דרושים » אבטחת מידע וסייבר » Offensive Security team lead בחברת הייטק בתחום ה-DevSecOps ו-MLOps

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
לפני 9 שעות
GotFriends
דרושים בGotFriends
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה
החברה מפתחת כלי CI/CD שבאים לייעל את תהליכי הפיתוח והפצת התוכנה למפתחים בחברות אחרות. לחברה מספר מוצרים שבאים לתת פתרון End to End למפתחים כגון מוצר Security, מוצר עדכון תוכנה לIOT, מוצר CI/CD ועוד.
החברה ממוקמת בתל אביב- קו רכבת, משלבת מודל עבודה היברידי ומונה 1800 עובדים גלובלית.
מהות התפקיד: הובלת צוות ה-Offensive Security Engineer, צוות חדש, כרגע כולל ניהול של איש אחד, דיווח ל-Group Leader. 70% Hands On. רוצים לייצר יכולות תקיפה פנימיות בתוך הקבוצה-הובלה, תכנון וביצוע פעילות ה-Red Team. עזרה בפיתוח וביצוע תרחישי תקיפה מתקדמים בענן בעולמות של Kubernetes, Docker, Terraform, כדי להעריך את יכולות האבטחה ולשפר את העמידות שלה.
דרישות:
- 6 שנות ניסיון במחקר
- ניסיון ב-Offensive Security Operations/Red Teaming/Threat Hunting/Threat Research
- ניסיון בפיתוח עם Cloud המשרה מיועדת לנשים ולגברים כאחד.
 
הסתר
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8220267
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 9 שעות
DSIT
דרושים בDSIT
Location: More than one
Job Type: Full Time
Cybersecurity Engineer & Implementation Specialist Technological Projects
Location: Givat Shmuel, Israel | Full-time | On-site
A leading company specializing in the development and implementation of multidisciplinary systems, comprehensive defense and protection solutions against various underwater threats, is looking for a Cybersecurity Engineer & Implementation Specialist to join its growing team.
The Cybersecurity Engineer will be responsible for all cybersecurity aspects of the companys technological projects from design to deployment ensuring multi-level protection and compliance with industry standards.
Key Responsibilities:
Harden operating systems (Windows / Linux) according to CIS Benchmarks and other best practices
Monitor and analyze security events using tools such as SIEM, EDR, Sysmon, etc.
Apply identity and access management (IAM) policies
Write and maintain technical security documentation and procedures
Participate in system analysis and design to ensure security is embedded from the start
Participate in all other phases including coding, testing, and integration to ensure security is not forgotten in any stage
Collaborate with infrastructure, development, and project teams to align security with engineering goals
Requirements:
At least 2 years of experience in cybersecurity including both information and network security analysis mandatory
Proven experience in hardening mandatory
Solid understanding of several cybersecurity frameworks such as CIS Benchmarks, NIST, ISO 27001 mandatory
Experience with security monitoring and detection tools (SIEM, Sysmon, EDR, etc.)
Technical writing abilities mandatory
Experience in multidisciplinary projects mandatory
Independent, proactive, and a team player
Advantage: defense-related projects
 
*
This position is open to all candidates.
 
Show more...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8199034
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Herzliya
Job Type: Full Time
We are seeking a highly skilled and motivated Senior Security Researcher to join our dynamic team at our company. As a Senior Security Researcher, you will play a pivotal role in simulating real-world attack scenarios, identifying vulnerabilities, and contributing to the development of innovative security solutions. You will work alongside some of the best security experts in the industry, driving research initiatives and enhancing your knowledge of emerging threats and attack techniques.
Key Responsibilities:
Conduct in-depth research and analysis of n-day vulnerabilities to assess risk and potential impact.
Investigate attack vectors across various operating systems and cloud environments (IaaS/SaaS).
Define and document mitigation strategies for discovered attack techniques, collaborating with development teams for implementation.
Drive the integration of research findings into product features, ensuring enhanced security capabilities.
Stay abreast of the latest security trends, technologies, and best practices to maintain expertise in the field.
Collaborate with cross-functional teams to communicate and implement identified attacks, techniques, and solutions.
Contribute to public security research through blog posts and potentially present findings at industry conferences.
Requirements:
Qualifications:
A minimum of 5+ years of experience in security research, penetration testing, red teaming, or related fields.
Strong knowledge of adversary tactics, techniques, and procedures (TTPs).
Proficiency with common protocols (e.g., TCP/IP, HTTP, LDAP, Kerberos, RPC, SSL, SSH) and deep knowledge of Windows, Linux, or macOS internals.
Competence in programming languages such as C/C++, Java, TypeScript, or Python.
Demonstrated ability to manage and drive complex research projects independently and collaboratively.
Self-motivated, with a passion for continuous learning and professional development.
Preferred Qualifications:
Bachelors degree in Computer Science or equivalent experience (military background is a plus).
Familiarity with cloud platforms (AWS, GCP, Azure) and container orchestration systems like Kubernetes.
Experience with developing, extending, or modifying exploits, shellcode or exploit tools.
Reverse engineering skills, including familiarity with debuggers and disassemblers.
Relevant industry certifications such as OSCP, OSCE, OSWE, or similar credentials.
Experience in source code review to identify control flow and security vulnerabilities.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8210195
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/05/2025
Location: Tel Aviv-Yafo and Netanya
Job Type: Full Time
We are looking for an experienced Vulnerability Researcher to lead our world-class vulnerability research team.
As a Vulnerability Researcher Team Lead, you will perform research and responsible disclosure on the latest open-source software, working with your team to find flaws in the most popular components today. The position requires proven experience in vulnerability research, both on web applications and native applications.
As a Vulnerability Researcher Team Lead you will...
Research zero-day vulnerabilities in open-source projects and popular web applications
Manage a team of senior researchers, setting the teams research targets and methodologies
Manage the coordinated disclosure process for vulnerabilities identified by the team
Write & review technical blogposts for vulnerabilities identified by the team
Speak in the most important global security conferences about vulnerabilities identified by the team.
Requirements:
3+ years of vulnerability research experience in open-source projects
3+ years of vulnerability research experience in web applications
Experience in team management
Experience in writing technical vulnerability blogs
Advantage - Experience in binary reverse engineering.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8196740
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/05/2025
חברה חסויה
Location: Tel Aviv-Yafo and Netanya
Job Type: Full Time
We are looking for an experienced malware researcher to lead our malware research team.
As a Malware Research Team Lead, you will lead research on source code, compiled code, and various software supply chain attacks. The position requires proven experience in researching malicious code, understanding supply chain attack techniques, and experience in developing malware monitoring and analysis automation.
As a Malware Research Team Lead you will...
Lead a team of experienced malware researchers to discover malicious code in open source & new supply chain attack techniques
Research malicious code in public repositories from various coding languages and technologies
Define and implement ways to automatically detect malicious code in open-source software
Write technical reports and outward-facing publications regarding all research subjects mentioned above
Present your teams research in local and international security conventions.
Requirements:
Malware research experience in all of the following languages:
Python 3+ years
Node.JS 3+ years
Advantage Native code (C, C++), C#, Java, Go
Programming experience in Python
Experience in a managerial role
Experience in writing technical reports
Advantage Experience in binary reverse engineering
Advantage DevOps experience.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8197241
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/06/2025
Location: Herzliya
Job Type: Full Time and Hybrid work
We are looking for a talented Application Security and Secure Software Development Lifecycle (Secure-SDLC) Expert to lead our elite security researchers team. As an Application Security Leader, you will take an active role in leading various services including penetration testing and security development lifecycle activities that will help evaluate our customers security level and improve it. A typical job could be breaking into a segmented secure system at a Fortune 500 organization or perform a threat modeling process for a critical enterprise system.
Responsibilities:
Ensure customers security by hands-on penetration testing, hypothesizing threats, helping development teams remediate risks upfront, and executing secure implementation efforts
Escort, evaluate and improve the application security development lifecycle of our customers, including Secure-SDLC gap analysis, threat modeling and other related activities
Improve secure coding and Secure-SDLC practices, application security requirements, automation, training, and metrics
Lead the internal Secure-SDLC process of the R&D department in
Identify, communicate, and drive the resolution of vulnerabilities as an application security domain expert
Research and advocate for new application security solutions and technologies
Continue to drive security evaluation earlier in the cycles through iterative security testing
Requirements:
5+ years of experience in Application Security including penetration testing, deep understanding of major Application Security attacks, vulnerabilities, and mitigations including XSS, CSRF, SQL Injection, Deserialization, RCE, etc.
Experienced with Secure-SDLC methodologies and standards such as Microsoft SDL, OWASP SAMM, and OWASP ASVS
Experienced with threat analysis processes
Experienced with web & mobile application security, API analysis, and unique client/ server architectures
Experienced in code auditing and best practices
Deep understanding of OWASP Top 10 and CWE 25; with proven track record and experience in implementing and integrating remediation strategies
Managerial experience
Relevant certifications such as CEH and EWPTX an advantage
Hand-on proven experience in software development or familiarity with a vast range of high-level programming languages (Java, JS, Python, etc.) an advantage
Familiarity with cloud environments an advantage
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8200187
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
11/05/2025
חברה חסויה
Location: Herzliya
Job Type: Full Time
Required PRODUCT SECURITY TEAM LEADER
Responsibilities:
Manage and lead a team of product security engineers, overseeing daily operations and ensuring high-quality execution of product security assessments and projects.
Develop and execute the strategic roadmap for the team, aligning with the groups KPIs, organizational goals, and industry best practices.
Oversee post-production activities, tools, and procedures, such as penetration testing, WAF policies, and runtime protection policies, in advanced Kubernetes (k8s) environments, micro-services architectures, and cutting-edge CI/CD pipelines.
Manage the companys bug bounty programs, collaborating with external security researchers.
Plan, manage, and execute security projects, coordinating cross-functional teams to ensure timely and effective implementation of security initiatives.
Collaborate closely with software architects, security champions, and R&D teams to triage security findings and develop mitigation strategies.
Be responsible for monitoring and protecting the companys external attack surface by leading the design and development of internal (and our OSS) security tools and proprietary products. More about how we manage our attack surface: The Continuous Recon Mindset
Develop and conduct security training sessions for R&D and other departments to foster a strong security culture within the organization.
Lead incident response efforts, coordinating with the incident response team during security crises to ensure swift and effective resolution.
Promote continuous improvement in security methodologies, staying abreast of the latest trends and threats.
Ensure compliance with EU GDPR, CCPA, and other relevant standards by guiding technological compliance efforts.
Requirements:
4+ years of experience in web and mobile application security, SSDLC, and threat modeling.
Proven experience in leading and managing an application/product security team.
Strong background in planning, executing, and overseeing security projects within complex technological environments.
Extensive experience with Kubernetes (k8s), micro-services architectures, and CI/CD pipelines.
Experience in penetration testing, vulnerability scanning, SAST, and DAST, and familiarity with related tools and technologies.
Experience in managing bug bounty programs.
Excellent verbal and written communication skills to interact with diverse teams and present security findings and recommendations.
Experience in writing scripts and automations; OSS contributions are a major advantage.
Experience in conducting security training sessions and mentoring technical teams to enhance their security posture.
Understanding of EU GDPR, CCPA, and other relevant compliance standards, with the ability to guide technological compliance efforts.
Relevant security certifications (e.g., CISSP, OSCP, CEH) are highly desirable.
Strong leadership qualities with the ability to inspire and build a cohesive, high-performing security team.
Excellent problem-solving and critical thinking skills to address complex security challenges and implement effective solutions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8171340
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/05/2025
Location: Tel Aviv-Yafo and Netanya
Job Type: Full Time
The CSO Security team is looking for a Senior Application Security Researcher. In this role, you will perform vulnerability research, assess existing architectures, and build and run tools to secure the application landscape at scale. You will work closely with R&D and DevOps teams and be the focal point for identifying and solving complex security challenges. This is a hands-on, development-focused role with the goal of ensuring our products adhere to the stringent security requirements of our thousands of customers.
As a Senior Application Security Researcher you will
Continuously assess and challenge our overall security posture to ensure optimal and up-to-date platform security in our products and systems
Evaluate architecture, design, and code to ensure they are free from potential vulnerabilities and security risks
Train and mentor developers about security frameworks, testing, vulnerabilities, and best practices to ensure code compliance
Evaluate new technologies and standards in the application security domain
Plan and lead cross-company efforts with the R&D that will improve JFrogs security posture.
Requirements:
4+ years of hands-on experience in an application security role
Experience with Web Penetration Testing (Hands On) - Mandatory
Strong coding skills, preferably in Java, Golang, and JavaScript - Mandatory
Experience with cloud environments - an advantage
Experience with microservices (Docker, K8S, Service Mesh) - an advantage
Excellent problem-solving skills and the ability to work independently with a strong sense of ownership
Good communication skills and a true passion to educate others and achieve continuous improvement.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8197240
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/05/2025
חברה חסויה
Location: Herzliya
Job Type: Full Time
Required Security Researcher
As a Security Researcher, you will:
Be a part of the OPSEC department which is in charge of research, design, development and enforcement of advanced OPSEC solutions
Be in charge of the operational security research of a cyber intelligence product
Your role will include: Researching OS internals, deconstructing of applications, architecture reviews and red-team tests
Define product requirements, alert mechanisms, working procedures and more.
Requirements:
In-depth knowledge of Android OS Internals
At least 2 years of experience in one or more of the following areas: malware research, mobile forensics and vulnerability research
At least 2 years of hands-on experience with code analysis tools (both static and dynamic), such as: Frida, JADX, JEB or similar tools
Experience with evasion techniques and anti-RE techniques
Software development skills in at least one programming language: Java, C/C++, Python
B.Sc. in a technological field or a relevant IDF background
Ability to work independently and as a part of a team
It would be great if you also have:
Knowledge of Android app development
Experience with network analysis tools, such as: Wireshark/Fiddler/Burp.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8197319
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/06/2025
Location: Herzliya
Job Type: Full Time and Hybrid work
We're seeking an experienced CISO for a part-time, flexible consulting role to guide our security strategy and ensure best practices across development and infrastructure teams. This role also plays a key part in supporting our compliance initiatives.
Key Responsibilities:
Oversee and maintain security policies and processes
Advise application development teams on secure coding and architecture
Support infrastructure teams with secure configuration and best practices
Lead involvement in key compliance activities.
Requirements:
Proven experience as a CISO or senior security advisor in a SaaS or tech environment.
Deep knowledge of security frameworks (e.g., ISO 27001, SOC 2, NIST) and regulatory standards.
Hands-on experience with secure software development and DevSecOps practices.
Familiarity with cloud infrastructure security (AWS, Azure, or GCP).
Strong communication skills, with the ability to guide and influence technical and non-technical stakeholders.
Experience supporting internal and external audit processes.
Availability for flexible, part-time consulting .
Advantage: prior work with startups or fast-paced, high-growth environments
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8205145
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
11/05/2025
חברה חסויה
Location: Herzliya
Job Type: Full Time
we are looking for a creative and highly motivated Security Research Analyst to join the company's research team and work closely with the cyber research, data analytics, and product teams within the company.
As a Security Research Analyst you will research the automotive cyber security domain, and turn data into actionable information.
You will drive innovative Cyber ideas for the automotive industry, using cutting-edge tools and methodology, and have a major part in developing the next generation of security and knowledge management for the automotive industry.
This role is full-time and is based in Herzliya, Israel.
Responsibilities
Work with the product and analytics disciplines within the company.
Turning data into actionable information for data-driven decision making.
Research large scale and diverse automotive data sets.
Work closely with the engineering team and cyber research team to build our analytics solution.
Build an innovative security technology.
Research new technologies and adopt them for use in our companys product.
Requirements:
At least 3 years of experience as a Domain Data Analyst (cyber security - an advantage) or similar role from the cybersecurity industries.
Passionate about complex, data oriented, problem-solving.
Statistical knowledge and extensive analytical skills with experience in using statistics for analyzing datasets
Python or similar knowledge - an advantage
SQL skills with experience in querying large, complex data sets- advantage.
A team player with excellent collaboration skills and ability to communicate with both business and technical counterparts.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8171281
סגור
שירות זה פתוח ללקוחות VIP בלבד