Offensive Cyber Security Researcher

1 week ago


Israel Novartis Full time ₪120,000 - ₪180,000 per year

Job Description Summary

Location: Tel Aviv, Israel; #LI-Hybrid (12 days/month in office)

The role is based in Tel Aviv. Novartis is unable to offer relocation support for this role: please only apply if this location is accessible for you.

About the Role:

The Offensive Cyber Security Researcher will join a newly established Think Tank of advanced security researchers responsible for continuously challenging Novartis' information security defenses, application security posture, and data protection capabilities.

In this role, the researcher will take a true attacker-focused perspective, analyzing Novartis' infrastructure, identity systems, and business applications as a sophisticated adversary would. This includes conducting deep vulnerability research, exploring innovative infiltration and exfiltration techniques, mapping attack paths, and developing realistic breach scenarios that reflect modern threat actor behavior.

The researcher will proactively identify and evaluate weaknesses, related exploits, and attack vectors, translating offensive insights into actionable defensive recommendations that improve Novartis' overall security resilience.


 

Job Description

Key Responsibilities:  

  • Proactively identify gaps and vulnerabilities in Novartis systems and architectures, and validate possible exploitation by defining the most likely threat actors and required capabilities.
  • Design and develop tools, frameworks, and the methods required for facilitating and executing complex attacks and emulating adversarial tactics, techniques and procedures (TTPs).
  • Conduct deep-dive research into AD, Entra ID, and hybrid identity attack surfaces.
  • Develop and maintain cutting-edge techniques for privilege escalation, credential compromise, session hijacking, lateral movement, and domain dominance.
  • Track emerging identity-related threats, TTPs, attack paths, and novel exploitation techniques
  • Provide in-depth technical analysis of computer networks applications and systems, culminating in the identification of existing potential vulnerabilities.
  • Collaborate with engineering teams to test for and prevent threats to Novartis Networks infrastructure and data, and work closely with the Threat Hunters and Intelligence teams to help improve the team's abilities in Detection, Prevention and Response capabilities.
  • Maintain up-to-date awareness of computer network exploitation and attack tools, threats and vulnerabilities and respective counter/mitigation measures.
  • Assist with security investigations, root-cause analysis and corrective measures as required.
  • Design and execute realistic attack simulations against enterprise identity systems to validate detection, controls, and architectural design.
  • Compose Red Team test reports and record vulnerability data according to Governance, Risk, and Compliance processes.
  • Deliver technical debriefs to engineers and developers as needed, and work with IS&RM managers to prioritize vulnerability findings for remediation.
  • Mentor and train Novartis IS&RM employees in attack techniques, intelligence analysis and adversarial tactics

Essential Requirements:

  • Education: BA or BSc in Computer Science or a related field, or comparable work experience
  • 5+ Years experience in Security Research, Web-Application & Network Penetration Testing or adjacent fields.
  • Experience in Software development with proficiency in multiple languages, mainly C/C++  and other object-oriented platforms. Experience with scripting languages such as Python/Perl/Ruby.
  • Expertise with reverse engineering tools (e.g. disassemblers, debuggers, instrumentation frameworks, etc.).
  • Ability to understand and apply attack and penetration concepts including the attack surface; identification of system software and configuration vulnerabilities and critical information, data and processes that must be protected.
  • Basic understanding of concepts in vulnerability research: Shellcode, ROP, ASLR, exploit types, and heap manipulation;  Experience in IOT and Industrial Controls Systems.
  • Ability to manage new and existing security requirements, help with training personnel, and implement control and risk procedures to ensure all operations are conducted in accordance of Novartis networks standards.
  • Very strong team and interpersonal skills along with sense of ownership, and the ability to work independently and achieve individual goals; ability to collaborate and coordinate with other team members to achieve the specified objectives; excellent communication skills

Commitment to Diversity & Inclusion:

We are committed to building an outstanding, inclusive work environment and diverse teams representative of the patients and communities we serve.

Why Novartis?
Our purpose is to reimagine medicine to improve and extend people's lives and our vision is to become the most valued and trusted medicines company in the world. How can we achieve this? With our people. It is our associates that drive us each day to reach our ambitions. Be a part of this mission and join us Learn more here:

Join our Novartis Network: If this role is not suitable to your experience or career goals but you wish to stay connected to learn more about Novartis and our career opportunities, join the Novartis Network here:

Accessibility and accommodation:
Novartis is committed to working with and providing reasonable accommodation to all individuals. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the recruitment process, or in order to receive more detailed information about the essential functions of a position, please send an e-mail to and let us know the nature of your request and your contact information. Please include the job requisition number in your message.


 

Skills Desired

Communication Skills, Cyber-Security Regulation, Cyber Threat Hunting, Cyber Threat Intelligence (Cti), Cyber Threat Management, Cyber Vulnerabilities, Decision Making Skills, Influencing Skills, Information Security Risk Management

  • Israel Novartis Full time ₪120,000 - ₪180,000 per year

    BandLevel 5Job Description SummaryLocation: Tel Aviv, Israel; #LI-Hybrid (12 days/month in office) The role is based in Tel Aviv. Novartis is unable to offer relocation support for this role: please only apply if this location is accessible for you.About the Role:The Offensive Cyber Security Researcher will join a newly established Think Tank of advanced...


  • Israel Novartis Full time ₪72,000 - ₪300,000 per year

    SummaryLocation: Tel Aviv, Israel; #LI-Hybrid (12 days/month in office)The role is based in Tel Aviv. Novartis is unable to offer relocation support for this role: please only apply if this location is accessible for you. About the Role: The Offensive Cyber Security Researcher will join a newly established Think Tank of advanced security researchers...

  • Security Researcher

    1 week ago


    Tel Aviv, , Israel Echo Full time ₪120,000 - ₪180,000 per year

    At echo, we're fixing a broken system. Vulnerability management isn't working – it's reactive, noisy, and unsustainable. Instead of chasing CVEs, we're eliminating them at the source.Our AI-powered platform produces vulnerability-free base images that integrate cleanly into existing workflows, helping security and platform teams eliminate patching overhead...


  • Tel Aviv-Yafo, Gush Dan, Israel At-Bay Full time ₪120,000 - ₪180,000 per year

    About At-BayAt-Bay is a fast-growing InsurSec company (Insurance x Cybersecurity) on a mission to bring innovative products to the market that help protect small businesses from digital risks. As an InsurSec provider, we uniquely combine insurance with mission-critical security technologies, threat intelligence, and human expertise to bridge the critical...


  • Hamerton House - Aharon Bart St., Bldg. B rd Floor, Petah Tikva, Israel ServiceNow Full time ₪120,000 - ₪180,000 per year

    Company Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500. Our intelligent cloud-based...


  • Tel Aviv/ Netanya, Israel JFrog Full time ₪80,000 - ₪150,000 per year

    At JFrog, we're reinventing DevOps to help the world's greatest companies innovate – and we want you along for the ride. This is a special place with a unique combination of brilliance, spirit and just all-around great people. Here, if you're willing to do more, your career can take off. And since software plays a central role in everyone's lives, you'll...


  • Ramat Gan, Tel Aviv District, , Israel ActiveFence Full time $80,000 - $120,000 per year

    About the positionAs a Red Team Specialist focused on Generative AI Models, you will play a critical role in enhancing the security and integrity of our cutting-edge AI technologies.Your primary responsibility will be to conduct analysis and testing of our generative AI systems, including but not limited to language models, image generation models, and any...

  • sdr

    2 weeks ago


    Israel Waterfall Security Full time $60,000 - $120,000 per year

    Job Position: Sales Development Representative (SDR)-SingaporeAbout Since 2007, Waterfall Security Solutions has been providing the highest level of protection for critical infrastructure and vital industries. With headquarters in Israel and offices in UAE, Singapore, USA, Europe, and Australia, Waterfall delivers the highest level of OT protection while...


  • Israel Commvault Full time ₪60,000 - ₪120,000 per year

    Recruitment Fraud AlertWe've learned that scammers are impersonating Commvault team members—including HR and leadership—via email or text. These bad actors may conduct fake interviews and ask for personal information, such as your social security number.  What to know:Commvault does not conduct interviews by email or text.We will never ask you to...

  • ML Engineer

    6 days ago


    Israel Cynet Full time ₪120,000 - ₪240,000 per year

    Shape the Future of Cybersecurity with UsAre you driven by curiosity, innovation, and the desire to turn cutting-edge research into real-world impact?Join Cynet, an established but rapidly growing cybersecurity startup, where you'll be part of a small, elite team building groundbreaking AI-powered security products from the ground up. Work alongside top...