Security Researcher

1 week ago


Tel Aviv, Tel Aviv, Israel Element Security Full time ₪90,000 - ₪120,000 per year

About Element Security

Element Security is a leader in external attack surface security. Our CTEM platform continuously validates real risk by executing safe, controlled exploitation to surface high-impact exposures that truly matter.

Job Description

We are hiring a Security Researcher with deep web application expertise to design and maintain attack modules for our exploitation engine. You'll turn cutting-edge research into reliable, production-grade modules that identify and validate real exposures across modern web stacks.

What You'll Do

  • Build attack modules for web apps, APIs, and services (REST, GraphQL, WebSockets, gRPC).
  • Encode exploitation logic for authN/authZ flaws, JWT/OAuth/OIDC/SAML, CSRF/CORS, SSRF, SQLi/NoSQLi, XSS, template injection, deserialization, path traversal, file upload, command injection, IDOR/BOLA, race conditions, and misconfigurations (general app and cloud-native).
  • Implement safe, idempotent exploitation with guardrails (timeouts, rate limits, retries, target capability checks, rollbacks).
  • Research and track new CVEs, techniques, and exploit chains; convert findings into reusable module templates and signatures.
  • Collaborate with Platform/R&D to integrate modules (module framework, data models, telemetry) and ship via CI/CD.
  • Write clear docs and PoCs, plus unit/integration tests and module simulations.
  • Contribute to threat intelligence: enrichment logic, fingerprinting, version/parsing heuristics.
  • Triage and validate platform-discovered vulnerabilities with reproducible evidence.

Required Qualifications

  • 3+ years in web app security, offensive research, or application pentesting.
  • Strong web-app exploitation tooling experience in Python 3 or another modern language (Go/Rust/Ruby), and a commitment to write production Python day-to-day.
  • Deep understanding of HTTP, sessions/cookies, TLS, proxies, API auth (OAuth/OIDC/JWT), SSO, and modern app architectures (SPAs, microservices).
  • Familiarity with OWASP Top 10, API Security Top 10, and practical exploitation/mitigation paths.
  • Experience with pentest tooling (e.g., Burp Suite, Nmap) and turning manual techniques into automated checks.
  • Comfortable in Linux/Docker, Git workflows, and basic CI (e.g., GitHub Actions).
  • Excellent written communication for module docs and reproduction steps.

How You Work

  • Pragmatic researcher who can productize exploits with clean, testable code.
  • Bias to safety and reliability: noisy vs. stealthy tradeoffs, sandboxing, and target impact minimization.
  • Curious, collaborative, and comfortable moving between research spikes and steady module delivery.
  • Ethical by default: you respect boundaries and legal frameworks.

What You'll Work On

  • Internal module framework and templates
  • Advanced exploitation workflows for modern web apps and APIs
  • Observability (metrics, traces, evidence artifacts)
  • Continuous delivery of modules to production customers

  • Security Researcher

    6 days ago


    Tel Aviv, Tel Aviv, Israel Astrix Security Full time ₪60,000 - ₪120,000 per year

    We're looking for a passionate and curiousSecurity Research Studentto join our Research team at Astrix. This is a unique opportunity to explore cutting-edge technologies in the emerging domain ofNon-Human Identity (NHI) Security, working alongside experienced researchers in cybersecurity, cloud, and AI.About the role:Conduct in-depth security research on...

  • Security Researcher

    6 days ago


    Tel Aviv, Tel Aviv, Israel Astrix Security Full time ₪60,000 - ₪80,000 per year

    We're looking for a passionate and curious Security Research Student to join our Research team at Astrix. This is a unique opportunity to explore cutting-edge technologies in the emerging domain of Non-Human Identity (NHI) Security, working alongside experienced researchers in cybersecurity, cloud, and AI. About the roleConduct in-depth security research on...

  • Security Researcher

    2 days ago


    Tel Aviv, Tel Aviv, Israel Oligo Security Full time ₪90,000 - ₪120,000 per year

    About UsOligo is a rapidly growing startup headquartered in Tel Aviv, leading the way in reshaping Application Security. With a strong investment from top-tier VCs including Greenfield Partners, Red Dot Capital Partners, Lightspeed, Ballistic Ventures, and TLV Partners, we are developing a unique solution to address application security challenges, mainly...

  • Security Researcher

    2 days ago


    Tel Aviv, Tel Aviv, Israel Upwind Security Full time $150,000 - $200,000 per year

    DescriptionUpwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools, Upwind uses runtime data proactively for risk prioritization and posture insights, ensuring teams focus on what truly matters....


  • Tel Aviv, Tel Aviv, Israel Salt Security Full time ₪90,000 - ₪120,000 per year

    About us:Salt Security is a leading cybersecurity company dedicated to providing innovative solutions that protect organizations from API-related security threats. Our comprehensive platform helps businesses identify, monitor, and protect their APIs from vulnerabilities, ensuring the security and integrity of their digital assets. With a focus on...


  • Tel Aviv, Tel Aviv, Israel Upwind Security Full time ₪90,000 - ₪120,000 per year

    DescriptionUpwind is the runtime-powered CNAPP that leverages runtime data to secure our customers' cloud infrastructure. Upwind's holistic approach to cloud security helps organizations mitigate the risks that actually matter, identify the root causes of threats in minutes and respond with context and automation. Upwinders are spread across the globe in all...


  • Tel Aviv, Tel Aviv, Israel LayerX Security Full time ₪120,000 - ₪240,000 per year

    As the Security Research Team Lead, you will head a team of researchers focused on web security, browser internals, AI security, AI browsers, and DLP attack paths. You will be responsible for designing research methodologies, driving innovation, and ensuring our findings feed directly into product improvements, customer protection, and industry thought...

  • Security Researcher

    2 weeks ago


    Tel Aviv, Tel Aviv, Israel Microsoft Full time ₪120,000 - ₪240,000 per year

    Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified...

  • Security Researcher

    1 week ago


    Tel Aviv, Tel Aviv, Israel SAM Seamless Network Full time ₪104,000 - ₪130,878 per year

    About the Role:We are seeking an experienced and curious Network & Security Researcher to join our growing teamIn this role, you'll dive deep intonetwork traffic analysis, cyber-attack techniques, and IoT vulnerabilities, developing advanced detection methods and firewall policies that protect millions of connected devices worldwide.This is an exciting...

  • Security Researcher

    2 weeks ago


    Tel Aviv, Tel Aviv, Israel NSO Group Full time ₪90,000 - ₪120,000 per year

    NSO Group provides vetted government agencies with cutting-edge technological solutions designed to prevent and investigate terrorism and crime. We are constantly exploring new technologies to address the next challenge in this dynamic, ever-changing market. Want to join us in making a difference (and have a lot of fun along the way)? Apply nowAs a Security...