דרושים » אבטחת מידע וסייבר » Lead / Senior Offensive Security Engineer (Offsec AI Team)

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a passionate Lead or Senior Offensive Security Engineer for our growing Offensive Security Automation team. This hands-on offensive security position requires a cyber security professional whose primary focus is to perform security assessments and vulnerability research using internal AI tools using frontier models, with a focus of designing and developing the AI automation and autonomous harnesses together with the team.
This is a role for someone who can perform offensive security testing at scale, combining deep security expertise with the judgment to direct and improve AI-driven tooling.

Key Responsibilities:

Offensive Security & Vulnerability Research (primary)

Perform security assessments and vulnerability research across web applications, APIs, and cloud/hybrid infrastructure, using internal AI tools and frontier models to scale coverage and depth that you will develop.

Make sure our internal solution can perform exploitation, vulnerability chaining, business logic and authorization abuse, privilege escalation, and lateral movement, beyond what automated tooling alone can find.

Run end-to-end engagements: scoping, execution, reporting, and remediation guidance.

Discover systemic/architectural weaknesses, not just isolated bugs, and drive secure-by-default fixes.

Partner with engineering, security architecture, and detection & response teams to close root causes and validate control effectiveness.

Produce high-quality technical reports with clear exploitation paths and prioritized remediation.


AI Automation & Autonomous Harness Design (secondary)

Develop the automation and autonomous harnesses that direct frontier models to perform offensive security testing continuously and at scale.

Design agent-based workflows that reason over large data, plan for risk signals, business logic and execute multi-step offensive testing that will adapt based on results, recon, hypothesis ranking, chaining of bugs exploitation, AI-Driven assessments, and reporting.

Establish human-in-the-loop checkpoints so automation scales offensive coverage without sacrificing safety or precision.

Translate your own tradecraft into reusable, explainable automation that the team can run and build on.
Requirements:
Required Qualifications:

6+ years (Senior) / 8+ years (Lead) hands-on offensive security experience such as pentesting, red teaming, or app/security research, with proven complex engagement delivery.

Deep, must-have vulnerability knowledge in cloud and web application security: OWASP Top 10+ vulnerability classes, identity/authz attack vectors, and cloud/hybrid attack surfaces.

Hands-on experience using internal AI tools and frontier models to perform or accelerate security testing, not just conceptual familiarity!

Software engineering fundamentals: System design, API integration, working with distributed services and technologies.

Ability to write custom scripts/tooling/payloads and contribute to building automation and autonomous harnesses including prompt engineering.

Excellent written and verbal communication skills.


Preferred Qualifications:

Experience with agentic frameworks, prompt optimization, agent evaluation, or lightweight model fine-tuning.

Published security research, CVEs, or conference talks.

Familiarity with MITRE ATT&CK/ATLAS and offensive AI/ML attack surfaces (prompt injection, agentic privilege abuse).
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798562
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a Security Vulnerability Researcher to be a core driver in how our product empowers security teams. You will be expected to deeply understand customer needs and translate them directly into product features that deliver real value. You'll own key parts of our frontend stack, drive key architectural decisions, and turn complex security data into clear, actionable business insights.



This is a hands-on role for a seasoned offensive researcher who thrives on technical depth and creativity. Youll collaborate closely with product, marketing, and engineering teams to deliver research that drives customer trust, informs product direction, and shapes industry thought leadership.

What Youll Do

Perform AI-Focused Vulnerability Research: Investigate security risks in AI models, APIs, and infrastructure to uncover exploitable weaknesses and publish insights that strengthen our market leadership.
Lead Red Teaming Against AI Systems: Simulate adversarial attacks on AI pipelines and APIs, creating impactful PoCs that showcase real-world risk and defensive strategies.
Build Customer-Facing Proof-of-Concepts: Partner with product and engineering teams to design and deliver PoCs that align with customer use cases and highlight security capabilities.
Requirements:
5+ years in Security Research or Offensive Engineering with a proven track record in penetration testing or vulnerability discovery on complex targets.
Deep expertise in Application & AI Security, including experience exploiting APIs, web applications, and AI/ML vulnerabilities such as prompt injection, adversarial manipulation, or model abuse.
Offensive Security & Red Teaming Experience, with practical use of tools, custom exploits, or adversarial testing methods.
Proficiency in developing and presenting PoCs that clearly demonstrate security risks to both technical and non-technical audiences.
Recognized achievements in Bug Bounty or Military-Grade Security Research, or equivalent real-world offensive security experience.
Solid software engineering background, with the ability to read, write, and debug code (Python, JavaScript, Go, etc.).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8761851
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
4 ימים
Location: Tel Aviv-Yafo
Job Type: Full Time
our company builds the real-time 3D platform that powers games and interactive experiences, along with tools used across ads, automotive, aerospace, architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top of it, safe for millions of creators and their users.
We are seeking a Senior Application Security Engineer with profound expertise in application security. In this role, you will execute fundamental AppSec tasks, including threat modeling, secure design reviews, code evaluation, and vulnerability management, leveraging both manual methods and advanced AI tooling. You will also help secure the AI systems our company itself is building, including agentic tools and AI-assisted development workflows.
You will work directly with engineering teams across the US and EMEA.
What you will do
Lead threat modeling, secure design reviews, and penetration testing for our company products and services, from the engine and editor to cloud services, APIs, and internal platforms.
Perform deep code review and manual testing on high-risk systems, using AI-assisted review processes and covering areas automated tooling cannot fully reach.
Build and operate security automation. Use and extend AI-assisted tooling for continuous code review, finding triage, and automated penetration testing, and step in where human judgment is required.
Secure our company's AI and agentic systems. Assess AI-native products, LLM integrations, and agent workflows for the risks specific to them.
Partner with engineering teams to drive remediation, turning recurring findings into guardrails, secure defaults, and paved paths.
Investigate and respond to application security incidents, including root cause analysis and durable corrective action.
Contribute to our company's secure development lifecycle and to compliance work.
Requirements:
5+ years in application security, with a track record on complex, large-scale systems.
Strong command of secure coding and common vulnerability classes (OWASP Top 10 and beyond)
Hands-on secure development experience across several languages.
Practical penetration testing, security assessment, and vulnerability management experience with standard tooling (SAST, DAST, SCA, and manual techniques).
Experience with Cloud security (GCP, AWS, or Azure).
Working knowledge of authentication, authorization, cryptography, and secure architecture patterns.
Clear technical communication for both engineers and non-technical partners across regions.
Preferred Qualifications
Experience in the technology, gaming industry or Ad tech.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796309
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
4 ימים
Location: Tel Aviv-Yafo
Job Type: Full Time
our company's attack surface spans several distinct businesses: the engine and editor developers build on, a wide portfolio of cloud products and services, a large monetization business, and a growing set of AI-assisted creation tools. Code built with our company runs everywhere from a developer's workstation to billions of end-user devices, so targets range from native binaries to distributed cloud systems to AI pipelines, and findings here matter.
This role brings an attacker's mindset to that landscape: penetration testing and red team engagements built on complex attack chains. You would combine manual techniques with automation and tooling you develop as part of your craft, extending your reach across the company ecosystem.
What you'll be doing
Plan and execute objective-based penetration tests and red team engagements across our company's products, cloud services, and infrastructure
Find and validate exploitable vulnerabilities, chain them into realistic attack paths, and demonstrate impact with reproducible proofs of concept
Develop the automation and tooling that extend the team's offensive reach across the company ecosystem
Run joint exercises with the SOC and detection engineering teams to validate telemetry and improve detections
Deliver clear findings to engineering teams and surface recurring risk patterns to security leadership.
Requirements:
5+ years of hands-on experience in offensive security, penetration testing, or red teaming
Proven ability to find, exploit, and chain vulnerabilities across applications
Deep understanding of how modern web applications and APIs break
Hands-on experience assessing cloud environments (AWS or GCP)
Strong ability to develop and validate offensive tooling
You might also have
Adversary emulation experience: designing engagements around real threat actor TTPs
Security research in real-time 3D, game engines or SDKs, or mobile runtimes
Experience attacking CI/CD and build systems.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796320
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Lead Detection Engineer .This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline.

Youre welcome to work in our offices in Tel Aviv, Israel

Your responsibilities will include:

Detection coverage strategy across endpoint, identity, cloud, and infrastructure - how it's measured, prioritized, and continuously improved.
Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic.
Architecture connecting detections to enrichment, triage, and automated response workflows.
Technical standards for how detections are designed, tested, documented, deployed, and retired.
Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops.
Design and build high-fidelity behavioral detections across SIEM and EDR platforms.
Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.
Validate detections through threat simulations and continuous detection testing.
Partner with SOC analysts to close the feedback loop between detections and real investigations.
Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership.
Make architectural decisions that scale as the team and organization grow.
Requirements:
We expect you to have:

Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role - with demonstrated depth, not just breadth.
Experience owning or leading detection engineering work as a senior technical contributor
Strong understanding of attacker tradecraft and adversary behavior.
Hands-on experience with at least one enterprise SIEM and EDR platform - Splunk, Microsoft Sentinel, CrowdStrike, or equivalent.
Cloud security depth across Azure, AWS, or GCP.
Strong query development skills in SPL, KQL, Sigma, or similar.
Strong scripting skills (python, powershell etc)
Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows.
Experience using MITRE ATT&CK to design, validate, and measure detection coverage  
Ability to make and defend technical decisions and establish standards others adopt.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8761440
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
5 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Information Security Engineer
The world of digital assets is accelerating in speed, scale, and complexity, opening new ways to leverage blockchain. Our platform and network provide the simplest and most secure way for companies to work with digital assets, and it is trusted by some of the largest financial institutions, banks, globally-recognized brands, and Web3 companies in the world, including BNY Mellon, BNP Paribas, ANZ Bank, Revolut, and thousands more.
Security isnt an afterthought; its the foundation of everything we do.
Making Security Real:
As a Senior Information Security Engineer, youll be on the front lines of protecting the systems, users, and data at scale. This role is about turning strategy, architecture, and intent into enforced controls, effective detections, and resilient operations. Youll work hands-on with the tools, signals, and incidents that define our real security posture.
If you believe security should be practical, measurable, and embedded into daily operations-and not just documented-we want you on the team.
What the Role Looks Like in Practice:
You will be the technical anchor of our internal security posture:
Architectural Ownership: Deploy, manage, and tune enterprise-grade security stacks (EDR, DLP, IAM, CASB, MDM) with a focus on deep integration and automation.
The AI Frontier: Lead the charge on AI Security. You will implement and secure AI-driven workflows, ensuring LLM use is governed and protected against emerging threats such as data leakage and prompt injection.
Proactive Defense: Build and maintain high-fidelity detections and guardrails that align with real-world attack techniques.
Cross-Functional Synergy: Partner as a peer with Engineering, IT, and DevOps to ensure security controls are frictionless, automated, and effective.
Requirements:
What Youll Bring
Technical Must-Haves:
4+ Years of Experience: Extensive hands-on experience in InfoSec Engineering or SecOps within high-growth, cloud-native environments.
AI Security Mastery (Required): You are ahead of the curve. You have practical experience securing AI adoption and leveraging AI-driven platforms to scale defensive capabilities.
Deep Technical Stack: Expert-level knowledge of endpoint security (macOS/Linux), SaaS ecosystems, and Identity (Okta/OIDC).
The Developer Mindset: Advanced scripting skills (Python is a must) to automate away manual toil and build custom security integrations.
Professional & Interpersonal Excellence:
Strategic Communication: The ability to articulate complex technical risks as actionable business intelligence for diverse stakeholders, ensuring alignment between security objectives and business goals.
Collaborative Influence: A track record of fostering strong partnerships with R&D and DevOps. You are a facilitator of Secure-by-Design principles, focused on engineering solutions rather than creating administrative bottlenecks.
Crisis Management & Decisiveness: The capacity to maintain operational composure during high-stakes incidents, applying rigorous prioritization and risk-based analysis to drive remediation.
Pragmatic Professionalism: A disciplined approach to balancing theoretical security ideals with the functional requirements of a high-velocity, global financial infrastructure.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8794668
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Platform Security Director to lead the engineering of our security infrastructure. Your mission is to build a Security Machine that is as sophisticated as our AI. You will move us beyond traditional "defense" into a "Secure-by-Default" reality, where our multi-cloud infrastructure (AWS and Azure) is hardened, automated, and resilient by design.
Youll Own:
The end-to-end security strategy across Application Security, Cloud (AWS/Azure), and Platform layers, ensuring a Secure-by-Default framework, as measured by deployment coverage, critical vulnerability reduction, and developer adoption metrics.
A unified Security Engineering organization covering AppSec, SecDevOps, and AI Security leadership, collaboration points with adjacent teams (Infrastructure, R&D, Product Engineering), and building and mentoring a high-performing team.
Lead our Platform Security domain - from Layer 7 protections to AWS architecture, security tooling, automated risk scoring, and AI-assisted automation workflows that improve detection and remediation times.
Security controls (WAF, Rate Limiting) embedded into the SDLC and CI/CD pipelines, including mandatory security gates, artifact scanning, and automated deployment checks.
Lead our AI strategy - enabling secure use in our platform products as well as for our internal engineering usage, and scaling AI security governance and controls.
The evolution of scalable infrastructure security, including Kubernetes, containers, IAM, and Zero Trust architectures, strengthening Kubernetes and cloud security posture.
Own and execute the comprehensive Vulnerability Management program, from discovery (SAST/DAST/OSS scanning) through remediation tracking, and manage the external Bug Bounty program, with a focus on improving remediation SLAs and automation coverage.
Mature secure-by-default engineering practices across the SDLC.
Increase developer adoption of automated security tooling.
Youll Solve:
Eliminating manual bottlenecks through code-driven guardrails and frictionless developer experiences.
Securing complex production systems and multi-tenant AI architectures in cloud-native production environments, with a focus on model integrity, training data provenance, data exfiltration prevention, and minimizing unique risks associated with Large Language Models (LLMs), by applying specific AI threat models.
Operationalizing Red/Purple Team exercises, penetration testing, and the Bug Bounty program to ensure a continuous feedback loop that drives proactive risk reduction.
Youll Impact:
Support a culture where security is embedded into the foundation of engineering
Turn security into a strategic product advantage and customer trust differentiator
Improve developer experience by making the secure path the easiest path
Increase engineering velocity while strengthening platform resilience
Shape the future intersection of Security, AI, and Platform Engineering
Create scalable systems, processes, and relationships that grow with the companys innovation pace.
Requirements:
An Experienced Leader: 10+ years in Security/Software Engineering with a track record of scaling departments in high-growth R&D environments.
A Technical Architect: Deep expertise in AWS/Kubernetes and modern platform security practices, Infrastructure-as-Code (Terraform/Crossplane), and secure coding (Java/Python/TypeScript).
A Systems Thinker: You have a proven track of building security machines from the ground up, with a people-first mindset, technology, and process.
Your work ensures that as our company defines the future of AI-driven revenue, we do so on the most secure and resilient platform in the industry, building customer trust and promoting responsible AI adoption.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8788377
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Senior Security Engineer.
Senior Security Engineer to act as a hands-on technical leader inside our security org, part builder, part architect, part trusted partner to R&D. You'll sit in design reviews, push back (constructively) on architecture choices, prototype the controls we're missing, and help R&D ship faster and safer.
This role suits an engineer who thinks in systems, codes when needed, and is energized by securing modern AI-driven, multi-cloud environments.
What you'll do:
Act as a security architect for new initiatives. Join design and solution-concept meetings with R&D before code is written and help shape architectures that are secure by default. Produce threat models, reference designs, and decision docs that engineers actually use.
Partner with R&D as a peer, not a gatekeeper. Embed with product and engineering teams. Translate security requirements into engineering language, and engineering trade-offs into risk language for leadership.
Own security across our multi-cloud footprint (AWS, GCP, Azure). Design and implement controls for identity, network, workload, and data protection that work consistently across environments.
Drive AI security. Build our defenses against threats specific to LLM and ML systems: prompt injection, model abuse, training-data integrity, agentic-workflow risks, MCP/tool-use exposure, secrets in prompts, and supply-chain risk in the AI stack. Help define what "secure AI development" means for us in practice.
Lead data security initiatives. Classification, encryption, key management, DLP, access governance, and data-flow mapping.
Evaluate and implement new technologies. Run POCs and deploy new tooling end-to-end. We expect you to have strong opinions on the security stack and to evolve it as the threat landscape shifts.
Write code. Automate controls, build internal tools, contribute to detection pipelines, and integrate security into CI/CD.
Requirements:
5+ years in security engineering, application security, or cloud security, with meaningful time in a hands-on technical capacity
Strong software development background - you've shipped production code and read others' code fluently.
Deep experience securing multi-cloud environments, including IAM, networking, workload security, and infrastructure-as-code
Architect-level thinking: ability to look at a system diagram and identify trust boundaries, blast radius, failure modes, and the controls that actually matter
Hands-on experience with data security at scale, classification, encryption, key management, access controls
Demonstrated experience introducing and operationalizing new security technologies, not just maintaining existing ones
Track record of working closely with engineering teams; you're comfortable in design reviews and code reviews
Direct experience with AI/ML security, securing LLM applications, agentic systems,model deployments, or AI infrastructure
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8757871
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a Senior Security Researcher for the Exposures team, you will conduct research into vulnerability detection, remediation, and prioritization to enhance our asset intelligence platform. You will lead end-to-end research projects, collaborating directly with Product and Development teams to convert technical research into product features. You will analyze large-scale security data, automate workflows, and prototype logic to address enterprise attack surfaces. This is a high-impact role where your research directly shapes how our customers identify and mitigate their most critical security gaps.

Responsibilities
Lead end-to-end security research projects focusing on vulnerability detection, risk prioritization, and exposure management logic.
Utilize Python, SQL, and AI/LLM tools to build data analysis pipelines, automate threat research, and prototype research tools.
Research and define remediation strategies, compensating controls, and configuration-based mitigations beyond standard patching.
Partner weekly with Product and Engineering teams to transform technical research into production-ready product capabilities.
Requirements:
4+ years of professional experience in security research, vulnerability analysis, or penetration testing.
Demonstrated proficiency with Python for scripting/automation and SQL for querying complex security data sets.
Hands-on experience integrating AI/LLMs into technical workflows to accelerate data analysis, parsing, or research output.
Practical understanding of security frameworks and metrics including CVSS, EPSS, and MITRE ATT&CK.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8781437
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a Product Security Architect , you will be responsible for designing, shaping, and evolving the security architecture of the Enterprise Browser. This role combines deep technical expertise with strategic thinking, focusing on proactively reducing risk through secure design, architectural reviews, and close collaboration with engineering and product teams. You will play a key role in defining security standards, guiding threat modeling efforts, and ensuring security is built into the product from its earliest design stages throughout its production lifecycle and evolutions.

Key Responsibilities:

Security Architecture & Design: Define and own product security architecture across browser components, OS integrations, and enterprise-facing features, ensuring security-by-design principles are consistently applied.
Threat Modeling & Risk Assessment: Lead threat modeling efforts for new features and architectural changes, identifying attack surfaces, trust boundaries, and mitigation strategies in collaboration with engineers and product leaders.
Security Reviews & Guidance: Perform architecture and design reviews, providing actionable security recommendations and guiding teams on secure implementation patterns.
Vulnerability & Attack Surface Analysis: Proactively assess systemic risks, design flaws, and high-impact vulnerability classes relevant to browsers and enterprise platforms.
Security Standards & Enablement: Develop and maintain security guidelines, patterns, and reference architectures; support teams in adopting secure coding and design practices.
Cross-Functional Collaboration: Partner closely with engineering, product, and product security leadership to balance security, usability, and performance tradeoffs.
Security Strategy & Innovation: Track emerging threats, exploitation techniques, and industry trends to continuously improve long-term security posture.
Requirements:
Strong background in security architecture, secure systems design, or product security engineering.
Deep understanding of browser security models, OS security primitives, or application-level security.
Experience conducting threat modeling, design reviews, and architectural risk assessments.
Proficiency in one or more programming languages (e.g., Python, JavaScript, C/C++, Go) with the ability to reason about implementation-level risk.
Solid knowledge of common vulnerability classes and systemic security failures (e.g., sandbox escapes, RCE, privilege escalation).
Ability to translate complex security concepts into clear guidance for engineering teams.
Security research or vulnerability research experience is a strong advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769489
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Security Operations & Automation
About Your Day-to-Day:
As a Security Operations & Automation, you'll be the hands-on architect of how we detect, investigates, and responds to threats - built around AI agents and deep tooling integrations, not manual triage. You'll own incident response across corporate systems, workstations, and identity, unify alerts from every source - including cloud-originated signals that need a response - into a single SOAR/XDR fabric, and deploy AI agents to handle first-line investigation and response.
You'll work closely with IT and the Cloud Security team - taking the lead on investigation, triage, and response while they own the underlying cloud and SDLC architecture - and turn complex security signals into structured, AI-assisted, largely autonomous outcomes - fighting fire with fire.
Responsibilities:
Architect and own our AI-driven detection and response stack, integrating SIEM, XDR, SOAR, EDR, and IAM into a single automated fabric rather than siloed tools.
Deploy and tune AI agents to handle first-line alert triage, enrichment, and investigation, with humans engaged only for true edge cases - manual L1 triage is the exception, not the default.
Build SOAR playbooks and integrations across the security and IT toolchain (endpoint, identity, ticketing, chat) so detection, enrichment, and remediation run automatically end to end - regardless of which system or platform an alert originates from.
Own the alert pipeline as a whole: unify signals from EDR, IAM, and other sources - including cloud and SaaS alerts surfaced by the Cloud Security team - into one triage and response workflow, so nothing falls through the cracks between tools.
Evaluate and integrate best-of-breed, AI-native security tools - SIEM, XDR, SOAR, EDR, email security, AI guardrails, ZTNA, and others - wiring each into the unified detection and response fabric rather than running them as siloed point solutions. Hands-on tool integration (APIs, connectors, log and telemetry ingestion) is a core skill for this role, not an occasional task.
Drive vulnerability and patch management across corporate systems and endpoints, automating prioritization and remediation workflows and coordinating with IT against strict SLAs.
Build and tune detection rules specific to our environment, treating detection as code and feeding AI-driven correlation across the XDR layer.
Maintain security dashboards (MTTD/MTTR, automation rate, % of alerts resolved without human touch) and report on how automation is cutting noise and response time.
דרישות:
5+ years of experience in security operations, SecOps, or security engineering roles.
Hands-on experience operating EDR/XDR. SOAR/XSOAR, SIEM platforms and cloud security services (IAM, CSPM, SSPM).
Experience building automations and playbooks using SOAR platforms or scripting (Python, Bash).
Strong incident response skills, including triaging alerts and conducting root cause analysis.
Hybrid position based in our Tel Aviv office.
Excellent written and verbal English skills
Personal Attributes & Mindset:
High ownership mentality: You take responsibility for the security stack and follow through on every alert.
Strong sense of structure: You can manage vulnerability SLAs and maintain precise security policies.
Comfortable with ambiguity: You can take a vague threat and turn it into a clear detection rule or automated playbook.
Collaborative by nature: You enjoy working as a partner to R&D to solve security challenges without slowing down development.
Curious and self-driven: You are motivated to stay ahead of emerging threats and continuously improve Port's defenses.
Nice to Have:
Relevant certifications: CompTIA Security+, GSEC, CySA+, or AWS Security Specialty.
Deep understanding of the SDLC and experience embedding security tools (SAST, SCA) into CI/CD pipelines.
Experience with CNAPP/CSPM or code security platforms.
Familiarity with compliance frameworks (SOC 2, ISO המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8775548
סגור
שירות זה פתוח ללקוחות VIP בלבד