Security Researcher
Description About the Position OX Security is securing the AI-driven SDLC from prompt to production. We’re building the next generation of security technology for a world where AI is changing how software is built, deployed, and attacked. We’re looking for a highly skilled Security Researcher to join our Security Research group and help us discover, investigate, and build new ways to identify and understand security risks across modern applications and infrastructure. This is a hands-on research and engineering role. You’ll investigate how real-world systems can be attacked, explore new attack techniques, develop proof-of-concepts, and turn your research into production-grade capabilities used to detect and prioritize real security risks at scale. You’ll work closely with security researchers, software engineers, AI and data scientists, and product teams to solve complex problems at the intersection of security research, automation, and AI. If you enjoy taking an idea from "What if?" to a working POC to a production capability, this role is for you. Responsibilities What You'll Be Doing Research and investigate new attack techniques, vulnerabilities, and security weaknesses across modern applications and infrastructure Analyze complex attack scenarios and identify how vulnerabilities can be chained into meaningful attack paths Develop proof-of-concepts, exploits, and research tools to validate security hypotheses Build detection engines and automated security capabilities based on your research Explore ways to use application, code, cloud, and runtime context to identify real-world security risks Prototype and turn research ideas into scalable, production-ready security capabilities Analyze large-scale security data to identify patterns, attack opportunities, and emerging threats Collaborate closely with Engineering, Product, AI, and Data teams to bring research into the product Contribute to the research direction and technical strategy of the Security Research group Stay ahead of emerging vulnerabilities, attack techniques, and changes in the modern software development landscape Requirements What We're Looking For 4+ years of experience in security research, application security, vulnerability research, penetration testing, red teaming, or a related field Strong understanding of common application and infrastructure vulnerabilities and exploitation techniques Experience investigating vulnerabilities and understanding how they can be exploited in real-world environments Strong programming skills and the ability to build scripts, tools, and proof-of-concepts Experience with code-level analysis and modern software development stacks Ability to independently investigate complex technical problems and turn findings into practical solutions Strong understanding of how modern applications and infrastructure work - and how they can break Ability to communicate complex technical concepts clearly A curious, creative, and highly hands-on mindset Ability to thrive in a fast-paced startup environment and work effectively with cross-functional teams The DNA We're Looking For Researcher at heart: You enjoy going down the rabbit hole to understand how things actually work Builder: You don't stop at identifying a problem - you build the tools and capabilities to solve it Curious by default: You constantly ask "what if?" and explore unconventional ways systems can fail Systems thinker: You understand how vulnerabilities, applications, infrastructure, and environments connect Pragmatic: You know how to turn deep technical research into something useful and scalable Ownership-driven: You are comfortable with ambiguity and take initiative to define the path forward Bonus Points For Experience with vulnerability research or exploit development Experience with bug bounty programs or independent security research Experience publishing technical security research, blogs, CVEs, or conference talks Strong software engineering background Experience with cloud security, Kubernetes, or modern infrastructure Experience with LLMs, AI agents, or security automation Familiarity with DevSecOps and modern application security tools Experience building security products or research platforms
מצאו את המשרה הבאה שלכם בלוח הדרושים של ישראל.
כל המשרות