דרושים » ניהול ביניים » Senior Manager - Product Red Team

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
Location: Petah Tikva
Job Type: Full Time and Hybrid work
We seek an experienced offensive security leader to build and lead the Product Red Team. This newly established function emulates real-world attacks against synthetic customer instances to identify vulnerabilities, misconfigurations, and design gaps before external threat actors or researchers discover them.
This role requires an operator who has led offensive security operations in high-consequence environments-covert intelligence or military settings preferred-with proven ability to establish operational standards, navigate ambiguous mission parameters, and influence cross-functional stakeholders around complex security trade-offs.
You will build upon this team's charter, engagement frameworks, and rules of engagement with other teams. You will help drive our product security and response posture through adversary emulation, vulnerability research, exploit development, and collaboration with other offensive and defensive teams.
Key Responsibilities:
Establish Operations Objectives, Policies & Procedures:
Own Product Red Team's operation objectives and engagement selection criteria in alignment with product security roadmap and risk register, CISO directives, and company priorities.
Expand upon rules of engagement, threat actor emulation standards, testing policies, and protocols.
Establish operational security procedures for covert operations, detection evasion, and incident response protocols.
Create escalation procedures and approval frameworks for high-risk engagements.
Own campaign selection processes, engagement proposal templates, and findings documentation and readout standards.
Define Engagement Framework & Success Metrics:
Design and implement engagement types: vulnerability risk assessment, product security assessments, and ongoing adversarial campaigns.
Establish and report on technical and operational success metrics: kill chain coverage, remediation velocity, and detection engineering insights.
Create reporting templates-technical findings, executive briefings, engineering recommendations-that drive actionable remediation.
Define boundaries and operational testing windows in coordination with product engineering and detection engineering teams.
Lead Offensive Operations Team:
Build team capability across threat actor emulation, exploit development, persistence mechanisms, supply chain security, and AI-specific attack vectors (prompt injection, model manipulation, data poisoning).
Mentor team on operational security tradecraft, documentation discipline, and risk management under ambiguous conditions.
Support team members in their time zones, spanning from US West Coast to India.
Requirements:
12+ years of offensive security experience, with minimum 5+ years leading offensive operations teams in mission-critical environments.
Background in leading covert offensive cyber operations in:
Intelligence communities, or
Contracted equivalent, or
Top-tier private-sector adversary emulation firms or internal teams.
Expertise in:
Threat actor emulation and MITRE ATT&CK methodologies as translated and applied to product security.
Exploit development and proof-of-concept creation.
Persistence mechanisms, detection evasion, and command & control operations in SaaS environments.
Kill chain analysis and attack path development.
Security control validation and testing under strict rules of engagement.
Proven ability to:
Operate under ambiguous mission parameters and establish doctrine.
Establish and enforce operational security discipline in high-stakes environments.
Navigate regulatory and legal constraints while maintaining operational effectiveness.
Mentor elite operators and maintain team excellence under pressure.
Brief executives on complex security risks and influence decision-making.
Product security awareness: Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and multi-tenant architecture considerations.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8751380
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בריקרוטיקס בע"מ
Job Type: Full Time and Hybrid work
Junior Cybersecurity Specialist
at a Leading Cyber Company
Our company
specializes in cybersecurity consulting, and we are looking for a motivated
Junior Cybersecurity Specialist
to join our technology team.
We offer a dynamic entry-level role in a company that greatly values human capital, with exposure to cutting-edge security technologies and top-tier clients.
Responsibilities:
Assist in performing technical security surveys and basic risk assessments for organizational systems and cloud/on-prem environments (Azure/AWS/MS365).
Support implementation of hardening guidelines and security best practices.
Assist in configuration and maintenance of security tools such as EDR, FW, Intune and access controls.
Prepare documentation and reports following technical reviews.
Work closely with senior team members and collaborate with IT and internal teams to support
Requirements:
Certificate or diploma in cybersecurity. Up to 1-2 years of hands-on experience in cybersecurity / IT (including relevant military or student roles).
Basic familiarity with hardening and security tools (EDR, FW).
Basic understanding of cloud environments (AWS / Microsoft 365 & Azure).
Familiarity with Windows Active Directory environments (ADUC, GPO).
Basic networking knowledge (Switch, Router/FW, Segmentation).
Familiarity with scripting (PowerShell / Python ) - advantage.
Strong motivation to learn and grow in the cybersecurity field.
This position is open to all candidates.
 
Show more...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8745077
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בלוגיקה IT
סוג משרה: משרה מלאה ועבודה היברידית
Ready to Power Up Your Career?

דרוש/ה GRC Security Specialist
תל אביב | משרה מלאה | יומיים בשבוע מהבית

לחברת SaaS מובילה בתל אביב דרוש/ה GRC Security Specialist לתפקיד Hands-On משמעותי בצוות אבטחת המידע.
במסגרת התפקיד תהיה אחריות על ניהול תהליכי GRC מקצה לקצה, כולל הערכת סיכוני ספקים וגורמי צד ג', הובלת ביקורות פנימיות וחיצוניות, תחזוקת הסמכות ועמידה בתקנים, כתיבה ועדכון של מדיניות ונהלי אבטחת מידע, וכן הובלת פעילויות מודעות והדרכות בארגון.
התפקיד כולל עבודה שוטפת מול ממשקים רבים בארגון, בהם צוותי Security" פיתוח, תשתיות, IT, משפטית, פרטיות ורכש, תוך תרגום דרישות אבטחת מידע ורגולציה לתהליכים פרקטיים וברורים.
דרישות:
2+ שנות ניסיון בעולמות GRC, אבטחת מידע או Compliance
ניסיון בניהול עצמאי של תהליכי TPRM והערכת סיכוני ספקים
היכרות מעמיקה עם תקנים ומסגרות כגון: ISO 27001, SOC 2, GDPR, NIST ו-HIPAA
ניסיון בניהול ביקורות, איסוף ראיות, עבודה מול מבקרים והובלת תהליכי תיקון
יכולת עבודה עצמאית, ניהול מספר משימות במקביל וירידה לפרטים
תקשורת מצוינת בעברית ובאנגלית
ניסיון מחברת SaaS - יתרון משמעותי

"When the match is right - everything Powers Up" המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8739749
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים ביוניטסק
סוג משרה: משרה מלאה ועבודה היברידית
לתפקיד מוביל ומאתגר בתחום הסייבר דרוש/ה ראש צוות IR לניהול והובלת צוות תגובה לאירועי סייבר ברמת Tier 3.
התפקיד כולל הובלה מקצועית של צוות Incident Response.

תיאור התפקיד:
ניהול והובלת צוות IR ותכנון תוכנית עבודה שנתית, כולל הצבת יעדים, תעדוף משימות וניהול שוטף
הובלת חקירות סייבר מורכבות מקצה לקצה (Tier 3) כולל Forensics ו-Threat Hunting
פיתוח ותחזוקה של חוקי זיהוי ב-EDR ובמערכות הגנה נוספות
עבודה על שיפור מתמיד של Playbooks והטמעת בקרות מבוססות Threat Intelligence ו-MITRE ATT CK
ניהול והפעלת ספק SOC חיצוני כולל SLA, KPI ובקרת איכות
אחריות על מוכנות לוגים ויכולת חקירה אפקטיבית
הובלת POCs, חדשנות ובחינת טכנולוגיות הגנה מתקדמות
הפעלת תהליכי Purple Team ו-Breach Attack Simulation לשיפור יכולות זיהוי ותגובה
עבודה שוטפת מול צוותי IT, ענן, תשתיות, BCP, מודיעין סייבר והנהלה
דרישות:
ניסיון של 3+ שנים בחקירות אירועי סייבר ברמת Tier 3 - חובה
ניסיון בניהול צוות טכני - חובה
ניסיון בעבודה ו/או ניהול SOC חיצוני כולל SLA - חובה
ניסיון בכתיבת חוקי זיהוי ב-EDR - חובה
ניסיון בעבודה עם SIEM (Sentinel / Splunk) וכתיבת שאילתות KQL / SPL - חובה
הבנה עמוקה בתשתיות IT: רשתות, Windows/ Linux, Active Directory / Entra ID - חובה
היכרות עם MITRE ATT CK ותרגום TTPs לבקרות - יתרון
ניסיון ב-Purple Team / Red Team / Pentest - יתרון
ניסיון עם מערכות סימולציה התקפית - יתרון
הסמכות רלוונטיות (GCIH / GCFA / OSCP / CRTO וכו) - יתרון
אנגלית ברמה גבוהה מאוד המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8723551
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים במלם תים
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה ומתאים גם לחיילים משוחררים
חברת InfraEdge מגייסת אותך לתפקיד Cyber security Architect להובלת תכנון ויישום תפיסת אבטחה מתקדמת בסביבות Multi Cloud SaaS.
במסגרת התפקיד תכנון ארכיטקטורת הגנה רב שכבתית, הגדרת סטנדרטים וקווי בסיס לאבטחה, חיבור בין ארכיטקטורה, צוותי ניטור ותגובה לאירועים לצורך שיפור נראות וזיהוי איומים, והובלת פתרונות אבטחה משלב התכנון ועד לעלייה לייצור תוך מדידה ובקרה.
דרישות:
-  ניסיון של 3+ שנים בתחום ה-Cloud Security / Security Architecture
-  ניסיון מוכח בתכנון ארכיטקטורת אבטחה בלפחות שני ספקי ענן מובילים (AWS/GCP/Azure)
- רקע קודם בעולמות Security או DevOps /Cloud עם התמחות באבטחת מידע.
- היכרות עם SaaS, CSPM/CNAPP, IaC ותקני אבטחה כגון NIST / SOC2 - יתרון משמעותי. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8654277
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
לפני 23 שעות
דרושים בJob-Time
סוג משרה: משרה מלאה
לתאגיד פיננסי מוביל דרוש/ה ראש צוות IR למשרה מלאה ברמת גן.
במסגרת התפקיד: ניהול והובלת צוות IR ותוכנית העבודה, הובלת חקירות סייבר מורכבות (Tier 3), Forensics ו-Threat Hunting, פיתוח ושיפור יכולות זיהוי והגנה (EDR, SIEM, Playbooks), ניהול פעילות SOC חיצוני, SLA ובקרת איכות, הובלת תרגילי Purple Team, סימולציות תקיפה (BAS) ויוזמות חדשנות.
דרישות:
לפחות 3 שנות ניסיון בחקירת אירועי סייבר ברמת Tier 3 - חובה.
ניסיון בניהול צוות טכני - חובה.
ניסיון בעבודה עם EDR, SIEM (Sentinel / Splunk) וכתיבת שאילתות KQL / SPL - חובה.
ניסיון בניהול או עבודה מול SOC חיצוני - חובה.
היכרות מעמיקה עם עולמות AI בהיבטי איומים והגנה - חובה.
הבנה רחבה של תשתיות IT, רשתות, Windows/ Linux וזהויות (AD / Entra ID) - חובה.
ניסיון ב-MITRE ATT CK, Purple Team / Red Team / BAS או Pentest - יתרון.
הסמכות רלוונטיות (GCIH, GCFA, GCIA, OSCP, CRTO וכד') - יתרון.
אנגלית ברמה גבוהה. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8747222
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
דרושים בNishapro
מיקום המשרה: רמת גן ופתח תקווה
סוג משרה: משרה מלאה ועבודה היברידית
לארגון פיננסי גדול ומוביל דרוש/ה סוקר אבטחת מידע לביצוע, סקרי סיכונים.
ביצוע סקרי סיכונים למערכות החברה
זיהוי חולשות במערכות קיימות ומערכות בתהליכי הטמעה.
סקירה של הקשחות אל מול סטנדרטים מקובלים
בדיקות רגולטוריות בהתאם לרגולציות בארגונים פיננסים
הערכת האפקטיביות של הבקרות המפצות.
מתן המלצות למידור החולשות
עבודה מול הצוותים המקצועיים במטרה לוודא מיגור החולשות.
עבודה בצוות מקצועי במתכונת של purple team
דרישות:
ידע וניסיון קודם בביצוע סקרי אבטחת מידע: ביצוע סקרים שונים(security assessments) לרמות תשתית ואפליקציה, כולל זיהוי, דיווח ופתרון בעיות אבטחה.
כולל הכנת דוחות והמלצות לאחר סיום הסקרים. (ONPREMIS/AZURE/AWS/ Linux )
ניסיון בביצוע מבדקי חדירה(penetration testing): ניסיון מעשי בביצוע מבדקי חדירה ברמות תשתית ואפליקציה פלטפורמות, שרתים, אפליקציות ו-mobile (ONPREMIS/AZURE/AWS/ Linux ) כולל הכנת דוחות והמלצות לאחר סיום הסקרים.
הבנה טכנית גבוהה: ידע מעמיק בטכנולוגיות אבטחת מידע, סקרי פגיעויות, פרוטוקולים, טכניקות חדירה וכלי עבודה בתחום ה penetration testing.
ראייה מערכתית: יכולת עבודה עם מגוון רחב של מערכות טכנולוגיות ויכולת להבין את השפעת אבטחת המידע בהיבטים רחבים של מערכות ארגוניות.
הכרות עם סטנדרטים בתחום אבטחת המידע: ידע והבנה מעמיקה של דרישות אבטחת המידע והרגולציות בתחום הפיננסי, כולל יכולת התאמה לרגולציות מחמירות כמו:ISO 2700 NIST, PCI-DSS, GDPR.
הסמכות רלוונטיות: הסמכות מוכרות בתחום אבטחת המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8746839
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בבזק בינלאומי בע"מ
מיקום המשרה: פתח תקווה
סוג משרה: משרה מלאה
אגף פתרונות לעסקים בבזק בינלאומי TECH מגייס מומחה/ית אבטחת מידע
לפעילות בצוות Professional Services עבור יישום פרויקטים, ביצוע התקנות ותפעול תקלות בפתרונות אבטחת מידע עבור הלקוחות העסקיים והאסטרטגיים של החברה.
מדובר בתפקיד הנמצא בחוד החנית בכל הקשור לעבודת HANDS ON בעולמות השונים של אבטחת מידע, וכרוך בהיכרות מעמיקה ועבודה שוטפת עם מוצרי אבטחת מידע של מיטב היצרנים - כדוגמת סיסקו, פורטינט, F5 ועוד רבים וטובים.
העבודה כוללת הקמת פרויקטים מאתגרים בעולמות אבטחת המידע עבור לקוחותינו העסקיים, לרבות אפיון טכני ברמת LOW LEVEL DESIGN, בניית תיקי מערכת, מעקב ובקרה על משימות, טיפול בתקלות ותחזוקה של מוצרי אבטחת המידע.
דרישות:
- ניסיון מעשי של 4 שנים באינטגרציה ובפרט בעולמות אבטחת המידע (ארכיטקטורה, תשתיות, אפליקציה).
- ניסיון מוכח עם לפחות חלק ממוצרי היצרנים הבאים: צ'קפוינט, פורטינייט, F5, סיסקו, פאלו אלטו- חובה
יתרון למועמדים העומדים בקריטריונים הבאים:
-יתרון משמעותי לבעלי הסמכות
- ניסיון בתפעול והגנה של שירותים אפליקטיביים
- ידע עדכני באיומים, פגיעויות ופרצות אבטחת מידע במגוון רחב של טכנולוגיות ומערכות.
- הסמכות בתחום אבטחת מידע / מוצרי אבטחת מידע
- ניסיון במתודולוגיות, נהלים וכתיבת מסמכים בתחום אבטחת מידע
- ניסיון בליווי פרויקטים או ניהול משימות מורכבות טכנולוגית.
- ניסיון בתפעול מערכות אבטחת מידע ארגוניות כגון FW,AV,IPS,WAF, SIEM / SOC ומוצרי אבטחה למערך המיילים.
- סיווג בטחוני - יתרון המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8717013
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
Location: Petah Tikva
Job Type: Full Time and Hybrid work
We seek a Senior Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.
The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.
As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.
Key Responsibilities:
Triage and Resolve Bug Bounty Reports:
Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition.
Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed.
Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues.
Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom.
Propose remediations, or design them with engineering, and verify the fix resolves the issue.
Assign and defend severity ratings using the program's severity framework.
Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure.
Own Researcher and Stakeholder Communication:
Act as our primary technical point of contact for bug bounty researchers across the full lifecycle of a report.
Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible.
Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk.
Mentor the Team and Raise Triage Standards:
Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication.
Set and maintain the bar for triage quality and strengthen program practices over time.
Requirements:
8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.
Expertise in:
Common web and application vulnerability classes and exploitation techniques.
Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity.
Coordinated vulnerability disclosure.
Code and development fluency:
Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests.
Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code.
Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC.
Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research.
Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8751365
סגור
שירות זה פתוח ללקוחות VIP בלבד