Threat Researcher
Conduct end-to-end security research on emerging threats, CVEs, misconfigurations, and cloud attack surfaces, then turn findings into scalable detection capabilities. Requires at least five years of security research or related experience, strong scripting skills, and expertise in network and application security.
About the job
Responsibilities
- Research emerging threats, CVEs, and misconfigurations to assess real-world exploitability and customer impact.
- Design, build, and test detection rules and scanning logic for exposed and vulnerable assets.
- Build automations to validate, benchmark, and monitor AI-driven detection capabilities at scale.
- Investigate cloud services, frameworks, and commonly deployed technologies to uncover new attack surfaces.
- Analyze large-scale scan results to identify and prioritize meaningful risks.
- Drive research projects end-to-end, from initial idea to production-ready detection.
- Collaborate with Product and R&D teams to transform research findings and attack methodologies into product capabilities.
Requirements
- 5+ years of hands-on experience in security research, red-teaming, penetration testing, incident response, or vulnerability research.
- Strong understanding of network and application security, including TCP/IP, DNS, TLS, web technologies, modern APIs, and application- and network-layer exploitation techniques.
- Strong scripting and automation skills using Python, Bash, or equivalent.
- Experience developing, customizing, using, or researching vulnerability scanners, including DAST, SAST, network, or host scanners.
- Experience writing detection rules or building automated vulnerability and exploitability validation tools.
- Ability to independently lead projects from research through delivery.
- Strong writing and presentation skills in English and Hebrew.
Preferred Qualifications
- Experience developing or researching cloud environments such as AWS, Azure, or Google Cloud.
- Familiarity with security aspects of Kubernetes, containers, and CI/CD.
- Familiarity with AI-assisted development tools such as Claude Code or similar.
- Familiarity with Burp Suite, nmap, Metasploit, Nuclei, or similar scanning tools.
- Published security research, exploits or proof-of-concepts, or contributions to open-source security tooling.
Skills
Python, Bash, TCP/IP, DNS, Tls, Web Security, Api Security, Vulnerability Scanning, DAST, SAST, Cloud Security, Kubernetes, Burp Suite, Nmap, Metasploit
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Leads information security governance, compliance, security operations, risk management, and incident response for a healthcare AI company. Requires 5+ years of security experience and hands-on expertise with major compliance frameworks, SIEM, incident response, and third-party risk.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.