דרושים » אבטחת מידע וסייבר » Penetration testing specialist- 2579

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
משרה זו סומנה ע"י המעסיק כלא אקטואלית יותר
מיקום המשרה:מרכז
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a talented Penetration Tester & Researcher to lead complex offensive security engagements and groundbreaking research. You will execute sophisticated attack simulations, identify high-value vulnerabilities, and collaborate with clients to enhance their security posture.

This role offers a balance between hands-on technical assessments and original research that shapes the broader cybersecurity community.

Roles and Responsibilities:
Conduct advanced penetration tests across web, mobile, and thick-client applications.
Contribute to internal tools, scripts, and methodologies that enhance efficiency.
Design and simulate real-world attack chains reflecting modern threat actors.
Perform vulnerability research, exploit development, and threat modeling.
Research, develop, and implement offensive security methodologies utilizing AI technologies.
Produce detailed technical reports with actionable remediation strategies.
Collaborate directly with clients to guide mitigation and improve resilience.
Publish research, present findings, and represent us at conferences or in public forums.
Requirements:
Requirements
2-3 years of experience in application penetration testing, including mobile, web, and thick-client applications.
Hands-on experience using AI offensively and attacking AI-powered systems.
Solid technical foundation in networking, operating systems, and cloud.
Excellent communication and presentation skills.
Fluency in Hebrew and English.


Preferred Skills
Active participation in bug bounty programs or responsible disclosure initiatives.
Industry certifications such as OSCP, OSWA, OSWE, or OSCE.
Familiarity with cloud and container security, Kubernetes, and IaC.
Experience integrating security practices within development lifecycles.
Proven ability to lead or publish offensive research.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8745599
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Herzliya
Job Type: Full Time
our Security team is looking for a highly skilled and security-savvy Application Security Engineer to lead our product and application security efforts. In this role, you will drive security design, ensure secure coding practices, and validate our services and environments against the highest security standards.
You will work closely with our R&D and Product teams to identify, mitigate, and prevent security risks throughout the software development lifecycle (SDLC). As a senior engineer, you will own security initiatives, mentor developers on security best practices, and play a key role in shaping the security posture of products.
The ideal candidate is highly motivated, eager to learn, and has a security by design mindset. This role provides career growth opportunities, enabling you to deepen your expertise in AppSec, DevSecOps, and cloud security.
What you'll do:
Partner with development and product teams to integrate security best practices into the SDLC
Lead threat modeling and architecture security reviews to proactively identify and mitigate risks
Conduct security assessments, including code reviews, vulnerability scans, penetration testing, and secure product design reviews
Stay up to date with emerging security threats, vulnerabilities, and industry trends, ensuring remains ahead of evolving risks.
Support and contribute to security incident response activities, including root cause analysis and post-incident improvements
Automate security processes and integrate security tools within CI/CD pipelines
Develop and deliver secure coding training to engineering teams
Requirements:
4+ years of experience in Application Security, Penetration Testing, or Product Security in a SaaS company
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience)
Deep understanding and hands-on experience of web application security, including OWASP Top 10, authentication, encryption, and secure coding principles
Proficiency in scripting or programming languages (Python, JavaScript, Go, etc.) for security automation
Experience with cloud security best practices (AWS, GCP, or Azure)
Hands-on experience with DevSecOps and integrating security tools into CI/CD pipelines
Strong communication skills, with the ability to explain security risks and recommendations to technical and non-technical stakeholders, including executive management
Experience working with large-scale, complex R&D environments
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8723935
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
09/07/2026
חברה חסויה
Location: Herzliya
Job Type: Full Time
we are looking for a talented Application Security Specialist to join our team. In this role, you will take an active part in application penetration testing, threat modeling, Secure SDLC activities, and AppSec initiatives that help evaluate and improve security posture. The position includes hands-on security testing of web, mobile, API, thick client, AI/LLM integrations, and MCP-based application components, identifying and validating vulnerabilities, assessing real business impact, supporting customers with clear remediation guidance, and contributing to application security processes, tools, and best practices.

Responsibilities
Perform hands-on application penetration testing across web, mobile, API, thick client, AI/LLM integrations, and MCP-enabled application components.

Perform threat modeling and secure design reviews to identify risks early in the development lifecycle.

Support development teams with practical remediation guidance and secure implementation recommendations.

Perform Secure Software Development Lifecycle and secure coding training for developers.

Evaluate and improve customers application security development lifecycle, including secure coding practices, vulnerability management, remediation workflows, and security gates.

Participate in client-facing discussions, including assessment scoping, finding walkthroughs, remediation alignment, and retest updates.
Requirements:
Qualifications
2+ years of hands-on experience in application penetration testing.

Strong understanding of OWASP Top 10 and CWE Top 25, with proven experience identifying vulnerabilities and supporting practical remediation strategies.

Familiarity with high-level programming languages (Java, JS, Python, etc.).

Relevant App PT training and certifications such as EWPTX, OSWE, etc.

Strong English communication skills, with the ability to communicate technical topics clearly in client-facing discussions.

Advantage: Deep understanding of the LLM Top 10, AI security risks, MCP security risks, and AI/LLM hacking techniques.

Advantage: Proven experience in secure code review or high-level code auditing.

Advantage: Knowledge of Secure SDLC practices, and methodologies, including Microsoft SDL, OWASP SAMM, and OWASP ASVS.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8731965
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/07/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly skilled and experienced Head of Application Security to join our dynamic team. This role is pivotal in driving the security of our software development lifecycle and ensuring the robustness of our applications against potential threats. The ideal candidate will have a strong background in secure software development practices, including SSDLC implementation, and a deep understanding of security risks & tools. This position reports directly to an R&D VP.
Key Responsibilities
Lead the application security team, providing strategic direction and mentorship.
Develop and implement a comprehensive Secure Software Development Lifecycle (SSDLC) framework.
Oversee the integration of security practices into all phases of the software development lifecycle, including CI/CD guardrails.
Conduct risk assessments and threat modeling to identify and mitigate potential security vulnerabilities.
Collaborate with development teams to ensure secure coding practices and adherence to security standards, while maintaining developer productivity.
Implement and manage security automation tools and processes to enhance the efficiency of security operations.
Stay up-to-date on the latest security trends, vulnerabilities, and technologies to continuously improve our security posture.
Provide expert guidance on security architecture and design for new and existing applications.
Lead incident response efforts related to application security breaches and vulnerabilities.
Foster a culture of security awareness and continuous improvement within the organization.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 7 years of experience in application security, with at least 3 years in a leadership role.
Proven experience in implementing and managing SSDLC frameworks.
In-depth knowledge of security frameworks and methodologies.
Strong understanding of threat modeling methodologies, secure coding practices and common vulnerabilities (e.g., OWASP Top Ten).
Proficiency in programming languages such as Java, Python, C#, or similar.
Experience in implementing security tools and technologies such as ASPM, SAST, DAST in complex and high-scale environment.
Excellent communication and leadership skills, with the ability and passion to drive change across the organization.
Relevant certifications such as CISSP, CISM, or CSSLP are desirable.
Proven experience in a similar role at another leading software development company.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8719435
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
09/07/2026
חברה חסויה
Location: Herzliya
Job Type: Full Time
we are looking for a Cyber Security Expert with hands-on experience in offensive security, possessing strong technical capabilities, in-depth knowledge of adversary simulation, and a passion for Red Team operations.
Responsibilities
Participate in Red Team assessments that simulate real-world threats and remain undetected by the client's defensive team. These stealth operations simulate advanced adversaries and require careful planning, execution, and OPSEC
Lead or co-lead portions of internal and external offensive assessments, including perimeter exploitation and post-exploitation in Active Directory
Perform Purple Team engagements to help clients improve their monitoring and detection capabilities while sharpening your own offensive skills
Document attack paths, risk analysis, technical findings and remediation guidance in detailed reports tailored to both technical and executive audiences.
Collaborate with the team to develop and maintain internal tooling, scripts, and documentation for offensive operations
Continuously research and test new techniques, tools, and attack paths to further enhance Red Team capabilities
Requirements:
Requirements
2+ years of hands-on experience in offensive security, red teaming, or penetration testing
Hands-on experience with C2 frameworks (e.g., Cobalt Strike, Mythic, Sliver)
Strong understanding of Active Directory, domain escalation paths, Kerberos, trust relationships, GPO abuse, credential access, etc.
Proficiency in various offensive techniques such as Relay Attacks, Coercion, Kerberos Attacks, Privilege Escalation, etc.
Familiarity with network protocols (e.g., SMB, DNS, LDAP, HTTP) and system internals (Windows and Linux)
Strong understanding of OPSEC considerations during covert operations
Ability to present and produce clear and actionable technical reports and documentation in English
Experience working in client-facing roles or as part of structured engagements
Proficient in one or more scripting/programming languages: Python, PowerShell, C#, or C++
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8731960
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for talented hackers to join our unique Adversarial Tactics Department. As a Red Team Expert ,you will work with clients to build their resiliency, i.e their capability to prevent and to sustain attacks. You will also be involved in IR engagements with companies that were attacked by adversaries, learn new TTPs and apply those in Red and Purple team engageents.
Your responsibility as a Cyber consultant is to bring the attackers perspective to engagements. You will help design, create and execute Adversary Simulation exercises, and perform attacks against client services, platforms and infrastructure. This will include, among other things, identifying vulnerabilities through simulated external and internal attacks, validating and enhancing an organizations ability to respond and recover from targeted attacks and persistent adversaries.
Requirements:
5+ years of Red Teaming or Adversarial Simulation Experience.
Experience conducting internal and external penetration testing.
Experience designing and/or executing phishing campaigns.
Experience in social engineering.
Experience with EDR/XDR evasion and bypass techniques.
Deep familiarity with Active Directory attacks and defenses.
Extensive experience in penetration testing methodologies and tools.
Deep technical understanding of a broad technology set and the ability to learn new information at a rapid pace.
Proven presentation skills.
Developing, extending, or modifying exploits, shellcode or exploit tools.
Willingness to travel abroad.
Advantages:
Background in application security.
Experience developing tools in one or more of the following: C/C++, Bash, C#, Python, Java, or PowerShell.
Experience with cloud penetration testing (AWS, Azure, Google Cloud Platform).
Fluent English (written and spoken).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8739929
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
3 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for an individual who thrives on unraveling the intricacies of computing environments and attackers' techniques, ultimately providing our customers with cutting-edge tools to elevate their security posture. This role involves conducting both low-level and high-level research on security vulnerabilities, security tools, and the intersection of the two, leveraging various telemetries.
WHAT YOU WILL DO

Collaborate with engineering and product teams to enhance the efficiency and effectiveness of our existing detection engine.

Design and implement new features within our detection and correlation engine to address emerging cyber threats.

Conduct in-depth research on threats and vulnerabilities. Utilize this knowledge to innovate and develop cutting-edge security solutions.

Utilize research insights to innovate and develop cutting-edge security solutions with a focus on security controls and the way they mitigate risk.
Requirements:
3+ years of experience in cybersecurity, with a proven track record in Research analysis, threat detection engineering, or threat hunting.

3+ years of experience in industry cyber-security research

Ability to collect, process, analyze, and interpret large datasets to derive actionable insights, particularly within the realm of protocol research.

Proficiency in programming/scripting languages relevant to protocol analysis.

Experience with network/security-related data analysis.

Strong team player with excellent collaboration skills.

Experience in managing multi-departmental interactions with cybersecurity professionals, engineering teams, and product managers.

Proficiency in SQL and TCP/IP network fundamentals.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769596
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
4 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a rare opportunity to work at the intersection of offensive security and AI - and to have your expertise shape a platform used at enterprise scale. As an Security Researcher, you will push the boundaries of what autonomous agents can achieve.

Your goal is to conduct cutting-edge research into novel attack vectors and vulnerabilities, using those insights to both sharpen our AI and lead the industry conversation on AI-driven security. Youll work alongside a tight-knit team building excellent software in the security space.

Responsibilites
Original Research: Develop new attack strategies and offensive testing techniques for web, network and AI targets, and translate real-world knowledge into improvements for the AI agent
Thought Leadership: Produce high-quality technical content, including research papers, stage demonstrations, or technical blog posts that showcase unique capabilities and security philosophy.
Public Advocacy: Represent research at major security conferences and industry events.
AI Enhancement: Part of the team improving the AI hacker to make it more dangerous and creative.
Collaboration: Work closely with AI and engineering teams to continuously improve agent capabilities and ensure research findings are integrated into the product.
Requirements:
Technical Expertise: Deep expertise in Web and API security, including authentication, business logic, and injection flaws.
Publication Record: Proven experience publishing technical security research (e.g., personal or company blogs, whitepapers) or presenting at recognized security conferences (e.g., Black Hat, DEF CON, OWASP).
Coding Proficiency: Experience in writing code to develop tooling for penetration tests and security research.
Startup Mindset: Comfortable working in a fast-paced environment with a high degree of ownership and curiosity.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8768224
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a Security Vulnerability Researcher to be a core driver in how our product empowers security teams. You will be expected to deeply understand customer needs and translate them directly into product features that deliver real value. You'll own key parts of our frontend stack, drive key architectural decisions, and turn complex security data into clear, actionable business insights.



This is a hands-on role for a seasoned offensive researcher who thrives on technical depth and creativity. Youll collaborate closely with product, marketing, and engineering teams to deliver research that drives customer trust, informs product direction, and shapes industry thought leadership.

What Youll Do

Perform AI-Focused Vulnerability Research: Investigate security risks in AI models, APIs, and infrastructure to uncover exploitable weaknesses and publish insights that strengthen our market leadership.
Lead Red Teaming Against AI Systems: Simulate adversarial attacks on AI pipelines and APIs, creating impactful PoCs that showcase real-world risk and defensive strategies.
Build Customer-Facing Proof-of-Concepts: Partner with product and engineering teams to design and deliver PoCs that align with customer use cases and highlight security capabilities.
Requirements:
5+ years in Security Research or Offensive Engineering with a proven track record in penetration testing or vulnerability discovery on complex targets.
Deep expertise in Application & AI Security, including experience exploiting APIs, web applications, and AI/ML vulnerabilities such as prompt injection, adversarial manipulation, or model abuse.
Offensive Security & Red Teaming Experience, with practical use of tools, custom exploits, or adversarial testing methods.
Proficiency in developing and presenting PoCs that clearly demonstrate security risks to both technical and non-technical audiences.
Recognized achievements in Bug Bounty or Military-Grade Security Research, or equivalent real-world offensive security experience.
Solid software engineering background, with the ability to read, write, and debug code (Python, JavaScript, Go, etc.).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8761851
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
02/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Security Lead to join our companys R&D organization, taking a central, cross-functional role in shaping the security posture of our products. This role combines deep hands-on expertise with cross-organizational leadership, working closely with senior leaders to shape and implement security strategy across all product lines. You will lead end-to-end security initiatives, influence engineering practices at scale, and play a critical role in ensuring our products meet the highest security standards.
Key Responsibilities
Lead security in the R&D organization by professionalism and cooperation across our company
Maintain and develop the Secure Development Life Cycle of all our companys Products Organization, work with R&D, QA, Sales, Support, external researchers, and customers to make the cyber landscape a safer place.
Conduct architectural security reviews and threat modeling for R&D
Full triage for our company's VDP and BBP reports, including analyzing reports, calculating severities and communications with reporters.
Define and develop security training to implement cross organization
Be a first responder in security incidents, including leading and defining actions to resolution
Manage and monitor our company's SCA, SAST, DAST tools.
Requirements:
Proven ability to lead and influence leaders across the organization.
In-depth knowledge of Secure Development Life Cycle (SDLC) processes, secure architecture, third-party tools, and security policies.
Threat modeling & secure design - Ability to review architectures, identify abuse cases, and guide developers on secure design decisions early in the lifecycle.
Expertise in identifying, analyzing, and mitigating security vulnerabilities, including familiarity with Common Vulnerabilities and Exposures (CVE) and the Common Vulnerability Scoring System (CVSS).
Hands-on experience with AppSec tooling - SAST, DAST, SCA (e.g., SonarQube, Snyk, JFrog Xray), including tuning, triaging results, and integrating into CI/CD pipelines.
Experience with vulnerability management and the ability to interpret and apply security standards, guidelines, and regulations.
Proficiency in secure coding practices and the ability to conduct code reviews for security vulnerabilities.
Familiarity with incident response processes, security monitoring, and threat intelligence.
Offensive mindset - Ability to think like an attacker (manual testing, basic exploitation techniques) to validate real impact and reduce false positives.
Advantage:
Prior experience in software development.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8721058
סגור
שירות זה פתוח ללקוחות VIP בלבד