דרושים » אבטחת מידע וסייבר » מומחה /ית תקיפה /מבדקי חוסן למשרד ממשלתי באזור המרכז

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בSQLink
סוג משרה: משרה מלאה
משרד ממשלתי באזור המרכז מגייס מומחה/ית תקיפה / מבדקי חוסן
התפקיד כולל: ביצוע מבדקי חוסן (אפליקטיביים, תשתיתיים וענן) סימולציות תקיפה (Red Team) מול מערכות קריטיות, זיהוי חולשות מורכבות והובלת תיקונן מול צוותי פיתוח ותשתיות. עבודה מול SOC, IR וצוותי הגנה, כתיבת דוחות טכניים ומנהלתיים ברמה גבוהה ועוד.
דרישות:
- 5 שנות ניסיון בבדיקות חדירה / Red Team
- ניסיון בתקיפות Web (OWASP Top 10) ובתקיפות תשתית (AD, Kerberos,
lateral movement)
- נסיון במערכות הפעלה Windows / Linux
- ניסיון מעשי עם כלים כמו: o Burp Suite / Nessus / Nmap / Metasploit /
BloodHound
- ניסיון בכתיבת סקריפטים ( Python / PowerShell / Bash) והבנה עמוקה של רשתות
(TCP/IP, DNS, VPN וכו) המשרה מיועדת לנשים ולגברים כאחד.
 
הסתר
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8745160
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בדטה קיוב בע''מ
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה ועבודה היברידית
במסגרת התפקיד ביצוע מבדקי חדירה אפליקטיביים, תשתיתיים, בענן ובסביבות AI, ביצוע סקרי סיכונים, כתיבת דוחות מקצועיים, ניהול פגישות מול גורמי פיתוח וטכנולוגיה, פיתוח יכולות תקיפה חדשות ובדיקות תאימות לרגולציות וסטנדרטים.
עבודה עם PT, OWASP, NIST, PCI-DSS, AWS, Azure
סביבת עבודה מאתגרת הכוללת הובלת תהליכי אבטחת מידע מתקדמים ועבודה עם צוותים טכנולוגיים מובילים.
דרישות:
ניסיון של 3 שנים ומעלה בביצוע מבדקי חדירה למערכות Web ו-Mobile כאשר מבדקי חדירה מהווים 100% מהתפקיד
ידע מעמיק במתודולוגיות תקיפה ובתקנים OWASP, MITRE, NIST
הבנה בפרוטוקולי תקשורת TCP/UDP, DNS, IP, HTTPS ובטכניקות תקיפת רשת
היכרות עם AWS ו-Azure וביצוע מבדקי חדירה בסביבות ענן - יתרון
שליטה ב-PowerShell, Bash, JavaScript ו- Python או ניסיון בארגון פיננסי - יתרון המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8737697
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
1 ימים
דרושים בJob-Time
סוג משרה: משרה מלאה
לתאגיד פיננסי מוביל דרוש/ה ראש צוות IR למשרה מלאה ברמת גן.
במסגרת התפקיד: ניהול והובלת צוות IR ותוכנית העבודה, הובלת חקירות סייבר מורכבות (Tier 3), Forensics ו-Threat Hunting, פיתוח ושיפור יכולות זיהוי והגנה (EDR, SIEM, Playbooks), ניהול פעילות SOC חיצוני, SLA ובקרת איכות, הובלת תרגילי Purple Team, סימולציות תקיפה (BAS) ויוזמות חדשנות.
דרישות:
לפחות 3 שנות ניסיון בחקירת אירועי סייבר ברמת Tier 3 - חובה.
ניסיון בניהול צוות טכני - חובה.
ניסיון בעבודה עם EDR, SIEM (Sentinel / Splunk) וכתיבת שאילתות KQL / SPL - חובה.
ניסיון בניהול או עבודה מול SOC חיצוני - חובה.
היכרות מעמיקה עם עולמות AI בהיבטי איומים והגנה - חובה.
הבנה רחבה של תשתיות IT, רשתות, Windows/ Linux וזהויות (AD / Entra ID) - חובה.
ניסיון ב-MITRE ATT CK, Purple Team / Red Team / BAS או Pentest - יתרון.
הסמכות רלוונטיות (GCIH, GCFA, GCIA, OSCP, CRTO וכד') - יתרון.
אנגלית ברמה גבוהה. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8747222
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 11 שעות
דרושים בIngima
מיקום המשרה: תל אביב יפו
סוג משרה: משרה מלאה
ביצוע סקרי סיכונים למערכות החברה
זיהוי חולשות במערכות קיימות ומערכות בתהליכי הטמעה.
סקירה של הקשחות אל מול סטנדרטים מקובלים
בדיקות רגולטוריות בהתאם לרגולציות בארגונים פיננסים
הערכת האפקטיביות של הבקרות המפצות.
מתן המלצות למידור החולשות
עבודה מול הצוותים המקצועיים במטרה לוודא מיגור החולשות.
עבודה בצוות מקצועי במתכונת של purple team
דרישות:
ידע וניסיון קודם בביצוע סקרי אבטחת מידע: ביצוע סקרים שונים(security assessments) לרמות תשתית ואפליקציה, כולל זיהוי, דיווח ופתרון בעיות אבטחה.
כולל הכנת דוחות והמלצות לאחר סיום הסקרים. (ONPREMIS/AZURE/AWS/ Linux )
ניסיון בביצוע מבדקי חדירה(penetration testing): ניסיון מעשי בביצוע מבדקי חדירה ברמות תשתית ואפליקציה פלטפורמות, שרתים, אפליקציות ו-mobile (ONPREMIS/AZURE/AWS/ Linux ) כולל הכנת דוחות והמלצות לאחר סיום הסקרים.
הבנה טכנית גבוהה: ידע מעמיק בטכנולוגיות אבטחת מידע, סקרי פגיעויות, פרוטוקולים, טכניקות חדירה וכלי עבודה בתחום הpenetration testing-
ראייה מערכתית: יכולת עבודה עם מגוון רחב של מערכות טכנולוגיות ויכולת להבין את השפעת אבטחת המידע בהיבטים רחבים של מערכות ארגוניות.
הכרות עם סטנדרטים בתחום אבטחת המידע: ידע והבנה מעמיקה של דרישות אבטחת המידע והרגולציות בתחום הפיננסי, כולל יכולת התאמה לרגולציות מחמירות כמו:ISO 2700 NIST, PCI-DSS, GDPR.
הסמכות רלוונטיות: הסמכות מוכרות בתחום המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8750108
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 13 שעות
דרושים באלעד מערכות
מיקום המשרה: פתח תקווה
סוג משרה: משרה מלאה ועבודה היברידית
אלעד מערכות מגייסת סוקר.ת אבטחת מידע | פתח תקווה
לארגון פיננסי גדול ומוביל דרוש.ה סוקר.ת אבטחת מידע להשתלבות בצוות מקצועי במתכונת Purple Team, עם עבודה על מערכות מורכבות, סקרי סיכונים ובדיקות מתקדמות בסביבות Enterprise.
דרישות:
ניסיון בביצוע סקרי אבטחת מידע, Penetration Testing
ניסיון בעבודה עם סביבות AWS / Azure / Linux
היכרות עם כלי אבטחת מידע, סקרי פגיעויות וטכניקות תקיפה
ניסיון בכתיבת דוחות והמלצות מקצועיות
היכרות עם תקני אבטחת מידע ורגולציות כגון ISO27001 / NIST / PCI-DSS
יכולת עבודה בצוות וראייה מערכתית
הסמכות בתחום הסייבר כגון CEH / OSCP / CISSP - יתרון 
ניסיון עם Docker / Kubernetes / CI-CD - יתרון 
ניסיון בעבודה בארגונים פיננסיים - יתרון המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8669381
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 14 שעות
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה
במסגרת תפקידו יוביל חקירות של אירועי סייבר - זיהוי, ניתוח, תיעוד, תגובה ושיפור תהליכים.
אחריות על הפקת תוצרים מודיעיניים וכתיבת דוחות טקטיים ואסטרטגיים.
יבצע חקירות פורנזיות, ניתוח לוגים, זיהוי דפוסי תקיפה והכנת תיקי חקירה.
עבודה עם הרבה ממשקים פנים ארגוניים - IT / SOC / SECOPS / GRC
עבודה עם שותפים מודיעיניים חוצי ארגון.
ניהול אירועי סייבר מתגלגלים מא' ועד ת'.
דרישות:
ניסיון של 2-3 שנים באירועי תגובה (Incident Response) ומודיעין סייבר
חובה - ניסיון ב- Digital Forensics
יכולת ניהול חקירה מא' ועד ת' - לוגים, ניתוח טכני, שרתים, תחנות קצה, אפליקציות WEB וכו'
חובה - היכרות עם MITRE (מערכות למיפוי מתקפות - טכניקות תקיפה)
חובה - אנגלית כתובה ומדוברת המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8694926
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 18 שעות
דרושים בקבוצת Aman
מיקום המשרה: רמת גן
סוג משרה: משרה מלאה ועבודה היברידית
חלק מצוות הגנת הסייבר המנחה ומלווה פרויקטים תשתיתיים ואפליקטיביים בהיבטי אבטחת מידע, מאתר סיכונים למידע ומגבש פתרונות להקטנתם.
ליווי פרויקטים טכנולוגיים בהיבטי אבטחת מידע בכל שלבי מחזור החיים בפרויקט
הגדרת צרכי אבטחת מידע, מציאה והטמעת פתרונות מתאימים, התאמת טכנולוגיות רלוונטיות וביצוע בחינה טכנולוגית לשיפור מערך אבטחת המידע.
שותפות בתכנון ארכיטקטורה מאובטחת בהתאם למדיניות החברה.
ליווי סקרי אבטחה, הערכות סיכונים, מבדקי חדירה ותיקופם.
דרישות:
לפחות שנתיים ניסיון בתפקיד דומה בליווי פרויקטים תשתיתיים ואפליקטיביים או בתפקידים אחרים בצוות אבטחת מידע - חובה.
ניתוח סיכונים וחולשות אבטחת מידע והשלכותיהן על מערכות ארגוניות, מערכות הפעלה ותקשורת בשכבות השונות - חובה
ניסיון באבטחת מערכות אפליקטיביות ויכולת קריאת קוד -- חובה.
ניסיון בתיחום ותיקוף מערכות - חובה
ניסיון בעולמות ארכיטקטורה, תקשורת, פרוטוקולים, ואפליקציות- חובה.
ניסיון באבטחת מידע בארגון פיננסי גדול - יתרון.
הסמכות בתחום אבטחת מידע CISSP, CISM- יתרון.
עבודה מעשית במערכות -Firewall, הלבנה, וכספות לניהול גישה ומידע
רקע בעולמות מחשוב הענן ועולם המובייל. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8353192
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Herzliya
Job Type: Full Time
our Security team is looking for a highly skilled and security-savvy Application Security Engineer to lead our product and application security efforts. In this role, you will drive security design, ensure secure coding practices, and validate our services and environments against the highest security standards.
You will work closely with our R&D and Product teams to identify, mitigate, and prevent security risks throughout the software development lifecycle (SDLC). As a senior engineer, you will own security initiatives, mentor developers on security best practices, and play a key role in shaping the security posture of products.
The ideal candidate is highly motivated, eager to learn, and has a security by design mindset. This role provides career growth opportunities, enabling you to deepen your expertise in AppSec, DevSecOps, and cloud security.
What you'll do:
Partner with development and product teams to integrate security best practices into the SDLC
Lead threat modeling and architecture security reviews to proactively identify and mitigate risks
Conduct security assessments, including code reviews, vulnerability scans, penetration testing, and secure product design reviews
Stay up to date with emerging security threats, vulnerabilities, and industry trends, ensuring remains ahead of evolving risks.
Support and contribute to security incident response activities, including root cause analysis and post-incident improvements
Automate security processes and integrate security tools within CI/CD pipelines
Develop and deliver secure coding training to engineering teams
Requirements:
4+ years of experience in Application Security, Penetration Testing, or Product Security in a SaaS company
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience)
Deep understanding and hands-on experience of web application security, including OWASP Top 10, authentication, encryption, and secure coding principles
Proficiency in scripting or programming languages (Python, JavaScript, Go, etc.) for security automation
Experience with cloud security best practices (AWS, GCP, or Azure)
Hands-on experience with DevSecOps and integrating security tools into CI/CD pipelines
Strong communication skills, with the ability to explain security risks and recommendations to technical and non-technical stakeholders, including executive management
Experience working with large-scale, complex R&D environments
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8723935
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
15/06/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a SecOps Engineer to join our Security Operations team as the technical lead for Incident Response and Cloud Security.

The team is responsible for monitoring our production and corporate environments, responding to security incidents, and continuously hardening our cloud, network, and CI/CD posture. This role is the senior technical anchor of the function: the first responder during critical incidents, the architect behind our cloud and network defenses, and a technical mentor to the rest of the team.

You will own the Incident Response practice, lead our cloud security program across CNAPP, SASE/ZTNA, and CI/CD supply-chain security, and partner with Engineering, DevOps, and Platform teams to drive security improvements at scale. Participation in an on-call rotation for critical incidents is required.

How Will You Make an Impact?

Own our SASE/ZTNA stack: policy management, network security, secure access.

Own our CNAPP platform: workload protection, posture management, vulnerability prioritization.

Own our CI/CD security platform and drive software supply-chain security across the organization.

Serve as IR Expert: first responder for critical security incidents, owning detection, containment, eradication, and recovery.

Lead post-incident root-cause analysis and drive remediation across the organization.

Build and maintain IR playbooks, runbooks, and tabletop exercises.

Partner with DevOps and Platform teams on secure-by-default cloud architecture.

Contribute to broader security architecture decisions across the security stack.

Mentor more junior engineers on the team and lead technical reviews of their work.

Act as deputy to the SecOps Team Lead on strategic initiatives.

Participate in the critical-incident on-call rotation.
Requirements:
 3-4 years of hands-on experience in Security Operations or Security Engineering.

Demonstrated Incident Response leadership: You have run real incidents end to end, from detection through post-incident review.

Hands-on experience with CNAPP, CSPM, or CWPP platforms.

Knowledge of AWS, GCP, or Azure security primitives and cloud-native threat models.

Experience with SASE or ZTNA architectures.

Familiarity with CI/CD and software supply-chain security (e.g., GitHub Actions hardening, SLSA).

Scripting skills in Python (or equivalent) for automation, tooling, and IR support.

Working knowledge of MITRE ATT&CK and modern adversary tradecraft.

Ability to lead a war room, brief executives, and communicate clearly under pressure
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8695446
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
09/07/2026
חברה חסויה
Location: Herzliya
Job Type: Full Time
we are looking for a Cyber Security Expert with hands-on experience in offensive security, possessing strong technical capabilities, in-depth knowledge of adversary simulation, and a passion for Red Team operations.
Responsibilities
Participate in Red Team assessments that simulate real-world threats and remain undetected by the client's defensive team. These stealth operations simulate advanced adversaries and require careful planning, execution, and OPSEC
Lead or co-lead portions of internal and external offensive assessments, including perimeter exploitation and post-exploitation in Active Directory
Perform Purple Team engagements to help clients improve their monitoring and detection capabilities while sharpening your own offensive skills
Document attack paths, risk analysis, technical findings and remediation guidance in detailed reports tailored to both technical and executive audiences.
Collaborate with the team to develop and maintain internal tooling, scripts, and documentation for offensive operations
Continuously research and test new techniques, tools, and attack paths to further enhance Red Team capabilities
Requirements:
Requirements
2+ years of hands-on experience in offensive security, red teaming, or penetration testing
Hands-on experience with C2 frameworks (e.g., Cobalt Strike, Mythic, Sliver)
Strong understanding of Active Directory, domain escalation paths, Kerberos, trust relationships, GPO abuse, credential access, etc.
Proficiency in various offensive techniques such as Relay Attacks, Coercion, Kerberos Attacks, Privilege Escalation, etc.
Familiarity with network protocols (e.g., SMB, DNS, LDAP, HTTP) and system internals (Windows and Linux)
Strong understanding of OPSEC considerations during covert operations
Ability to present and produce clear and actionable technical reports and documentation in English
Experience working in client-facing roles or as part of structured engagements
Proficient in one or more scripting/programming languages: Python, PowerShell, C#, or C++
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8731960
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a Senior Security Engineer to own and elevate the security posture of our
cloud-native, AI-driven SaaS platform. Reporting to the Director of DevOps, you'll be the technical
anchor for security across our product, infrastructure, and organization - combining hands-on
engineering with the strategic judgment to translate risk into clear, actionable priorities.
This is a high-ownership role for someone who can operate end to end: threat modeling a new feature
in the morning, hardening cloud infrastructure in the afternoon, and briefing leadership on risk posture
by the end of the week. As we scale our platform and deepen our use of AI/ML, you'll define how we
build, ship, and operate securely - often standing up programs and controls that don't yet exist.
You'll work cross-functionally well beyond engineering, partnering with Customer Success, Marketing,
Finance, and Legal to make security a shared, business-aware practice rather than a gate at the end of
the line.
What You'll Do:
Own the day-to-day security engineering function across cloud infrastructure, application, and data
layers.
Lead threat modeling, penetration testing, and vulnerability management across the product and
platform lifecycle.
Design, implement, and continuously improve cloud security controls across AWS, GCP, and/or
Azure environments.
Assess and secure our AI/ML systems, addressing the unique risks they introduce - from data
pipelines to model and LLM behavior.
Drive compliance readiness and audit support for frameworks such as SOC 2, ISO 27001, and
GDPR.
Embed security into the SDLC and CI/CD pipelines, partnering closely with DevOps and engineering
teams.
Translate technical risk into clear business and board-level language, and advise leadership on
prioritization and trade-offs.
Partner cross-functionally with non-engineering teams (Customer Success, Marketing, Finance,
Legal) to build security awareness and practical, low-friction controls.
Lead or support incident response, including detection, containment, remediation, and post-incident
review.
Requirements:
8+ years in security engineering, security architecture, or a CISO/Security Officer role.
Deep cloud security experience (AWS / GCP / Azure).
Hands-on with threat modeling, penetration testing, and vulnerability management.
Working knowledge of AI/ML systems and their unique security challenges.
Experience with compliance frameworks: SOC 2, ISO 27001, GDPR (or equivalent).
Strong communication - translates technical risk into business and board language.
Comfortable operating cross-functionally with non-engineering teams (CS, Marketing, Finance).
Nice to Have
Prior experience in a fast-scaling SaaS or AI-driven product company.
Hands-on red-teaming of LLM-based systems.
Familiarity with the OWASP LLM Top 10 and NIST AI RMF.
Certifications: CISSP, CISM, CCSP, or equivalent.
Experience standing up a security program from scratch (rather than scaling an existing one).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8718587
סגור
שירות זה פתוח ללקוחות VIP בלבד