רובוט
היי א אי
stars

תגידו שלום לתפקיד הבא שלכם

לראשונה בישראל:
המלצות מבוססות AI שישפרו
את הסיכוי שלך למצוא עבודה

Senior Security Specialist

מסמך
מילות מפתח בקורות חיים
סימן שאלה
שאלות הכנה לראיון עבודה
עדכון משתמש
מבחני קבלה לתפקיד
שרת
שכר
משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP

חברות מובילות
כל החברות
כל המידע למציאת עבודה
5 טיפים לכתיבת מכתב מקדים מנצח
נכון, לא כל המגייסים מקדישים זמן לקריאת מכתב מק...
קרא עוד >
לימודים
עומדים לרשותכם
מיין לפי: מיין לפי:
הכי חדש
הכי מתאים
הכי קרוב
טוען
סגור
לפי איזה ישוב תרצה שנמיין את התוצאות?
Geo Location Icon

משרות בלוח החם
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
דרושים בNishapro
מיקום המשרה: רמת גן ופתח תקווה
לארגון פיננסי גדול ומוביל דרוש/ה סוקר אבטחת מידע לביצוע, סקרי סיכונים.
ביצוע סקרי סיכונים למערכות החברה
זיהוי חולשות במערכות קיימות ומערכות בתהליכי הטמעה.
סקירה של הקשחות אל מול סטנדרטים מקובלים
בדיקות רגולטוריות בהתאם לרגולציות בארגונים פיננסים
הערכת האפקטיביות של הבקרות המפצות.
מתן המלצות למידור החולשות
עבודה מול הצוותים המקצועיים במטרה לוודא מיגור החולשות.
עבודה בצוות מקצועי במתכונת של purple team
דרישות:
ידע וניסיון קודם בביצוע סקרי אבטחת מידע: ביצוע סקרים שונים(security assessments) לרמות תשתית ואפליקציה, כולל זיהוי, דיווח ופתרון בעיות אבטחה.
כולל הכנת דוחות והמלצות לאחר סיום הסקרים. (ONPREMIS/AZURE/AWS/ Linux )
ניסיון בביצוע מבדקי חדירה(penetration testing): ניסיון מעשי בביצוע מבדקי חדירה ברמות תשתית ואפליקציה פלטפורמות, שרתים, אפליקציות ו-mobile (ONPREMIS/AZURE/AWS/ Linux ) כולל הכנת דוחות והמלצות לאחר סיום הסקרים.
הבנה טכנית גבוהה: ידע מעמיק בטכנולוגיות אבטחת מידע, סקרי פגיעויות, פרוטוקולים, טכניקות חדירה וכלי עבודה בתחום ה penetration testing.
ראייה מערכתית: יכולת עבודה עם מגוון רחב של מערכות טכנולוגיות ויכולת להבין את השפעת אבטחת המידע בהיבטים רחבים של מערכות ארגוניות.
הכרות עם סטנדרטים בתחום אבטחת המידע: ידע והבנה מעמיקה של דרישות אבטחת המידע והרגולציות בתחום הפיננסי, כולל יכולת התאמה לרגולציות מחמירות כמו:ISO 2700 NIST, PCI-DSS, GDPR.
הסמכות רלוונטיות: הסמכות מוכרות בתחום אבטחת המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8746839
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בOne DatAI
מיקום המשרה: לוד ותל אביב יפו
לארגון פיננסי גדול ומוביל דרוש/ה מפתח/ת Splunk לצוות SIEM

התפקיד כולל קליטה וחיבור של לוגים, יצירת תוכן, בניית Dashboards, פיתוח בReact, כתיבת חוקים, טיפול בהתראות קיימות וטיוב תהליכי ניטור.

התפקיד דורש יכולת טכנית גבוהה, חשיבה יצירתית, יכולת עבודה עצמאית וניסיון מעשי בעבודה עם Splunk.

תחומי אחריות
ביצוע פיתוחים על גבי תשתית Splunk
כתיבת Dashboards מתקדמים
כתיבת חוקים והתראות
טיפול, תחזוקה וטיוב של חוקים, Alerts ודשבורדים קיימים
קליטה, עיבוד ונרמול נתונים ממקורות שונים
עבודה מול צוותי אבטחת מידע, סייבר ותשתיות
דרישות:
ניסיון של לפחות 3 שנים בעבודה עם Splunk Enterprise / Splunk Cloud
ניסיון מעשי בכתיבת SPL מורכב, כולל: joins, stats, tstats, transactions, lookups
ניסיון בפיתוח ותחזוקה של Dashboards מתקדמים
ניסיון בפיתוח ותחזוקה של Alerts, Reports וSaved Searches
ניסיון בהטמעת data Inputs כגון REST APIs, Syslog וHEC
היכרות עם Indexes, Sourcetypes, props.conf, transforms.conf
ניסיון בPerformance Tuning וSearch Optimization

ניסיון של 2-3 שנים לפחות בפיתוח בPython, ניסיון בכתיבת Splunk Modular Inputs
ניסיון בכתיבת סקריפטים לאוטומציה ואינטגרציות
עבודה עם REST APIs, כולל requests, authentication וpagination
עבודה עם JSON, XML, Parsing וData Normalization
יתרון לניסיון עם Splunk Add-on Builder
פיתוח frontend - React - ניסיון בפיתוח React, כולל Hooks, Components וState Management
עבודה עם REST APIs וAsync Calls
ניסיון בבניית UI למערכות פנימיות / כלי תפעול
היכרות עם JavaScrip המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8649037
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בריקרוטיקס בע"מ
Job Type: Full Time and Hybrid work
CISO Role in a Leading Cybersecurity Company
Our company specializes in cybersecurity consulting and we are currently expanding our team, and looking for a talented CISO to join our top star team.
We offer a dynamic and challenging role in a company that greatly values human capital and work with cutting-edge security technologies and top-tier clients.
What will you do?
Strengthen cybersecurity across cloud & on-prem networks
Implement security frameworks & best practices
Provide expert guidance on advanced security controls
Requirements:
Job Requirements:
At least 2 years of experience in a CISO role.
Certificate of CISO ( Chief Information Security Officer ) or Professional certification in information technology/security.- MUST
Extensive knowledge of cybersecurity best practices for network and cloud infrastructure.
Familiarity with privacy protection regulations and certifications such as ISO 27001 and SOC2.
Hands-on experience with technical security controls (FW, EDR, etc).
Strong organizational skills, team-oriented, and service-focused.
Knowledge of web security and familiarity with the OWASP Top 10 security risks is advantageous.
High proficiency in English.
This position is open to all candidates.
 
Show more...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8761449
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בלוגיקה IT
Ready to Power Up Your Career?

דרוש/ה GRC Security Specialist
תל אביב | משרה מלאה | יומיים בשבוע מהבית

לחברת SaaS מובילה בתל אביב דרוש/ה GRC Security Specialist לתפקיד Hands-On משמעותי בצוות אבטחת המידע.
במסגרת התפקיד תהיה אחריות על ניהול תהליכי GRC מקצה לקצה, כולל הערכת סיכוני ספקים וגורמי צד ג', הובלת ביקורות פנימיות וחיצוניות, תחזוקת הסמכות ועמידה בתקנים, כתיבה ועדכון של מדיניות ונהלי אבטחת מידע, וכן הובלת פעילויות מודעות והדרכות בארגון.
התפקיד כולל עבודה שוטפת מול ממשקים רבים בארגון, בהם צוותי Security" פיתוח, תשתיות, IT, משפטית, פרטיות ורכש, תוך תרגום דרישות אבטחת מידע ורגולציה לתהליכים פרקטיים וברורים.
דרישות:
2+ שנות ניסיון בעולמות GRC, אבטחת מידע או Compliance
ניסיון בניהול עצמאי של תהליכי TPRM והערכת סיכוני ספקים
היכרות מעמיקה עם תקנים ומסגרות כגון: ISO 27001, SOC 2, GDPR, NIST ו-HIPAA
ניסיון בניהול ביקורות, איסוף ראיות, עבודה מול מבקרים והובלת תהליכי תיקון
יכולת עבודה עצמאית, ניהול מספר משימות במקביל וירידה לפרטים
תקשורת מצוינת בעברית ובאנגלית
ניסיון מחברת SaaS - יתרון משמעותי

"When the match is right - everything Powers Up" המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8739749
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בקבוצת Aman
מיקום המשרה: ירושלים
קבוצת Aman מגייסת מומחה/ית SIEM & Observability לארגון ממשלתי גדול בירושלים

היברידיות של 3 ימים מהבית

תחומי אחריות
ניהול ותפעול מערכות SIEM ותשתיות ניהול לוגים בארגון.
הובלת תהליכי קליטת לוגים, אגריגציה, אופטימיזציה ופיתוח יכולות ניטור.
עבודה בסביבות ענן מתקדמות וביצוע אוטומציות לשיפור תהליכים.
טיפול בתקלות מורכבות ומתן שירות לצוותים טכנולוגיים וללקוחות פנים.
הובלת פתרונות טכנולוגיים מקצה לקצה תוך חשיבה מערכתית.
דרישות:
ניסיון של לפחות 5 שנים בבדיקות חדירה או Red Team
ניסיון מעשי בבדיקות Web, תשתיות Active Directory ותקיפות בענן AWS / Azure / GCP
שליטה בכלים כגון Burp Suite, Nessus, Nmap, Metasploit ו-BloodHound וניסיון בכתיבת סקריפטים ב- Python / PowerShell / Bash
יתרון משמעותי להסמכות OSCP, OSEP, OSWE או CRTP/CRTE, לצד יכולת עבודה עצמאית, חשיבה התקפית ויכולת כתיבה מקצועית בעברית ובאנגלית המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8755517
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בלוגיקה IT
לחברה מדהימה המתמחה בעולמות הסייבר והקלאוד דרוש/ה Deputy CISO לעולמות IoT ו-Smart City
מיקום: תל אביב 
היקף משרה: משרה מלאה, אפשרות להיברידיות יום/יומיים 
*שימו לב - התפקיד לא HO* 
עובד חברה מהיום הראשון! 


תיאור התפקיד
התפקיד כולל עבודה צמודה עם מנהל אבטחת המידע הארגוני וסיוע בניהול תחומי אבטחת המידע והסייבר, תוך אחריות מקצועית והתמקדות בעולמות ה-IoT, התשתיות החכמות ויישומי Smart City.
 המועמד/ת יהיה/תהיה שותף/ה בגיבוש ובהטמעת מדיניות הסייבר הארגונית, בליווי פרויקטים טכנולוגיים ובהגנה על מערכות, התקנים ותשתיות עירוניות מחוברות.
 
תחומי אחריות
עבודה שוטפת וצמודה עם מנהל אבטחת המידע הארגוני ושמש/י כסגנו.
הובלת תחום אבטחת הסייבר במערכות IoT, OT ו-Smart City.
ליווי פרויקטים טכנולוגיים משלב התכנון ועד להטמעה, בהתאם לעקרונות Security by Design.
ביצוע סקרי סיכונים ובחינות אבטחה למערכות ולתשתיות מחוברות.
גיבוש מדיניות, נהלים, הנחיות ודרישות אבטחה למערכות IoT.
דרישות:
לפחות 5 שנות ניסיון בתחום אבטחת המידע והסייבר.
לפחות 3 שנות ניסיון באבטחת מערכות IoT, OT, ICS או Smart City.
ניסיון בתפקיד  CISO, Deputy CISO, Cybersecurity Architect, Security Consultant או תפקיד דומה.
ניסיון בביצוע סקרי סיכונים ובכתיבת מסמכי אבטחת מידע.
הבנה מעמיקה ברשתות תקשורת, הפרדת רשתות, TCP/IP ואבטחת תשתיות.
ניסיון בליווי פרויקטים טכנולוגיים ובהגדרת דרישות אבטחה.
ניסיון בעבודה מול ספקים, אינטגרטורים וגורמים ניהוליים.
יכולת כתיבה והצגה ברמה גבוהה בעברית ובאנגלית.
יכולת עבודה עצמאית, ניהול משימות והובלת ממשקים.
 
יתרון משמעותי
ניסיון בעבודה עם רשויות מקומיות, גופים ציבוריים או תשתיות קריטיות.
ניסיון בפרויקטים של Smart City או תשתיות עירוניות חכמות.
ניסיון באבטחת מצלמות, מערכות בקרת כניסה, חיישנים, תאורה חכמה, מערכות תחבורה, חניה חכמה, BMS או SCADA.
היכרות עם תקשורת אלחוטית ופרוטוקולים כגון Wi-Fi, LoRaWAN, NB-IoT ו-Zigbee. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8753891
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
דרושים בפרוסיד
מיקום המשרה: תל אביב יפו
הובלה מקצועית וארכיטקטונית של מערך אבטחת המידע בסביבות Multi-cloud AWS &
Azure.
התפקיד משלב תכנון אסטרטגי, כתיבת מדיניות והובלת פרויקטים טכנולוגיים מקצה לקצה.
המועמד/ת ישמשו כסמכות המקצועית בתחום הענן מול ממשקי פיתוח, תשתיות ומנהלי
פרויקטים, תוך הבטחת עמידה ברגולציות פיננסיות מחמירות.
דרישות:
ניסיון מקצועי:
לפחות 5 שנות ניסיון בתחום אבטחת המידע, מתוכן לפחות 3 שנים כארכיטקט/מומחה
תשתיות ענן Hands-on
ניסיון מוכח בעבודה בסביבות Multi-cloud (AWS ו- Azure (- חובה.
ניסיון מוכח בניהול והובלת פרויקטים טכנולוגיים חוצי ארגון.
הבנה עמוקה במערכות הפעלה) Linux /Windows (ותשתיות מבוססות
Containerization)כגון OCP/Kubernetes.)
היכרות מעמיקה עם רגולציות אבטחת מידע וסייבר)בדגש על הוראות בנק ישראל/גופים
פיננסיים(.
ניסיון בהובלת פרויקטי אבטחת מידע
כישורים אישיים:
אסרטיביות ויכולת עמידה בלחצים: יכולת עבודה עצמאית וקבלת החלטות קריטיות אל
מול ממשקים בעלי אינטרסים מנוגדים.
כושר ביטוי ברמה גבוהה: יכולת כתיבת מסמכי אפיון, נהלים ומצגות
יחסי אנוש ותקשורת בין-אישית: יכולת רתימה של צוותים טכניים וניהוליים למטרות
אבטחת המידע.
יכולת ונכונות ללמוד ולהשתלב בתחומים טכנולוגיים חדשים המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8662020
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בעידור מחשבים בע"מ
אחריות לזמינות, אמינות וביצועים של מערכות אבטחה בענן
ניהול שוטף של מעטפת האבטחה במספר Landing Zones בענן ציבורי
ניהול שינויים דרך תהליכי CI/CD מאובטחים IaC ושימוש ב Terraform
בעלות מקצועית על מערכות אבטחה בקטגוריות CNAPP, SAST, SCA
שותפ/ה בתכנון Landing Zones חדשים ובפרויקטים אסטרטגיים של עליה לענן
עבודה מול אנשי Platform, DevOps, סייבר וארכיטקטים
דרישות:
תואר במדעי המחשב/ הנדסת מחשבים / מערכות מידע /יוצא יחידות צבאיות/קורסים מתקדמים בתחום - חובה
ניסיון של לפחות 7 שנים ביישומי באבטחת מידע, מתוכן לפחות 3 שנים בענן ציבורי (Azure יתרון משמעותי)
היכרות ועבודה עם ארכיטקטורות ענן בארגוני Enterprise
ניסיון בעבודה עם רכיבי אבטחה בענן כגון: Firewall, API GW, WAF, Azure Policy, APM
רקע משמעותי ב כתיבת תשתיות באמצעות IaC (Terraform או שווה ערך)
ניסיון באבטחת Kubernetes (AKS / OpenShift)הכולל Network Policies, RBAC, Secrets Management, Image Scanning, Admission Control
ניסיון רב-עננים (Multi-Cloud) - AWS / GCP בנוסף ל-Azure- יתרון משמעותי
ניסיון בעבודה במודל CCoE / Platform Team / Enterprise Architecture- יתרון משמעותי המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8753070
סגור
שירות זה פתוח ללקוחות VIP בלבד
לוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/07/2026
Location: Petah Tikva
Job Type: Full Time and Hybrid work
We seek an experienced offensive security leader to build and lead the Product Red Team. This newly established function emulates real-world attacks against synthetic customer instances to identify vulnerabilities, misconfigurations, and design gaps before external threat actors or researchers discover them.
This role requires an operator who has led offensive security operations in high-consequence environments-covert intelligence or military settings preferred-with proven ability to establish operational standards, navigate ambiguous mission parameters, and influence cross-functional stakeholders around complex security trade-offs.
You will build upon this team's charter, engagement frameworks, and rules of engagement with other teams. You will help drive our product security and response posture through adversary emulation, vulnerability research, exploit development, and collaboration with other offensive and defensive teams.
Key Responsibilities:
Establish Operations Objectives, Policies & Procedures:
Own Product Red Team's operation objectives and engagement selection criteria in alignment with product security roadmap and risk register, CISO directives, and company priorities.
Expand upon rules of engagement, threat actor emulation standards, testing policies, and protocols.
Establish operational security procedures for covert operations, detection evasion, and incident response protocols.
Create escalation procedures and approval frameworks for high-risk engagements.
Own campaign selection processes, engagement proposal templates, and findings documentation and readout standards.
Define Engagement Framework & Success Metrics:
Design and implement engagement types: vulnerability risk assessment, product security assessments, and ongoing adversarial campaigns.
Establish and report on technical and operational success metrics: kill chain coverage, remediation velocity, and detection engineering insights.
Create reporting templates-technical findings, executive briefings, engineering recommendations-that drive actionable remediation.
Define boundaries and operational testing windows in coordination with product engineering and detection engineering teams.
Lead Offensive Operations Team:
Build team capability across threat actor emulation, exploit development, persistence mechanisms, supply chain security, and AI-specific attack vectors (prompt injection, model manipulation, data poisoning).
Mentor team on operational security tradecraft, documentation discipline, and risk management under ambiguous conditions.
Support team members in their time zones, spanning from US West Coast to India.
Requirements:
12+ years of offensive security experience, with minimum 5+ years leading offensive operations teams in mission-critical environments.
Background in leading covert offensive cyber operations in:
Intelligence communities, or
Contracted equivalent, or
Top-tier private-sector adversary emulation firms or internal teams.
Expertise in:
Threat actor emulation and MITRE ATT&CK methodologies as translated and applied to product security.
Exploit development and proof-of-concept creation.
Persistence mechanisms, detection evasion, and command & control operations in SaaS environments.
Kill chain analysis and attack path development.
Security control validation and testing under strict rules of engagement.
Proven ability to:
Operate under ambiguous mission parameters and establish doctrine.
Establish and enforce operational security discipline in high-stakes environments.
Navigate regulatory and legal constraints while maintaining operational effectiveness.
Mentor elite operators and maintain team excellence under pressure.
Brief executives on complex security risks and influence decision-making.
Product security awareness: Familiarity with SDLC integration, CI/CD pipelines, SaaS threat models, and multi-tenant architecture considerations.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8751380
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/07/2026
Location: Petah Tikva
Job Type: Full Time and Hybrid work
We seek a Senior Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.
The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.
As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.
Key Responsibilities:
Triage and Resolve Bug Bounty Reports:
Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition.
Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed.
Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues.
Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom.
Propose remediations, or design them with engineering, and verify the fix resolves the issue.
Assign and defend severity ratings using the program's severity framework.
Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure.
Own Researcher and Stakeholder Communication:
Act as our primary technical point of contact for bug bounty researchers across the full lifecycle of a report.
Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible.
Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk.
Mentor the Team and Raise Triage Standards:
Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication.
Set and maintain the bar for triage quality and strengthen program practices over time.
Requirements:
8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.
Expertise in:
Common web and application vulnerability classes and exploitation techniques.
Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity.
Coordinated vulnerability disclosure.
Code and development fluency:
Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests.
Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code.
Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC.
Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research.
Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8751365
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Ra'anana
Job Type: Full Time and Hybrid work
Required Senior Embedded Vulnerability Researcher
Were seeking passionate professionals who thrive in a fast-paced, creative, and collaborative environment - those who want to be part of the next generation of airspace security innovation.
Join us and help make the world a safer place.
Work with the worlds leading cyber-takeover counter-drone technology provider and shape the future of safe airspace.
Scope:
Our mission is to defend and mitigate the danger from rogue drones.
We are looking to expand our drone take-over research team, which is responsible for the core technology of our product.
This is a great opportunity for you to expand your capabilities working on versatile and innovative cyber research projects as part of a young and extremely talented team.
Requirements:
4+ years of relevant industry experience as embedded vulnerability researcher or equivalent.
Experience with a dis-assembler for vulnerability research (IDA Pro or GHIDRA).
Deep understanding of OS internals (Linux, RTOS, Android etc.).
Experience with complicated exploitation methods on embedded systems.
Experience with writing code in assembly or c and Python.
Advantage - Graduate of an elite technological unit in IDF.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8707218
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות שנמחקו