Security Researcher
פורסם 15 ביוני · 0 מועמדים
התפקיד במילים פשוטות
התפקיד כולל מחקר מעמיק של חולשות אבטחה ו-CVEs, ניתוח גורמי שורש ווקטורי תקיפה כדי להזין את פלטפורמת המניעה מבוססת ה-AI של החברה. החוקר יבצע הנדסה לאחור באמצעות כלים כמו IDA Pro או Ghidra ויחקור מנגנוני מערכת מורכבים ברמת ה-kernel, רשתות ומערכות הפעלה. התובנות מהמחקר יוטמעו במהירות במוצר כדי למנוע חולשות אבטחה בקונטיינרים באופן יזום.
- 5+ years of experience in security research with focus on vulnerability analysis and exploitation
- IDA Pro
- Ghidra
- Jeb
- Deep knowledge of complex low-level system mechanisms (kernel, networking, services, operating systems, embedded systems)
- Record of public research contributions (CVEs discovered, technical write-ups, conference talks, or open-source security projects)
- Experience working with AI tools and methodologies in security research contexts
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
תפקיד זה מתאים לחוקרי אבטחה מנוסים עם לפחות 5 שנות ניסיון בניתוח חולשות והנדסה לאחור, בעלי הבנה עמוקה במערכות הפעלה ורשתות. הוא פחות יתאים למי שאין לו ניסיון מעשי נרחב בכלי reverse engineering או רקע טכני נמוך-מפלס (low-level).
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןAt echo, we’re fixing a broken system. Vulnerability management isn't working – it’s reactive, noisy, and unsustainable. Instead of chasing CVEs, we’re eliminating them at the source.
Our AI-powered platform produces vulnerability-free base images that integrate cleanly into existing workflows, helping security and platform teams eliminate patching overhead without slowing down developers. Backed by top-tier investors and led by second-time founders who previously built the first software supply chain security company, which was later acquired by Aqua Security, we’ve gone from stealth to serving global enterprise customers in under six months.
We're now looking for an experienced Security Researcher to join our core team and deep dive into CVEs, conducting cutting-edge vulnerability research that directly powers Echo's revolutionary approach to eliminating container vulnerabilities at the source.
What You’ll Do
• Conduct deep-dive research into CVEs and vulnerabilities, analyzing root causes and attack vectors to inform our AI-powered prevention platform
• Perform reverse engineering analysis using tools like IDA Pro, Ghidra, or similar platforms to understand complex security vulnerabilities and exploitation techniques
• Research and analyze complex low-level system mechanisms including kernel vulnerabilities, network security issues, and operating system weaknesses
• Think outside the box, challenge existing assumptions, and create innovative approaches to vulnerability research and prevention
• Work in a unique environment where your research insights are rapidly implemented into our product, creating direct real-world impact from your vulnerability research
• Contribute to Echo's technical knowledge base and help establish new methodologies for proactive vulnerability identification and mitigation
Requirements
Requirements:
• 5+ years of experience in security research with focus on vulnerability analysis and exploitation
• Extensive hands-on experience with reverse engineering tools (IDA, Ghidra, Jeb, or similar)
• Proven experience working with CVEs, and the broader security research domain
• Deep knowledge of complex low-level system mechanisms (kernel, networking, services, operating systems, embedded systems)
• Excellent written and verbal communication skills with ability to present complex technical findings
• Innovative mindset with ability to think outside the box and challenge conventional approaches
Preferred
• Record of public research contributions (CVEs discovered, technical write-ups, conference talks, or open-source security projects)
• Experience working with AI tools and methodologies in security research contexts
• Background in container security, supply chain security, or related domains
Why echo?
We're a fast-growing team composed of some of the coolest and most passionate people you'll meet, solving hard problems that really make a difference. You’ll have real ownership and a clear mission: to make cloud-native infrastructure secure by design.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 5+ years of experience in security research with focus on vulnerability analysis and exploitation, IDA Pro, Ghidra, Jeb, Deep knowledge of complex low-level system mechanisms (kernel, networking, services, operating systems, embedded systems)