Offensive Security Researcher
Description OX Security is securing the AI-driven SDLC from prompt to production. We’re building the next generation of security technology for a world where AI is changing how software is built, deployed, and attacked. We’re looking for an experienced Offensive Security Researcher to join our Security Research group and help us rethink how offensive security can be performed at scale. This is not a traditional pentesting role. You’ll go beyond finding vulnerabilities. You’ll research how real-world attackers think and operate, discover ways to chain vulnerabilities and misconfigurations, develop novel attack techniques, and help build automated agentic systems that can continuously simulate attacks against modern applications and infrastructure. You’ll work at the intersection of offensive security, application security, exploit development, automation, and AI - building the next generation of autonomous and agentic pentesting capabilities. If you enjoy breaking complex systems, finding unexpected attack paths, and building tools that can do it repeatedly and at scale, this is the role for you. Responsibilities What You'll Be Doing Conduct advanced offensive security research across modern applications, APIs, cloud environments, and infrastructure Identify and exploit vulnerabilities, misconfigurations, logic flaws, and weaknesses across complex systems Research and develop novel attack techniques and exploitation methods Discover and demonstrate multi-step attack chains and real-world attack paths Develop proof-of-concepts, exploits, and automated offensive security tools Build automated attack capabilities that can discover and validate exploitable vulnerabilities at scale Research how attackers can move from individual vulnerabilities to meaningful business impact Work with application, code, cloud, and runtime context to simulate realistic attack scenarios Prototype and ship offensive security & agentic capabilities into production Collaborate closely with Engineering, Product, AI, and Data teams to build next-generation security capabilities Contribute to the development of OX's autonomous and agentic pentesting technology Stay current with emerging exploitation techniques, offensive tooling, and real-world attack trends Requirements What We're Looking For 4+ years of experience in offensive security, penetration testing, red teaming, application security, or vulnerability research Strong hands-on experience identifying and exploiting vulnerabilities in modern applications and infrastructure Deep understanding of web application security, APIs, authentication, authorization, and common attack techniques Strong knowledge of OWASP Top 10 and modern exploitation techniques Experience with vulnerability chaining and identifying complex attack paths Strong programming and scripting skills, with the ability to build offensive security tools and proof-of-concepts Ability to understand code and modern software architectures from an attacker's perspective Strong understanding of how modern applications and cloud environments can be attacked Ability to independently investigate complex systems and find creative ways to break them Strong communication skills and the ability to explain technical findings clearly A hands-on, curious, and highly technical mindset The DNA We're Looking For Attacker mindset: You naturally think about how a system can be abused, bypassed, or broken Builder-breaker: You enjoy both finding vulnerabilities and building the tools to exploit and automate them Creative attacker: You look beyond known vulnerabilities and find unconventional attack paths Scale-oriented: You’re excited by the idea of turning a manual offensive technique into an automated, agentic capability Systems thinker: You understand how seemingly small weaknesses can combine into a real attack Fearless investigator: You enjoy complex, ambiguous problems where there is no obvious answer Ownership-driven: You take initiative, experiment quickly, and push ideas from research to production Bonus Points For Experience with red teaming or advanced penetration testing Experience with exploit development Experience with bug bounty programs Experience with CTFs or competitive security research Experience with offensive security tooling and automation Experience attacking cloud environments, Kubernetes, or modern infrastructure Experience with LLMs, AI agents, or autonomous systems Experience researching real-world attack techniques or publishing technical research and CVEs Strong software engineering background
מצאו את המשרה הבאה שלכם בלוח הדרושים של ישראל.
כל המשרות