רובוט
היי א אי
stars

תגידו שלום לתפקיד הבא שלכם

לראשונה בישראל:
המלצות מבוססות AI שישפרו
את הסיכוי שלך למצוא עבודה

Senior Security Specialist

מסמך
מילות מפתח בקורות חיים
סימן שאלה
שאלות הכנה לראיון עבודה
עדכון משתמש
מבחני קבלה לתפקיד
שרת
שכר
משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP

חברות מובילות
כל החברות
כל המידע למציאת עבודה
להשיב נכון: "ספר לי על עצמך"
שימו בכיס וצאו לראיון: התשובה המושלמת לשאלה שמצ...
קרא עוד >
לימודים
עומדים לרשותכם
מיין לפי: מיין לפי:
הכי חדש
הכי מתאים
הכי קרוב
טוען
סגור
לפי איזה ישוב תרצה שנמיין את התוצאות?
Geo Location Icon

משרות בלוח החם
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
לפני 19 שעות
דרושים בTOP SOFT טופ סופט - השמה ומיקור חוץ
מיקום המשרה: תל אביב יפו
לחטיבת הסייבר דרוש/ה חוקר/ת מודיעין איומי סייבר לתפקיד מחקרי וטכנולוגי העוסק בזיהוי, חקירה וניתוח של תקיפות סייבר מתקדמות בסביבות ענן.

מה כולל התפקיד?

ביצוע מחקרים טכנולוגיים על תקיפות סייבר מתקדמות בסביבות Cloud.
חקירת שרשרת התקיפה וזיהוי Indicators / IOCs ומאפייני תקיפה.
גיבוש תפיסות ומתודולוגיות לחקירה בסביבות ענן.
זיהוי, איתור וניתוח איומים לצורך יצירת התרעות מוקדמות.
העשרת צוותי חקירות במידע מודיעיני וטכנולוגי.
ביצוע מחקרי עומק וכתיבת דוחות מודיעיניים וטכנולוגיים.
הפקת תובנות אופרטיביות לצורך שיפור יכולות הגילוי וההתמודדות עם תקיפות ענן.

תפקיד למי שרוצה להיות בחזית המחקר והמודיעין בעולם הCloud Security.
דרישות:
ניסיון של 4 שנים ומעלה בתחום Cyber / Threat Intelligence / Cyber Research.
ניסיון מוכח בחקירת תקיפות סייבר וניתוח שרשראות תקיפה.
ניסיון בסביבות Cloud - AWS / Azure / GCP.
ידע והבנה מעמיקה של Cloud Security ותשתיות ענן.
ניסיון באיתור וניתוח IOCs, TTPs וממצאים מודיעיניים.
היכרות עם MITRE ATT CK ומתודולוגיות Threat Intelligence - יתרון.
ניסיון בכלי חקירה, ניטור וניתוח בסביבות ענן - יתרון.
יכולות מחקר, אנליזה והסקת מסקנות ברמה גבוהה.
יכולת כתיבה והצגת מחקרים ודוחות טכנולוגיים.
יכולת עבודה עצמאית לצד עבודה מול צוותי Cyber וחקירות.

יתרון משמעותי:
ניסיון בחקירת תקיפות מתקדמות, APT, Cloud Attacks, Incident Response או Digital Forensics. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8781641
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 23 שעות
דרושים בNishapro
מיקום המשרה: רמת גן ופתח תקווה
לארגון פיננסי גדול ומוביל דרוש/ה סוקר אבטחת מידע לביצוע, סקרי סיכונים.
ביצוע סקרי סיכונים למערכות החברה
זיהוי חולשות במערכות קיימות ומערכות בתהליכי הטמעה.
סקירה של הקשחות אל מול סטנדרטים מקובלים
בדיקות רגולטוריות בהתאם לרגולציות בארגונים פיננסים
הערכת האפקטיביות של הבקרות המפצות.
מתן המלצות למידור החולשות
עבודה מול הצוותים המקצועיים במטרה לוודא מיגור החולשות.
עבודה בצוות מקצועי במתכונת של purple team
דרישות:
ידע וניסיון קודם בביצוע סקרי אבטחת מידע: ביצוע סקרים שונים(security assessments) לרמות תשתית ואפליקציה, כולל זיהוי, דיווח ופתרון בעיות אבטחה.
כולל הכנת דוחות והמלצות לאחר סיום הסקרים. (ONPREMIS/AZURE/AWS/ Linux )
ניסיון בביצוע מבדקי חדירה(penetration testing): ניסיון מעשי בביצוע מבדקי חדירה ברמות תשתית ואפליקציה פלטפורמות, שרתים, אפליקציות ו-mobile (ONPREMIS/AZURE/AWS/ Linux ) כולל הכנת דוחות והמלצות לאחר סיום הסקרים.
הבנה טכנית גבוהה: ידע מעמיק בטכנולוגיות אבטחת מידע, סקרי פגיעויות, פרוטוקולים, טכניקות חדירה וכלי עבודה בתחום ה penetration testing.
ראייה מערכתית: יכולת עבודה עם מגוון רחב של מערכות טכנולוגיות ויכולת להבין את השפעת אבטחת המידע בהיבטים רחבים של מערכות ארגוניות.
הכרות עם סטנדרטים בתחום אבטחת המידע: ידע והבנה מעמיקה של דרישות אבטחת המידע והרגולציות בתחום הפיננסי, כולל יכולת התאמה לרגולציות מחמירות כמו:ISO 2700 NIST, PCI-DSS, GDPR.
הסמכות רלוונטיות: הסמכות מוכרות בתחום אבטחת המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8746839
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
דרושים בOne DatAI
מיקום המשרה: לוד ותל אביב יפו
לארגון פיננסי גדול ומוביל דרוש/ה מפתח/ת Splunk לצוות SIEM

התפקיד כולל קליטה וחיבור של לוגים, יצירת תוכן, בניית Dashboards, פיתוח בReact, כתיבת חוקים, טיפול בהתראות קיימות וטיוב תהליכי ניטור.

התפקיד דורש יכולת טכנית גבוהה, חשיבה יצירתית, יכולת עבודה עצמאית וניסיון מעשי בעבודה עם Splunk.

תחומי אחריות
ביצוע פיתוחים על גבי תשתית Splunk
כתיבת Dashboards מתקדמים
כתיבת חוקים והתראות
טיפול, תחזוקה וטיוב של חוקים, Alerts ודשבורדים קיימים
קליטה, עיבוד ונרמול נתונים ממקורות שונים
עבודה מול צוותי אבטחת מידע, סייבר ותשתיות
דרישות:
ניסיון של לפחות 3 שנים בעבודה עם Splunk Enterprise / Splunk Cloud
ניסיון מעשי בכתיבת SPL מורכב, כולל: joins, stats, tstats, transactions, lookups
ניסיון בפיתוח ותחזוקה של Dashboards מתקדמים
ניסיון בפיתוח ותחזוקה של Alerts, Reports וSaved Searches
ניסיון בהטמעת data Inputs כגון REST APIs, Syslog וHEC
היכרות עם Indexes, Sourcetypes, props.conf, transforms.conf
ניסיון בPerformance Tuning וSearch Optimization

ניסיון של 2-3 שנים לפחות בפיתוח בPython, ניסיון בכתיבת Splunk Modular Inputs
ניסיון בכתיבת סקריפטים לאוטומציה ואינטגרציות
עבודה עם REST APIs, כולל requests, authentication וpagination
עבודה עם JSON, XML, Parsing וData Normalization
יתרון לניסיון עם Splunk Add-on Builder
פיתוח frontend - React - ניסיון בפיתוח React, כולל Hooks, Components וState Management
עבודה עם REST APIs וAsync Calls
ניסיון בבניית UI למערכות פנימיות / כלי תפעול
היכרות עם JavaScrip המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8649037
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
1 ימים
דרושים בלוגיקה IT
?Ready to Power Up Your Career

Cloud Security Engineer

תל אביב | משרה מלאה | היברידי

בואו להיות חלק מהעשייה הטכנולוגית שמשפיעה על הבריאות בישראל!
בחטיבת הטכנולוגיות אנחנו משלבים בין חדשנות טכנולוגית לשליחות אמיתית, כדי להמשיך ולפתח מערכת בריאות טובה ומתקדמת יותר עבור מיליוני חברי הארגון.
אצלנו תמצאו סביבת עבודה דינמית וחדשנית הכוללת שימוש בטכנולוגיות מובילות כמו ענן, בינה מלאכותית (AI) ופתרונות דיגיטליים חוצי-ארגון.
אנחנו מאמינים בשותפות ובפיתוח אישי ומקצועי, בסביבת עבודה נעימה שמורכבת מעובדים שמגיעים כל בוקר מתוך רצון להשפיע ולעשות טוב.

על המשרה:

אחריות לזמינות, אמינות וביצועים של מערכות אבטחה בענן
ניהול שוטף של מעטפת האבטחה במספר Landing Zones בענן ציבורי
ניהול שינויים דרך תהליכי CI/CD מאובטחים IaC ושימוש ב Terraform
בעלות מקצועית על מערכות אבטחה בקטגוריות  CNAPP, SAST, SCA
שותפ/ה בתכנון Landing Zones חדשים ובפרויקטים אסטרטגיים של עליה לענן
דרישות:
תואר במדעי המחשב/ הנדסת מחשבים / מערכות מידע /יוצא יחידות צבאיות/קורסים מתקדמים בתחום חובה
ניסיון של לפחות 7 שנים ביישומי באבטחת מידע, מתוכן לפחות 3 שנים בענן ציבורי (Azure יתרון משמעותי)
היכרות ועבודה עם ארכיטקטורות ענן בארגוני Enterprise
ניסיון בעבודה עם רכיבי אבטחה בענן כגון: Firewall, API GW, WAF, Azure Policy, APM
רקע משמעותי ב כתיבת תשתיות באמצעות IaC (Terraform או שווה ערך)
ניסיון באבטחת Kubernetes (AKS / OpenShift) הכולל Network Policies, RBAC, Secrets Management, Image Scanning, Admission Control
ניסיון רב-עננים (Multi-Cloud) AWS / GCP בנוסף ל-Azure- יתרון משמעותי
ניסיון בעבודה במודל CCoE / Platform Team / Enterprise Architecture- יתרון משמעותי


הבנה טכנולוגית גבוהה ויחסי אנוש מעולים
ראייה מערכתית רחבה ויכולת חשיבה ארכיטקטונית
יכולת עבודה עצמאית, עבודת צוות ויכולת לימוד עצמי מהיר
שליטה מלאה בעברית ואנגלית ויכולת ניסוח טובה בעל-פה ובכתב המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8743927
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לארגון פיננסי מוביל דרוש/ה רכז/ת GRC להשתלבות בצוות אבטחת המידע.
התפקיד כולל השתלבות בפעילות Governance, Risk Compliance, ניהול סיכוני סייבר וסיכוני ספקים,
ביצוע סקרי סיכונים ובקרות אבטחת מידע, ליווי תהליכי ציות לרגולציות ותקנים,
עבודה מול ספקים, צוותי פיתוח, תשתיות וגורמים עסקיים, תיעוד ומעקב אחר ממצאים ותוכניות טיפול,
כתיבה ועדכון של מדיניות ונהלי אבטחת מידע, הכנת דוחות ומצגות להנהלה, עבודה עם מערכות GRC והשתתפות בהיערכות לביקורות פנימיות וחיצוניות.
דרישות:
לפחות שנתיים ניסיון בתחום GRC, אבטחת מידע או ניהול סיכוני סייבר.
ניסיון בביצוע סקרי סיכונים, בקרות אבטחת מידע וניהול סיכוני ספקים.
ניסיון בעבודה מול ממשקים מרובים, ספקים וגורמים עסקיים.
תואר ראשון במערכות מידע, מדעי המחשב, הנדסת תעשייה וניהול, ניהול טכנולוגיה, משפטים או תחום רלוונטי.
היכרות עם תקנים ורגולציות כגון ISO 27001, תקנות הגנת הפרטיות, SOX או NIST - יתרון. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8765181
סגור
שירות זה פתוח ללקוחות VIP בלבד
לוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/07/2026
Location: Petah Tikva
Job Type: Full Time and Hybrid work
We seek an experienced offensive security leader to build and lead the Product Red Team. This newly established function emulates real-world attacks against synthetic customer instances to identify vulnerabilities, misconfigurations, and design gaps before external threat actors or researchers discover them.
This role requires an operator who has led offensive security operations in high-consequence environments-covert intelligence or military settings preferred-with proven ability to establish operational standards, navigate ambiguous mission parameters, and influence cross-functional stakeholders around complex security trade-offs.
You will build upon this team's charter, engagement frameworks, and rules of engagement with other teams. You will help drive our product security and response posture through adversary emulation, vulnerability research, exploit development, and collaboration with other offensive and defensive teams.
Key Responsibilities:
Establish Operations Objectives, Policies & Procedures:
Own Product Red Team's operation objectives and engagement selection criteria in alignment with product security roadmap and risk register, CISO directives, and company priorities.
Expand upon rules of engagement, threat actor emulation standards, testing policies, and protocols.
Establish operational security procedures for covert operations, detection evasion, and incident response protocols.
Create escalation procedures and approval frameworks for high-risk engagements.
Own campaign selection processes, engagement proposal templates, and findings documentation and readout standards.
Define Engagement Framework & Success Metrics:
Design and implement engagement types: vulnerability risk assessment, product security assessments, and ongoing adversarial campaigns.
Establish and report on technical and operational success metrics: kill chain coverage, remediation velocity, and detection engineering insights.
Create reporting templates-technical findings, executive briefings, engineering recommendations-that drive actionable remediation.
Define boundaries and operational testing windows in coordination with product engineering and detection engineering teams.
Lead Offensive Operations Team:
Build team capability across threat actor emulation, exploit development, persistence mechanisms, supply chain security, and AI-specific attack vectors (prompt injection, model manipulation, data poisoning).
Mentor team on operational security tradecraft, documentation discipline, and risk management under ambiguous conditions.
Support team members in their time zones, spanning from US West Coast to India.
Requirements:
12+ years of offensive security experience, with minimum 5+ years leading offensive operations teams in mission-critical environments.
Background in leading covert offensive cyber operations in:
Intelligence communities, or
Contracted equivalent, or
Top-tier private-sector adversary emulation firms or internal teams.
Expertise in:
Threat actor emulation and MITRE ATT&CK methodologies as translated and applied to product security.
Exploit development and proof-of-concept creation.
Persistence mechanisms, detection evasion, and command & control operations in SaaS environments.
Kill chain analysis and attack path development.
Security control validation and testing under strict rules of engagement.
Proven ability to:
Operate under ambiguous mission parameters and establish doctrine.
Establish and enforce operational security discipline in high-stakes environments.
Navigate regulatory and legal constraints while maintaining operational effectiveness.
Mentor elite operators and maintain team excellence under pressure.
Brief executives on complex security risks and influence decision-making.
Product security awareness: Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and multi-tenant architecture considerations.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8751380
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/07/2026
Location: Petah Tikva
Job Type: Full Time and Hybrid work
We seek a Senior Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.
The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.
As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.
Key Responsibilities:
Triage and Resolve Bug Bounty Reports:
Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition.
Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed.
Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues.
Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom.
Propose remediations, or design them with engineering, and verify the fix resolves the issue.
Assign and defend severity ratings using the program's severity framework.
Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure.
Own Researcher and Stakeholder Communication:
Act as our primary technical point of contact for bug bounty researchers across the full lifecycle of a report.
Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible.
Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk.
Mentor the Team and Raise Triage Standards:
Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication.
Set and maintain the bar for triage quality and strengthen program practices over time.
Requirements:
8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.
Expertise in:
Common web and application vulnerability classes and exploitation techniques.
Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity.
Coordinated vulnerability disclosure.
Code and development fluency:
Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests.
Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code.
Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC.
Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research.
Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8751365
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות שנמחקו