# Pentest Product Associate

**Company:** [Wiz](https://hotfix.jobs/companies/wiz)
**Location:** Tel Aviv, Israel
**Role:** Security Engineering
**Experience:** 2+ years
**Skills:** Application Security, Penetration Testing, Burp Suite, Owasp Zap, Acunetix, AWS, Azure, GCP, Linux, Docker, Kubernetes, Python, Bash, Go, GraphQL
**Posted:** 2026-07-02

> This product-focused security role operates an AI-driven DAST agent, develops cloud-native detection and attack logic, validates complex findings, and researches emerging threats. It requires at least two years of application security or penetration-testing experience plus strong cloud, web, scripting, and security-tool expertise.

## Job Description

## Responsibilities
- Develop advanced detection algorithms to classify cloud technologies and fine-tune attack policies for identifying and exploiting vulnerabilities.
- Analyze cloud services, APIs, and log payloads to validate complex attack paths, reduce false positives, and support compliance with industry standards.
- Research novel attack vectors and emerging cloud/API threats, translating new techniques into executable behaviors for a DAST engine.
- Collaborate with Research, Backend, and R&D teams to turn operational insights into product features.

## Requirements
- 2+ years of hands-on experience in application security or penetration testing.
- Proficiency with enterprise security tools such as Burp Suite, OWASP ZAP, or Acunetix.
- Knowledge of networking concepts, the OSI model, and cloud infrastructure such as AWS, Azure, or Google Cloud.
- Hands-on experience with Linux, Windows, Docker, Kubernetes, web protocols, and authentication mechanisms.
- Strong command of HTTP/S, REST, GraphQL, OAuth, and SAML.
- Proficiency in Python, Bash, or Go for automating security tasks and interacting with codebases.
- Ability to diagnose complex logs and scans and distinguish tool failures, configuration issues, and valid security findings.
- Self-motivated, collaborative, and able to communicate high-stakes security concepts effectively.

## Nice-to-haves
- Knowledge of AI/ML, LLMs, or reinforcement-learning agents in cybersecurity.
- SaaS and cloud experience with modern cloud-native architectures.
- Red-team experience, including simulated adversarial attacks and bypassing WAFs or other security controls.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Threat Researcher](https://hotfix.jobs/jobs/bb443443-936e-4115-b157-d05e093e19f1) - Wiz - Tel Aviv, Israel
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Information Security Manager](https://hotfix.jobs/jobs/ccc96673-5cad-40d0-a14b-bc1844e083a6) - Viz.ai - Tel Aviv, Israel
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr

**Apply:** https://hotfix.jobs/jobs/f2ab6e71-3472-40a8-bb5f-f21735badb98
**Canonical:** https://hotfix.jobs/jobs/f2ab6e71-3472-40a8-bb5f-f21735badb98