Pentest Product Associate
Join a cloud security product team as the primary operator of an AI-driven Dynamic Application Security Testing agent. Develop detection and attack logic, validate complex findings, research emerging threats, and help shape product improvements for cloud-native environments.
Responsibilities
- Develop detection algorithms for cloud technologies
- Define and tune attack policies for automated security agents
- Analyze cloud services, APIs, and log payloads to validate complex attack paths
- Reduce false positives and support compliance with industry standards
- Research emerging cloud and API attack vectors
- Translate new threat techniques into executable behaviors for a DAST engine
- Collaborate with research, backend, and R&D teams on product improvements
Requirements
- At least 2 years of hands-on application security or penetration testing experience
- Proficiency with penetration testing tools such as Burp Suite, OWASP ZAP, or Acunetix
- Knowledge of networking concepts, the OSI model, and AWS, Azure, or GCP infrastructure
- Hands-on experience with Linux, Windows, Docker, and Kubernetes
- Strong knowledge of HTTP/S, REST, GraphQL, OAuth, and SAML
- Scripting proficiency in Python, Bash, or Go
- Ability to analyze logs and scans and distinguish tool failures, configuration issues, and valid security findings
- Ability to communicate complex security concepts and collaborate across teams
- Legal authorization to work in Israel without visa sponsorship
Nice to have
- Knowledge of AI/ML, LLMs, or reinforcement learning agents in cybersecurity
- Experience with SaaS, cloud environments, and cloud-native architectures
- Red teaming experience, including simulated adversarial attacks and bypassing WAF or other security controls