methodologies utilizing AI technologies.
Produce detailed technical reports with actionable remediation strategies.
Collaborate directly with clients to guide mitigation and improve resilience.
Publish research, present findings, and represent us at conferences or in public forums.
Requirements:
Requirements
2-3 years of experience in application penetration testing, including mobile, web, and thick-client applications.
Hands-on experience using AI offensively and attacking AI-powered systems.
Solid technical foundation in networking, operating systems, and cloud.
Excellent communication and presentation skills.
Fluency in Hebrew and English.


Preferred Skills
Active participation in bug bounty programs or responsible disclosure initiatives.
Industry certifications such as OSCP, OSWA, OSWE, or OSCE.
Familiarity with cloud and container security, Kubernetes, and IaC.
Experience integrating security practices within development lifecycles.
Proven ability to lead or publish offensive research.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8745599
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Herzliya
Job Type: Full Time
our Security team is looking for a highly skilled and security-savvy Application Security Engineer to lead our product and application security efforts. In this role, you will drive security design, ensure secure coding practices, and validate our services and environments against the highest security standards.
You will work closely with our R&D and Product teams to identify, mitigate, and prevent security risks throughout the software development lifecycle (SDLC). As a senior engineer, you will own security initiatives, mentor developers on security best practices, and play a key role in shaping the security posture of products.
The ideal candidate is highly motivated, eager to learn, and has a security by design mindset. This role provides career growth opportunities, enabling you to deepen your expertise in AppSec, DevSecOps, and cloud security.
What you'll do:
Partner with development and product teams to integrate security best practices into the SDLC
Lead threat modeling and architecture security reviews to proactively identify and mitigate risks
Conduct security assessments, including code reviews, vulnerability scans, penetration testing, and secure product design reviews
Stay up to date with emerging security threats, vulnerabilities, and industry trends, ensuring remains ahead of evolving risks.
Support and contribute to security incident response activities, including root cause analysis and post-incident improvements
Automate security processes and integrate security tools within CI/CD pipelines
Develop and deliver secure coding training to engineering teams
Requirements:
4+ years of experience in Application Security, Penetration Testing, or Product Security in a SaaS company
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience)
Deep understanding and hands-on experience of web application security, including OWASP Top 10, authentication, encryption, and secure coding principles
Proficiency in scripting or programming languages (Python, JavaScript, Go, etc.) for security automation
Experience with cloud security best practices (AWS, GCP, or Azure)
Hands-on experience with DevSecOps and integrating security tools into CI/CD pipelines
Strong communication skills, with the ability to explain security risks and recommendations to technical and non-technical stakeholders, including executive management
Experience working with large-scale, complex R&D environments
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8723935
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
09/07/2026
חברה חסויה
Location: Herzliya
Job Type: Full Time
we are looking for a talented Application Security Specialist to join our team. In this role, you will take an active part in application penetration testing, threat modeling, Secure SDLC activities, and AppSec initiatives that help evaluate and improve security posture. The position includes hands-on security testing of web, mobile, API, thick client, AI/LLM integrations, and MCP-based application components, identifying and validating vulnerabilities, assessing real business impact, supporting customers with clear remediation guidance, and contributing to application security processes, tools, and best practices.

Responsibilities
Perform hands-on application penetration testing across web, mobile, API, thick client, AI/LLM integrations, and MCP-enabled application components.

Perform threat modeling and secure design reviews to identify risks early in the development lifecycle.

Support development teams with practical remediation guidance and secure implementation recommendations.

Perform Secure Software Development Lifecycle and secure coding training for developers.

Evaluate and improve customers application security development lifecycle, including secure coding practices, vulnerability management, remediation workflows, and security gates.

Participate in client-facing discussions, including assessment scoping, finding walkthroughs, remediation alignment, and retest updates.
Requirements:
Qualifications
2+ years of hands-on experience in application penetration testing.

Strong understanding of OWASP Top 10 and CWE Top 25, with proven experience identifying vulnerabilities and supporting practical remediation strategies.

Familiarity with high-level programming languages (Java, JS, Python, etc.).

Relevant App PT training and certifications such as EWPTX, OSWE, etc.

Strong English communication skills, with the ability to communicate technical topics clearly in client-facing discussions.

Advantage: Deep understanding of the LLM Top 10, AI security risks, MCP security risks, and AI/LLM hacking techniques.

Advantage: Proven experience in secure code review or high-level code auditing.

Advantage: Knowledge of Secure SDLC practices, and methodologies, including Microsoft SDL, OWASP SAMM, and OWASP ASVS.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8731965
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
09/07/2026
חברה חסויה
Location: Herzliya
Job Type: Full Time
we are looking for a Cyber Security Expert with hands-on experience in offensive security, possessing strong technical capabilities, in-depth knowledge of adversary simulation, and a passion for Red Team operations.
Responsibilities
Participate in Red Team assessments that simulate real-world threats and remain undetected by the client's defensive team. These stealth operations simulate advanced adversaries and require careful planning, execution, and OPSEC
Lead or co-lead portions of internal and external offensive assessments, including perimeter exploitation and post-exploitation in Active Directory
Perform Purple Team engagements to help clients improve their monitoring and detection capabilities while sharpening your own offensive skills
Document attack paths, risk analysis, technical findings and remediation guidance in detailed reports tailored to both technical and executive audiences.
Collaborate with the team to develop and maintain internal tooling, scripts, and documentation for offensive operations
Continuously research and test new techniques, tools, and attack paths to further enhance Red Team capabilities
Requirements:
Requirements
2+ years of hands-on experience in offensive security, red teaming, or penetration testing
Hands-on experience with C2 frameworks (e.g., Cobalt Strike, Mythic, Sliver)
Strong understanding of Active Directory, domain escalation paths, Kerberos, trust relationships, GPO abuse, credential access, etc.
Proficiency in various offensive techniques such as Relay Attacks, Coercion, Kerberos Attacks, Privilege Escalation, etc.
Familiarity with network protocols (e.g., SMB, DNS, LDAP, HTTP) and system internals (Windows and Linux)
Strong understanding of OPSEC considerations during covert operations
Ability to present and produce clear and actionable technical reports and documentation in English
Experience working in client-facing roles or as part of structured engagements
Proficient in one or more scripting/programming languages: Python, PowerShell, C#, or C++
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8731960
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Rehovot
Job Type: Full Time
The Cyber Security team is looking for a highly motivated GRC Security Specialist to join our team and take ownership of our Governance, Risk & Compliance program.
In this role, youll work closely with the CISO and cross-functional teams to embed security and compliance into everything we do. enabling the business to scale securely while meeting regulatory and customer expectations.
This is a high-impact position for someone who thrives in dynamic environments and wants to build, improve, and influence how security is managed across the organization.
Responsibilities
What will you be doing:
Own and lead the organizations Governance, Risk & Compliance (GRC) program
Reporting the CISO to define and execute a GRC strategy aligned with business objectives and risk appetite
Develop, implement, and maintain security policies, standards, and procedures aligned with industry best practices and regulatory requirements
Lead and manage risk assessment processes across cybersecurity, IT, third-party, and operational domains
Maintain and actively manage the risk register, ensuring risks are identified, prioritized, tracked, and remediated
Drive and manage compliance programs (e.g., ISO 27001, NIST, CIS, GDPR), ensuring continuous audit readiness
Lead internal and external audits end-to-end, including evidence collection, auditor coordination, and remediation tracking
Manage third-party risk (TPRM), including vendor security assessments, questionnaires, and ongoing monitoring
Support product and engineering teams by integrating security and compliance requirements into new features and systems
Build and deliver risk and compliance reporting, including dashboards, KPIs, and executive-level insights
Translate technical risks into clear, business-relevant communication for leadership and stakeholders
Drive security awareness initiatives and promote a security-first culture across the organization.
Requirements:
5+ years of experience in GRC, information security, risk management and compliance roles
Hands-on experience with security audits and certifications such as ISO 27001 and/or SOC 2
Strong understanding of risk management frameworks (e.g., NIST CSF, ISO 27001, CIS)
Experience managing third-party/vendor risk programs
Knowledge of data privacy and regulatory requirements (e.g., GDPR)
Familiarity with GRC platforms and compliance automation tools
Understanding of cloud environments (AWS, Azure, or GCP) and general security practices (infrastructure, application, and IT security)
Ability to manage multiple audit and compliance workstreams simultaneously with strong attention to detail
Experience with security tools and IT systems (advantage)
Familiarity with automation and/or AI-driven GRC processes (advantage)
Ability to think critically about emerging risks, including AI and evolving regulatory landscapes (advantage)
That special something you bring in:
Strong analytical and problem-solving skills, with the ability to assess and prioritize risks
Excellent written and verbal communication skills in English, with the ability to translate technical concepts into business language
Self-starter with the ability to work independently, prioritize effectively, and operate in a fast-paced environment
Strong organizational skills and ability to build structure and processes from scratch.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8775798
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for talented hackers to join our unique Adversarial Tactics Department. As a Red Team Expert ,you will work with clients to build their resiliency, i.e their capability to prevent and to sustain attacks. You will also be involved in IR engagements with companies that were attacked by adversaries, learn new TTPs and apply those in Red and Purple team engageents.
Your responsibility as a Cyber consultant is to bring the attackers perspective to engagements. You will help design, create and execute Adversary Simulation exercises, and perform attacks against client services, platforms and infrastructure. This will include, among other things, identifying vulnerabilities through simulated external and internal attacks, validating and enhancing an organizations ability to respond and recover from targeted attacks and persistent adversaries.
Requirements:
5+ years of Red Teaming or Adversarial Simulation Experience.
Experience conducting internal and external penetration testing.
Experience designing and/or executing phishing campaigns.
Experience in social engineering.
Experience with EDR/XDR evasion and bypass techniques.
Deep familiarity with Active Directory attacks and defenses.
Extensive experience in penetration testing methodologies and tools.
Deep technical understanding of a broad technology set and the ability to learn new information at a rapid pace.
Proven presentation skills.
Developing, extending, or modifying exploits, shellcode or exploit tools.
Willingness to travel abroad.
Advantages:
Background in application security.
Experience developing tools in one or more of the following: C/C++, Bash, C#, Python, Java, or PowerShell.
Experience with cloud penetration testing (AWS, Azure, Google Cloud Platform).
Fluent English (written and spoken).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8739929
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
7 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a rare opportunity to work at the intersection of offensive security and AI - and to have your expertise shape a platform used at enterprise scale. As an Security Researcher, you will push the boundaries of what autonomous agents can achieve.

Your goal is to conduct cutting-edge research into novel attack vectors and vulnerabilities, using those insights to both sharpen our AI and lead the industry conversation on AI-driven security. Youll work alongside a tight-knit team building excellent software in the security space.

Responsibilites
Original Research: Develop new attack strategies and offensive testing techniques for web, network and AI targets, and translate real-world knowledge into improvements for the AI agent
Thought Leadership: Produce high-quality technical content, including research papers, stage demonstrations, or technical blog posts that showcase unique capabilities and security philosophy.
Public Advocacy: Represent research at major security conferences and industry events.
AI Enhancement: Part of the team improving the AI hacker to make it more dangerous and creative.
Collaboration: Work closely with AI and engineering teams to continuously improve agent capabilities and ensure research findings are integrated into the product.
Requirements:
Technical Expertise: Deep expertise in Web and API security, including authentication, business logic, and injection flaws.
Publication Record: Proven experience publishing technical security research (e.g., personal or company blogs, whitepapers) or presenting at recognized security conferences (e.g., Black Hat, DEF CON, OWASP).
Coding Proficiency: Experience in writing code to develop tooling for penetration tests and security research.
Startup Mindset: Comfortable working in a fast-paced environment with a high degree of ownership and curiosity.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8768224
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
6 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for an individual who thrives on unraveling the intricacies of computing environments and attackers' techniques, ultimately providing our customers with cutting-edge tools to elevate their security posture. This role involves conducting both low-level and high-level research on security vulnerabilities, security tools, and the intersection of the two, leveraging various telemetries.
WHAT YOU WILL DO

Collaborate with engineering and product teams to enhance the efficiency and effectiveness of our existing detection engine.

Design and implement new features within our detection and correlation engine to address emerging cyber threats.

Conduct in-depth research on threats and vulnerabilities. Utilize this knowledge to innovate and develop cutting-edge security solutions.

Utilize research insights to innovate and develop cutting-edge security solutions with a focus on security controls and the way they mitigate risk.
Requirements:
3+ years of experience in cybersecurity, with a proven track record in Research analysis, threat detection engineering, or threat hunting.

3+ years of experience in industry cyber-security research

Ability to collect, process, analyze, and interpret large datasets to derive actionable insights, particularly within the realm of protocol research.

Proficiency in programming/scripting languages relevant to protocol analysis.

Experience with network/security-related data analysis.

Strong team player with excellent collaboration skills.

Experience in managing multi-departmental interactions with cybersecurity professionals, engineering teams, and product managers.

Proficiency in SQL and TCP/IP network fundamentals.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769596
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a Security Vulnerability Researcher to be a core driver in how our product empowers security teams. You will be expected to deeply understand customer needs and translate them directly into product features that deliver real value. You'll own key parts of our frontend stack, drive key architectural decisions, and turn complex security data into clear, actionable business insights.



This is a hands-on role for a seasoned offensive researcher who thrives on technical depth and creativity. Youll collaborate closely with product, marketing, and engineering teams to deliver research that drives customer trust, informs product direction, and shapes industry thought leadership.

What Youll Do

Perform AI-Focused Vulnerability Research: Investigate security risks in AI models, APIs, and infrastructure to uncover exploitable weaknesses and publish insights that strengthen our market leadership.
Lead Red Teaming Against AI Systems: Simulate adversarial attacks on AI pipelines and APIs, creating impactful PoCs that showcase real-world risk and defensive strategies.
Build Customer-Facing Proof-of-Concepts: Partner with product and engineering teams to design and deliver PoCs that align with customer use cases and highlight security capabilities.
Requirements:
5+ years in Security Research or Offensive Engineering with a proven track record in penetration testing or vulnerability discovery on complex targets.
Deep expertise in Application & AI Security, including experience exploiting APIs, web applications, and AI/ML vulnerabilities such as prompt injection, adversarial manipulation, or model abuse.
Offensive Security & Red Teaming Experience, with practical use of tools, custom exploits, or adversarial testing methods.
Proficiency in developing and presenting PoCs that clearly demonstrate security risks to both technical and non-technical audiences.
Recognized achievements in Bug Bounty or Military-Grade Security Research, or equivalent real-world offensive security experience.
Solid software engineering background, with the ability to read, write, and debug code (Python, JavaScript, Go, etc.).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8761851
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
15/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: More than one
we are looking for a Junior Fraud Data Scientist.
As a Junior Fraud Data Scientist, you will contribute to our ongoing efforts to protect our ecosystem from financial threats and abuse. Working under the guidance of senior team members in a data-rich environment, you will assist in identifying malicious behaviors, support detection coverage, and help maintain our automated mitigation strategies.
This role is designed for an analytical professional with 1-2 years of experience who wants to build a deep expertise in adversarial data, learn from an experienced team, and develop their technical skills across modern cloud data platforms.
What You Will Be Doing
Exploratory Data Analysis: Support the team by mining behavioral and transactional datasets to help identify anomalies and emerging fraud patterns.
Model Support & Optimization: Assist in building, tuning, and validating machine learning models (e.g., XGBoost, LightGBM) under the supervision of senior data scientists.
Feature Generation: Extract, engineer, and prepare new data features from structured and unstructured sources to help improve model performance.
Dashboarding & Monitoring: Build and maintain internal dashboards and pipelines to track model health, data drift, and key fraud KPIs.
Cross-functional Collaboration: Work alongside Fraud Analytics and Product teams to help translate operational fraud insights into automated data solutions.
Requirements:
Experience: 1-2 years of hands-on professional experience as a Data Scientist or Data Analyst in a data-intensive environment.
Data Science Tech Stack: Solid proficiency in Python (Pandas, NumPy, Scikit-Learn) and strong capability writing and optimizing SQL queries.
Modern Data Infrastructure: Exposure to or basic hands-on experience working within environments like Databricks and data warehouses like BigQuery.
Academic Background: Degree in a quantitative field (Computer Science, Statistics, Data Science, Industrial Engineering, or equivalent).
Business-Impact Focus: An understanding of how to look past raw model metrics (precision/recall) to appreciate the operational impact of data decisions.
Communication: Fluent English with the ability to communicate technical findings clearly to team members.
Bonus Points
Prior exposure to or hands-on projects involving machine learning models in a live, real-time production environment.
Familiarity with MLOps or orchestration tools such as MLflow or Airflow.
Previous domain exposure in FinTech, e-commerce, payments, or trust & safety.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8739975
סגור
שירות זה פתוח ללקוחות VIP בלבד