Cloud Security Researcher
פורסם 28 ביוני · 0 מועמדים
התפקיד במילים פשוטות
התפקיד כולל ביצוע מחקר מעשי בסביבות ענן מרכזיות כמו AWS, GCP ו-Azure, במטרה לחשוף פגיעויות מורכבות, חולשות ארכיטקטוניות וליקויים בבקרות ענן. החוקר יזהה ויאמת פגיעויות בארכיטקטורות ענן מקוריות, ינתח כשלים ב-IAM, שגיאות לוגיקה ב-API, ויבצע ניתוח שורש של ניצולים תיאורטיים וקיימים.
- 4+ years of hands-on experience in offensive security research, vulnerability research, red teaming, or cloud security engineering
- Strong practical knowledge of at least one major cloud provider: AWS, GCP, or Azure
- Experience researching or exploiting vulnerabilities in serverless compute, VMs, or cloud APIs
- Strong understanding of cloud defense methodologies and tools, including IAM policies, VPC, virtualization defense, CSPM, and CDR
- Experience developing in C, C++, or Rust
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים למועמדים בעלי ניסיון של 4+ שנים במחקר אבטחה התקפי, מחקר פגיעויות, Red Teaming או הנדסת אבטחת ענן, עם ידע מעשי חזק בלפחות ספק ענן מרכזי אחד. הוא פחות מתאים למי שאין לו ניסיון בפיתוח ב-C, C++ או Rust, או הבנה חזקה של מתודולוגיות וכלים להגנת ענן.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןI’m recruiting for a high-end cyber security research and R&D company founded by senior Israeli security researchers.
The company works with highly technical enterprise and government clients, helping them build secure products through advanced security research, architecture design, and low-level development across a wide range of technologies.
We are looking for a talented Cloud Security Researcher to join the Cloud Security team and take a key role in shaping offensive research around mission-critical cloud infrastructure, managed services, and cloud-native environments.
In this role, you will conduct hands-on research across major cloud providers such as AWS, GCP, and Azure, uncovering complex vulnerabilities, architectural weaknesses, IAM flaws, API logic issues, runtime escapes, and gaps in cloud control planes.
What you’ll do
• Research cloud environments, including VMs, serverless technologies, APIs, managed services, and cloud infrastructure
• Identify and validate vulnerabilities across cloud-native architectures
• Analyze IAM flaws, API logic errors, runtime escapes, and cloud service weaknesses
• Audit managed services and distributed systems
• Perform root cause analysis on theoretical and discovered exploits
• Think offensively to model advanced threat scenarios and build stronger defenses
• Design detection rules and strategies for subtle indicators of compromise within cloud control planes
• Translate research findings into stronger, more secure infrastructure-level mitigations
What you need
• 4+ years of hands-on experience in offensive security research, vulnerability research, red teaming, or cloud security engineering
• Strong practical knowledge of at least one major cloud provider: AWS, GCP, or Azure
• Experience researching or exploiting vulnerabilities in serverless compute, VMs, or cloud APIs
• Strong understanding of cloud defense methodologies and tools, including IAM policies, VPC, virtualization defense, CSPM, and CDR
• Experience developing in C, C++, or Rust
• Strong focus on accuracy of security controls and systemic architectural improvements
• Ability to work in a fast-paced, agile environment
• Strong communication skills in Hebrew and English
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 4+ years of hands-on experience in offensive security research, vulnerability research, red teaming, or cloud security engineering, Strong practical knowledge of at least one major cloud provider: AWS, GCP, or Azure, Experience researching or exploiting vulnerabilities in serverless compute, VMs, or cloud APIs, Strong understanding of cloud defense methodologies and tools, including IAM policies, VPC, virtualization defense, CSPM, and CDR, Experience developing in C, C++, or Rust