רובוט
היי א אי
stars

תגידו שלום לתפקיד הבא שלכם

לראשונה בישראל:
המלצות מבוססות AI שישפרו
את הסיכוי שלך למצוא עבודה

מומחה אבטחת מידע / סייבר

מסמך
מילות מפתח בקורות חיים
סימן שאלה
שאלות הכנה לראיון עבודה
עדכון משתמש
מבחני קבלה לתפקיד
שרת
שכר
משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP

חברות מובילות
כל החברות
כל המידע למציאת עבודה
5 טיפים לכתיבת מכתב מקדים מנצח
נכון, לא כל המגייסים מקדישים זמן לקריאת מכתב מק...
קרא עוד >
הטבות ובונוסים בעבודה בחברות הייטק
מכון כושר צמוד, חדר אוכל משובח, חדר משחקי וידאו...
קרא עוד >
טעויות נפוצות בניהול קריירה
הדרך לחיים של חוויות והזדמנויות עוברת דרך תכנון...
קרא עוד >
לימודים
עומדים לרשותכם
מיין לפי: מיין לפי:
הכי חדש
הכי מתאים
הכי קרוב
טוען
סגור
לפי איזה ישוב תרצה שנמיין את התוצאות?
Geo Location Icon

לוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
31/08/2026
Location: Tel Aviv-Yafo and Netanya
Job Type: Full Time
We are seeking a GRC Specialist (Governance, Risk, and Compliance) to join our growing GRC Team. This is a fantastic opportunity to be part of a growing team and support the company as it grows and matures. If you're a team player, self-driven, creative thinker, passionate about cybersecurity, and capable of blending a process-oriented mindset with a tech-oriented outlook, we are looking for you!

As a GRC specialist you will...
Maintain internal and external trust platforms, supporting ongoing customer due diligence activities including audits, questionnaires, and reviewing security contractual requirements.
Provide training and guidance to sales teams on compliance-related matters and develop tools and resources to enable the Sales Team to efficiently respond to compliance inquiries from prospective and existing customers.
Collaborate with cross-functional teams to support and enhance the overall GRC program.
Ensure company policies, procedures, and controls are aligned with regulatory requirements and industry standards.
Proactively gather customer feedback and stay abreast of industry trends to adapt and mature the GRC program accordingly.
Implement improvements and updates to the program, based on regulatory changes and customer requirements.
Participate in risk assessment and risk management processes.
Requirements:
Minimum 1-2 years as a cyber security / GRC specialist, expert, or consultant
Strong knowledge and hands-on experience with ISO 27001 and SOC 2 Type II
Familiarity with additional security frameworks as well as privacy regulations and standards (NIST, CSA, CAIQ, SIG, GDPR, CCPA, ISO 27701) is an advantage.
An excellent ability to communicate verbally and in writing
Ability to work on multiple projects simultaneously
Project management skills
Self-driven and fast learner with a can-do approach
Passionate about the team and responsibilities
Experience with auditing cloud environments
Experience in working with regulators and auditors
Experience in working with GRC tools
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8804094
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
31/08/2026
Location: Tel Aviv-Yafo and Netanya
Job Type: Full Time
. We are looking for an experienced malware researcher to join the team. As a Malware Researcher , you will perform research on source code, compiled code, and various software supply chain attacks. The position requires proven experience in security nomenclature and an understanding of both high-level and low-level attack
As a Malware Researcher you will...
Research malicious code in public repositories from various coding languages and technologies.
Define and implement ways to automatically detect malicious code in open-source software.
Write technical reports and outward-facing publications regarding all research subjects mentioned above.
Requirements:
3+ years malware research experience in any of the following languages: Native code (C, C++), .NET (C# etc), Python, Node.JS, Java, Go
Experience in writing technical reports
Programming experience in Python
Advantage - Binary reverse engineering experience
Advantage - DevOps experience
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8804079
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
30/08/2026
מיקום המשרה: חולון
סוג משרה: משרה מלאה
תנאים נוספים:החזר הוצאות
קומסקיור הנציגה הרשמית של Safetica בישראל, מגייסת מנהל /ת מוצר טכני להובלת פעילות המוצר בישראל.
אנחנו מחפשים איש סייבר עם ניסיון מעשי בעולמות ה- DLP שאוהב/ת לעבוד עם אנשים בדיוק כמו עם טכנולוגיה.
מישהו/י שיודע/ת להוביל תהליכים טכנולוגיים מול לקוחות ומשווקים, להיכנס לעסקאות מורכבות, לבצע Presale והטמעות ולהוביל את הרחבת הפעילות של Safetica בשוק הישראלי.

מה כולל התפקיד:
ביצוע Presale וליווי עסקאות מול לקוחות ומשווקים
ביצוע POC, הטמעות וטיפול באתגרים טכנולוגיים
הכשרת משווקים והעברת הדרכות מקצועיות
העברת וובינרים, סדנאות וימי עיון
בניית חומרי הדרכה ומסמכים טכניים
עבודה שוטפת מול יצרן המוצר
התאמת פתרונות DLP לצרכי הלקוחות
הרחבת הפעילות והגדלת קהילת השותפים הפעילים סביב המוצר
עבודה צמודה מול צוותי המכירות, התמיכה והשיווק בחברה

מדובר בתפקיד טכני עם עבודה מול אנשים, שטח ולקוחות ולא עבודה מול צוותי פיתוח.
דרישות:
לפחות 3 שנות ניסיון בעולמות אבטחת המידע - חובה
ניסיון מעשי במערכות DLP / Endpoint Security / data Security חובה
ניסיון ב- Presale, הטמעות, ייעוץ טכנולוגי או ניהול פרויקטים - חובה
יכולת פרזנטציה והעברת הדרכות
אנגלית ברמה גבוהה

יתרון משמעותי ל:
ניסיון קודם עם Safetica
ניסיון בניהול מוצר טכנולוגי
הסמכות בתחום הסייבר ואבטחת המידע המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8801230
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Security Researcher.
As a Senior Security Researcher, you will bridge our core research initiatives at the intersection of proactive exposure management, agentic workflows, and scalable threat modeling. We are looking for an innovator who translates complex security data into product-driven features, taking full ownership from concept to production.
What You'll Do:
Drive Product-Led Research: Translate complex, real-world security challenges into actionable, product-driven research. Take full ownership of research projects end-to-end, from identifying the security gap to collaborating with engineering to ship platform features.
Drive Proactive Exposure Management: Leverage Automated Security Control Assessments (ASCA) alongside vulnerability evaluation and prioritization to holistically assess organizational risk. Deep dive into enterprise security tools (EDR, SIEM, Firewalls, IAM, etc.) to analyze configurations, map defensive capabilities, and continuously evaluate their effectiveness against real-world threats.
Build Security Tool Integrations: Drive the technical research and define the data models required to actually build deep, functional integrations into diverse security platforms, ensuring the accurate extraction of telemetry, policies, and configuration data.
Build AI & Agentic Workflows: Define, design, and implement the logic and knowledge base that feeds Nagomi's AI-powered agents, ensuring they deliver accurate, context-aware security guidance and automated risk assessments.
Map Attack Paths: Define realistic attack flows, identify toxic combinations of misconfigurations, and surface the security gaps that help customers prioritize the risks that actually matter.
Engage with Customers: Work directly with customers to help them understand their exposure, translate your research findings into meaningful posture improvements, and gather feedback to drive product innovation.
Cross-Functional Collaboration: Partner closely with product, engineering, and data teams to embed security insights into everything we build.
Requirements:
Experience: 5+ years of hands-on experience in cybersecurity research, exposure management, vulnerability analysis, or threat intelligence.
Product Mindset: Strong ability to tackle projects end-to-end, translating theoretical security research into tangible product features and automated detection logic.
Broad Security Knowledge: Deep understanding of enterprise security tools (EDR, NDR, SIEM, VM, etc.), network topology, and how security components interact to impact network posture.
AI/Agentic Expertise: Proven experience building or heavily shaping AI-powered systems and agentic workflows. You must be able to point to concrete examples where you have integrated LLMs or AI processes to solve complex technical problems.
Attacker's Perspective: Solid foundation in how adversaries think, move laterally, and exploit enterprise environments, paired with expertise in leading vulnerability prioritization standards (MITRE ATT&CK, CISA KEV, EPSS).
Communication: Strong communication skills with demonstrated experience working directly with customers, stakeholders, and cross-functional engineering teams.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8802063
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/08/2026
Location: Petah Tikva
Job Type: Full Time
We are looking for an Information Security and Cyber Specialist with hands-on experience in information security systems to join the company’s Information Security team. The role includes responsibility for the operation and management of security systems, the investigation of information security incidents, and advanced technological areas within the Information Security Department.

Responsibilities:

* Monitoring, operation, and maintenance of information security systems.
* Handling and analyzing information security incidents at the Tier 2 level.
* Conducting initial and advanced investigations of cyber incidents.
* Working with IT and DevOps teams and external vendors.
* Writing procedures and technical documentation.
* Assisting with regulatory controls, risk assessments, and audits.
* In-depth knowledge of Microsoft 365 and Azure Security systems.
* Experience in managing and implementing EDR/XDR and SIEM systems and endpoint protection solutions.
* In-depth understanding of networking and Windows and Linux operating systems.
* Experience working with firewalls, VPN, NAC, and network security solutions.
* Ability to work independently, learn quickly, and maintain a system-wide perspective.
Requirements:
Mandatory Requirements
* At least five years of experience in information security and cybersecurity.
* Experience working with Microsoft 365 Security and Defender.
* Experience with EDR/XDR or SIEM systems.
* Knowledge of networking, Active Directory, Windows Server, and Entra ID.
* Experience handling information security incidents.
* Strong self-learning capabilities and the ability to work independently.
Preferred Qualifications
* Experience in Azure and on-premises environments.
* Knowledge of PowerShell or Python.
* Experience working with information security standards and regulatory requirements.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8801753
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/08/2026
Location: Ramat Gan
Job Type: Full Time
As a Cybersecurity GRC Specialist at our innovative healthcare startup, you will own our information security program end to end. We are on a mission to bring the first Hybrid Drug to market: a groundbreaking therapeutic entity that integrates mobile apps with traditional medication. Operating at the intersection of digital health and pharma means security, privacy, and compliance are core to what we build - and you'll be the one making sure we get it right. If you're excited to shape and lead the security function of a growing company (rather than inherit one), read on

About the Role
This is a hands-on role with broad ownership. You'll act as our security lead, serving as the go-to person for all things governance, risk, and compliance - working directly with leadership, engineering, quality, and clinical teams. It's a great fit for someone with a few years of GRC experience who's ready to take on company-wide responsibility, not a traditional executive CISO position.

‍

Responsibilities
Governance & Security Program
Build, implement, and maintain our Information Security Management System (ISMS) in line with ISO 27001.
Develop and enforce security policies, standards, guidelines, and procedures across the company.
Foster a culture of security awareness through training and ongoing communication.
Risk Management
Identify, assess, and prioritize cyber risks across our products, infrastructure, and vendors.
Conduct Business Impact Analyses (BIA) to map critical business functions and potential disruptions.
Own the risk register and drive mitigation plans with relevant stakeholders.
‍
Compliance & Regulatory Alignment
Ensure compliance with healthcare and privacy regulations, including HIPAA and GDPR.
Support regulatory and quality processes relevant to medical device software (e.g., working alongside our QA/RA team on standards such as ISO 13485 and IEC 62304 where security intersects).
Manage security aspects of customer, partner, and vendor due diligence, including security questionnaires and audits.
Resilience & Incident Preparedness
Design and maintain Business Continuity (BCP) and Disaster Recovery (DRP) plans.
Define and test incident response procedures; lead response efforts when needed.
Run periodic tabletop exercises and recovery drills.
Security Operations & Engineering Collaboration
Work with engineering to embed security requirements into the development lifecycle of our mobile and cloud platforms.
Coordinate penetration tests, vulnerability assessments, and remediation follow-up.
Evaluate and manage security tooling appropriate to our size and needs.
Requirements:
2-4 years of hands-on experience in a GRC, information security, or IT security role - ideally in healthcare, medtech, or another regulated industry.

Knowledge
Practical experience implementing or maintaining ISO 27001-based ISMS (certification project experience is a strong plus).
Solid understanding of risk management methodologies, BIA, BCP, and DRP.
Familiarity with privacy and healthcare regulations such as GDPR and HIPAA.
Skills & Mindset
Strong ability to translate security and compliance requirements into practical, business-aligned actions.
Comfortable working independently and owning a domain across the whole company.
Excellent communication skills - you can explain risk to engineers, executives, and auditors alike.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8800876
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
27/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for an AI Security Researcher to join us and uncover emerging AI threats, derive detection logic, discover new attack vectors, conduct red teaming, and identify insider threats and misconfigurations.
What You'll Do:
Deep-dive into AI usage risks, including threat detection for chat platforms and AI agents.
Research emerging agent threats and LLM attacks, such as jailbreaks and prompt injection.
Conduct red teaming and large-scale experiments on AI agents, including quantitative experimentation and advanced result analysis.
Assess internal and externally-facing AI agents for security posture and risk exposure.
Evaluate and attack real-time defenses and runtime protections for AI applications.
Conduct research across cloud, web, and API security to uncover novel threats and attack vectors relevant to AI systems.
Partner with product and engineering teams to turn research findings into detection logic, guardrails, or product features.
Stay current on and contribute to industry frameworks (e.g., OWASP LLM Top 10, MITRE ATLAS) - potentially contributing back to the community.
Publish blog posts, give talks, and represent research at conferences.
Requirements:
Background in AI/ML or security research. Ideal candidates have both, but we're equally open to candidates from data science or security research backgrounds with demonstrated depth in AI systems.
5+ years of experience in the AI or security industry.
Solid understanding of AI agents: how tool use, memory, planning, and orchestration layers interact, and where that architecture introduces risk.
Working knowledge of LLM and agentic security - prompt injection, jailbreaks, tool-use exploitation, memory/context poisoning, and related attack classes.
Knowledge of AI vulnerabilities at both the model and infrastructure layers, and familiarity with effective mitigation strategies (e.g., guardrails, sandboxing, input/output filtering, access controls).
In-depth understanding of LLMs, generative AI, agentic systems, and RAG pipelines - how they're built, where they break, and how failure modes propagate through a system.
Strong research methodology and judgment: experience designing large-scale experiments, forming hypotheses, and applying quantitative rigor to evaluate results, identify signal from noise, and draw defensible conclusions from complex or ambiguous data.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8800549
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
27/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Lead Security Researcher.
You will lead security research. This is not a bug hunting role. Your job is to invent the approaches that become product capabilities: new ways to detect, triage, and remediate vulnerabilities using LLMs and program analysis, proven on real data before a customer ever sees them.
You own the path from idea to shipped capability. You form the hypothesis, build the proof of concept, measure whether it actually works, and partner with engineering until it is in the product. You also own the quality bar: the benchmarks and evaluations that decide whether what we ship is good enough to put in front of customers.
You will set the research agenda, not just execute one. As the team grows, you will shape how research works here.
Requirements:
Experience. 8+ years in security research, vulnerability analysis, or applied security engineering.
Startup DNA. You have worked in an early stage or 0 to 1 environment. Comfortable with ambiguity, shipping without a big org behind you, and changing direction when the data says so. This is a requirement, not a bonus.
Research to product track record. You have turned research into things that shipped: features, tools, detections in production. Not just papers or reports.
Technical depth. Deep expertise in modern application stacks (microservices, containers, cloud platforms). You understand how these systems actually break.
Builder skills. Strong programming ability in at least one modern language (Python, Go, TypeScript). Comfortable writing production quality code.
Data rigor. Experience designing experiments, building datasets or benchmarks, and measuring quality quantitatively. You do not ship on vibes.
LLM fluency. Hands on experience applying LLMs to real problems, whether evaluation, prompting, fine tuning, or agentic systems, or a demonstrated ability to get there fast.
Proven findings. A history of discovering serious vulnerabilities (CVEs welcome) and responsible disclosure.
Communication. You can explain a complex attack and its real impact clearly to engineers, executives, and customers.
Work authorization. Permanent authorization to work in the US for the San Francisco role, or in Israel for the Israel role.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8800513
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
27/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for an experienced Security Researcher to join our core team and deep dive into CVEs, conducting cutting-edge vulnerability research that directly powers Echo's revolutionary approach to eliminating container vulnerabilities at the source.
Responsibilities:
Conduct deep-dive research into CVEs and vulnerabilities, analyzing root causes and attack vectors to inform our AI-powered prevention platform
Perform reverse engineering analysis using tools like IDA Pro, Ghidra, or similar platforms to understand complex security vulnerabilities and exploitation techniques
Research and analyze complex low-level system mechanisms including kernel vulnerabilities, network security issues, and operating system weaknesses
Think outside the box, challenge existing assumptions, and create innovative approaches to vulnerability research and prevention
Work in a unique environment where your research insights are rapidly implemented into our product, creating direct real-world impact from your vulnerability research
Contribute to Echo's technical knowledge base and help establish new methodologies for proactive vulnerability identification and mitigation
Requirements:
3+ years of hands-on experience with AI or machine learning frameworks
4+ years of experience as a Software Engineer
Experience deploying and scaling AI/ML models in production environments
Proficiency with cloud platforms, particularly AWS, for AI/ML workloads
Excellent communication skills and proven ability to work effectively in cross-functional teams
Strong problem-solving skills and ability to translate business requirements into technical AI solutions
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8800494
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
27/08/2026
Location: Haifa
Job Type: Full Time
This is a full-time on-site role located in Haifa for a SecOps professional. The responsibilities include maintaining and optimizing security operations, identifying and mitigating potential vulnerabilities, implementing security monitoring solutions, and responding to security incidents. The role involves working collaboratively with cross-functional teams to ensure the deployment of robust security measures and policies across systems and infrastructures.
Requirements:
Core Security & Operations
3+ years experience in SecOps / Cloud Security / Security Engineering
Hands-on experience securing Google Cloud Platform environments
Strong understanding of:
IAM (roles, service accounts, workload identity)
Network security (VPCs, firewall rules, load balancers)
Organization policies and security baselines
Experience operating and tuning security controls in production

Detection, Monitoring & Response
Experience with Google Cloud Security Command Center
Experience with Google SecOps (Chronicle) or equivalent SIEM
Building and tuning:
Detection rules
Alerts
Dashboards
Incident triage, investigation, and response in cloud environments
Log ingestion and normalization from cloud and third-party sources

Automation & Engineering
Strong scripting skills (Python preferred)
Security automation (SOAR-like workflows, custom tooling)
Experience integrating security tooling via APIs
CI/CD security controls (shift-left, pipeline security checks)
Cloud & Platform Security

Experience securing:
GKE
Cloud Run
Compute Engine
Knowledge of container security concepts (images, registries, runtime)
Vulnerability management and remediation workflows

Governance & Compliance
Experience with security posture management
Familiarity with common frameworks (ISO 27001, SOC 2, CIS Benchmarks)
Risk assessment and security findings remediation

Nice to Have:
Experience with Wiz, Prisma Cloud, or similar CSPM tools
Experience with threat modeling and attack simulations
Experience working with regulated environments
Google Cloud security certifications
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8800177
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
27/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a WAF Security Specialist.
What You'll Do:
Create - Produce production WAF rules across providers for high-impact CVEs and customer findings - driving the Copilot harness on most of them, writing the expression yourself on the hard ones (no public PoC, exploitable path reasoned out of a patch diff, urgent customer coverage). Your rules ship, and they set the bar generated rules are measured against.
**Optimize -**Tighten generated rules for real production constraints: WCU and rule-capacity budgets, latency, provider expression limits, and the anchoring required for a rule that fires against all traffic behind a shared Web ACL - not just the vulnerable app.
Validate - Own the adversarial pass. Build exploit variants the PoC doesn't cover, hunt bypasses in our own rules, and run the false-positive side seriously - verifying against how the legitimate client actually behaves on the wire, not against an assumption.
Monitor - Watch deployed rules in production: false-positive signals, hit patterns, coverage drift as managed rulesets shift underneath us, and the log→block promotion decision. Retire what no longer earns its capacity.
Make it reproducible - Turn every finding into a regression test. Build and curate the golden CVE datasets and scoring rubrics that gate whether a new Copilot version ships.
Set the coverage line. Judge which CVEs are genuinely WAF-mitigatable and which aren't, and make the call on what enters and leaves our managed rulesets - with the reasoning written down.
Requirements:
Deep, hands-on WAF expertise across multiple major providers - you've written, tuned, and operated real rules in production on several of: AWS WAFv2, Cloudflare, F5, Imperva, Akamai, Azure, GCP, Fortinet, ModSecurity/CRS. Not "managed a WAF vendor relationship" - written the rules.
You know the caveats cold. Body-inspection limits and oversize handling, text transformations and normalization order, encoding and unicode evasion, parameter pollution, chunked and multipart edge cases, rule precedence and evaluation order, WCU/capacity economics, and how each provider's expression language quietly differs from the others.
Strong security research background - application security, vulnerability research, or offensive security. You can read an advisory, build the PoC, derive the variants nobody published, and explain exactly which request component carries the exploit primitive.
A real feel for the false-positive tradeoff. You've had to defend a blocking decision to someone whose production traffic you broke, and you know why "block everything suspicious" is not a security posture.
Comfortable in code. Enough Python (or similar) to automate replay, build variant generators, and query exploit and traffic data yourself rather than waiting on someone.
Fast under pressure, systematic afterward. You can get a solid rule out the door when a customer needs one today - and your instinct once it ships is to build the check that catches the whole class, not just the instance you fixed.
Advantage: virtual patching / vulnerability-mitigation experience, or time on a WAF vendor's rules or research team.
Advantage: hands-on with LLMs and agentic tooling - you'll be shaping an AI system's output, and it helps to understand how it fails.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8800121
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
26/08/2026
מיקום המשרה: קרית שדה התעופה
סוג משרה: משרה מלאה
עבור ארגון גדול דרוש/ה מומחה/ית תשתיות ואבטחת מידע
מיקום: איירפורט סיטי
מה בתפריט?
הובלת תהליכי אפיון, עיצוב ויישום של שרתים, רשתות ופתרונות אחסון.
ניהול ופיתוח תשתיות ענן (AWS / Azure / GCP) ו-On-Premise, תוך שמירה על זמינות גבוהה ו-DR.
הטמעה ותחזוקה של פתרונות אבטחה תשתיתיים (EDR/XDR, FW, SIEM / SOC, IAM).
ניהול סביבות וירטואליזציה ( VMware /Hyper-V) והקשחת מערכות.
עבודה שוטפת וממשק מול גורמים בינלאומיים וספקים בעולם.
להגשת מועמדות ושליחת קורות חיים למייל.
דרישות:
* 5+ שנות ניסיון כמהנדס/ת תשתיות / סיסטם / ארכיטקט/ית בארגונים מרובי אתרים.
* ניסיון עשיר בסביבות ענן (AWS, Azure, GCP) וטכנולוגיות וירטואליזציה.
* הבנה מעמיקה בכלי אבטחת מידע ברמת התשתית והרשת (דגש על סביבת Cisco).
* ראייה מערכתית רחבה, עצמאות ויכולת פתרון בעיות מורכבות.
* ניסיון בארגון גלובלי - יתרון משמעותי! המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798696
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
26/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a Pentest Product Associate to join our Product team and help expand our power. In this pivotal role, you will be the primary operator of our cutting-edge AI-driven Dynamic Application Security Testing (DAST) agent while simultaneously innovating detection mechanisms for cloud-native technologies. You will bridge the gap between automated AI testing and cloud infrastructure, defining the "rules of engagement" for our agents to ensure they effectively simulate sophisticated attacks and accurately classify the modern attack surface.
Responsibilities:
Develop advanced detection algorithms to classify cloud technologies while fine-tuning the attack policies that define how our agents identify and exploit vulnerabilities.
Analyze cloud services, APIs, and log payloads to review complex attack paths, reducing false positives and ensuring compliance with industry standards.
Stay at the forefront of novel attack vectors and emerging cloud/API threats, translating new techniques into executable behaviors for the DAST engine.
Collaborate directly with Research, Backend, and R&D teams to turn operational insights into feature requests, positioning us as the market leader in vulnerability management.
Requirements:
Minimum Qualifications:
2 years of hands-on experience in AppSec or penetration testing, including proficiency with enterprise tools like Burp Suite, OWASP ZAP, or Acunetix.
Hands-on experience with Linux, Windows, Docker, Kubernetes, web protocols (HTTP/S, REST, GraphQL), and authentication mechanisms (OAuth, SAML).
Proficiency in scripting languages such as Python, Bash, or Go to automate security tasks and interact with codebases.
Solid knowledge of networking concepts, the OSI model, and cloud infrastructure (AWS, Azure, or GCP).
Preferred Qualifications:
Knowledge of AI/ML and how LLMs or reinforcement learning agents operate within a cybersecurity context.
SaaS and cloud experience, with familiarity in AWS, Azure, or GCP environments and modern cloud-native architectures.
A red teaming background, with experience in simulated adversarial attacks and bypassing standard WAF or security controls.
An analytical mindset with the ability to diagnose complex logs and scans to distinguish between tool failures, configuration issues, and valid security findings.
Self-motivated with the ability to work collaboratively and communicate high-stakes security concepts effectively across teams.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798539
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
e are currently seeking a dynamic Incident Response Analyst to contribute to the success of our rapidly growing business.



As an Incident Response Analyst, you will:

Investigate and respond to workspace security incidents across email, browser security and perimeter security domains.
Handle investigation requests submitted by customers
Perform targeted phishing analysis and investigation of new attack campaigns
Conduct threat hunting based on attack patterns, behaviors, and indicators
Build and improve detections based on new attack types, tactics, companies and trends
Collaborate with development and research teams to provide incident-driven insights, and develop new detection engines for identifying previously unknown attacks
Write professional blog posts based on incident investigations and attack trends, contributing to the companys research-driven content and public visibility
Work in rotating shifts as part of a 24/7 operation (including nights, weekends, and holidays)
Requirements:
At least 3 years of experience in an Incident Response or Security Operation roles
Strong understanding of attack vectors, including Phishing, BEC, Email spoofing and impersonation techniques, Malware, ATO and more
Knowledge of email protocols and security concepts: SMTP, SPF/DKIM/DMARC, headers, authentication methods
Strong querying skills using SQL, SPL, KQL or AQL
Good knowledge with Static & Dynamic techniques
Familiarity with and understanding of code and scripting languages such as Python, JavaScript, Visual Basic, or similar - with the ability to read, interpret, and analyze potentially malicious scripts
Excellent written and verbal communication in English
Team player with a proactive, ownership-driven approach
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8797736
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
26/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for an IT Operations & Security Specialist to join our IT & Security team. IT operations will be your primary domain - keeping global infrastructure running, employees productive, and office environments stable across Israel, Europe, and the US - with security work (endpoint monitoring, SaaS risk assessments, access governance, and customer-facing security reviews) as a natural extension of that ownership.
What You'll Do
Deliver Tier 1 and Tier 2 global technical support on a shifted schedule, covering employees across Tel Aviv, Europe, and the US.
Own the full employee onboarding and offboarding lifecycle - device provisioning, access activation, and secure asset retrieval and revocation.
Administer the full identity lifecycle across the core SaaS stack (Okta, Google Workspace), enforcing role-based access controls and license hygiene.
Manage the global hardware lifecycle and asset register, from shipping logistics through secure offboarding and inventory tracking.
Own the office infrastructure environment - network hardware, physical security systems, cabling, and AV/video conferencing setups.
Execute customer-facing security questionnaires and vendor assessments as the operational point of contact for sales-driven security reviews.
Monitor and maintain endpoint health across EDR (CrowdStrike) and MDM (JumpCloud), flagging and remediating non-compliant devices.
Conduct security risk assessments on new SaaS applications and support SOC 2 / ISO 27001 compliance initiatives and audits.
Requirements:
Must-have
3-5 years in IT Operations or Systems Administration within a global high-tech environment, with hands-on expertise troubleshooting, configuring, and deploying macOS and Linux systems.
Proven experience managing the full IT employee lifecycle - provisioning, identity/access setup, and secure offboarding.
Proven experience managing device fleets via enterprise MDM platforms (JumpCloud, Jamf) and administering IAM/SSO platforms (Okta, Google Workspace).
Solid understanding of enterprise networking (TCP/IP, DNS, DHCP, VLANs, firewall policies), with hands-on experience deploying physical network infrastructure; Cisco Meraki experience a strong advantage.
Hands-on security operations experience, including active management of enterprise EDR tooling such as CrowdStrike Falcon.
Ability to work a shifted schedule with dedicated overlap with US business hours.
Fluent English (written and verbal) with a service-oriented mindset for supporting global employees and vendors.
Comfortable with the physical demands of IT work - office setups, cabling, monitor installation, hardware inventory.
Nice to have
Prior experience with customer security questionnaires, SOC 2 / ISO 27001 audits, or vendor risk assessments.
Hands-on experience with hardware in Zoom Rooms environments.
Experience with low-code tools (Make.com, n8n) or basic scripting (Bash/Zsh).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8797626
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות שנמחקו