כדי לראות תפקידים מתאימים עליך להוסיף כישורים בפרופיל האישי במערכת COB.
ההרשמה והשימוש חינם!
מעולה, רוצה להירשם

Senior Security Specialist|אבטחת מידע וסייבר|ניהול ביניים
פתח תקווה
היברידי
רמת שכר
20,000
פורסם לפני 2 חודשים
פורסמה ברשת
We seek a Senior Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.
The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.
As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.
Key Responsibilities:
Triage and Resolve Bug Bounty Reports:
Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition.
Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed.
Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues.
Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom.
Propose remediations, or design them with engineering, and verify the fix resolves the issue.
Assign and defend severity ratings using the program's severity framework.
Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure.
Own Researcher and Stakeholder Communication:
Act as our primary technical point of contact for bug bounty researchers across the full lifecycle of a report.
Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible.
Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk.
Mentor the Team and Raise Triage Standards:
Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication.
Set and maintain the bar for triage quality and strengthen program practices over time.

Requirements:
8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.
Expertise in:
Common web and application vulnerability classes and exploitation techniques.
Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity.
Coordinated vulnerability disclosure.
Code and development fluency:
Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests.
Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code.
Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC.
Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research.
Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill.

This position is open to all candidates.
מידת ההתאמה שלי
התאמה למשרה
כישוריםמשקף את הכישורים שמופיעים בפרופיל שלך ביחס לכישורים הנדרשים למשרה.0%
יש לך 0 מתוך 1 הכישורים הנדרשים
כישורים חסרים:
.NET/Java/Node.js/Python
התאמתך למשרה מחושבת על פי כישוריך וניסיונך (כפי שסיפרת לנו עליהם) מול דרישות המעסיק - אין בכך כדי להעיד על קבלתך לעבודה (זה יחליט המעסיק)
מידע על תפקיד
מומחי אבטחת מידע מציעים מומחיות מעמיקה באבטחת מערכות מידע. הם מייעצים בנושאי אבטחה מורכבים, מפתחים פתרונות אבטחה מתקדמים ומובילים מאמצי תגובה לאירועים. מומחיות בארכיטקטורת אבטחה, מידול איומים ותקני תאימות היא קריטית.
קורסים והכשרות להגיע לתפקיד
למד את אמנות האבטחה ההתקפית כדי לחשוף איומי סייבר ופגיעויות לפני שפושעי הסייבר יעשו זאת
כיצד להעריך את הרשת, מערכות ההפעלה ונקודות הקצה לאיתור נקודות תורפה, וכיצד לאבטח את הרשת. כמו כן, תרכוש מיומנויות לשמירה על היושרה, הסודיות והזמינות ברשת שלך ובנתונים שלך
חקור את התחום המרגש של אבטחת סייבר ומדוע אבטחת סייבר היא קריירה מוגנת עתיד.
משרות חדשות במערכת שיכולות לעניין אותך
Malam Team
Full timeבכיריםמלאה
איזור המרכז
פורסם ב-25/02/2026
אנחנו מגייסים עבור לקוח ביטחוני מוביל Cloud Security Architect לתפקיד אסטרטגי בצוות הגנת הענן, המתמקד בתכנון והובלת אבטחה בסביבות Multi-Cloud. ...
Malam Team
מלאה
איזור המרכז
פורסם ב-04/08/2026
לחברת Enterprise מובילה דרוש/ה מנהל/ת תקשורת ואבטחת מידע בעל/ת ניסיון מוכח בניהול, תפעול והובלת סביבות תקשורת ואבטחה מורכבות. התפקיד משלב ...
מלאה
פורסם לפני 15 שעות
גוף בטחוני משמעותי ויציב מחפש Security Architect Requirements: 3+ years of experience as a Security Architect.6+ years of experience in ...
היברידי
איזור המרכז
פורסם לפני 15 שעות
אנו מגייסים סגן/ית מנהל /ת הגנת המידע והסייבר, לתפקיד ניהולי מרכזי המהווה יד ימינו של מנהל המחלקה, עם אחריות על ...
דוברי שפותמלאה
חיפהטירת כרמלנשר
פורסם לפני 2 ימים
לארגון מוביל בחיפה, דרוש/ה ראש/ת צוות אבטחת מידע וסייבר. התפקיד כולל: הובלת מדיניות וגיבוש אסטרטגיית אבטחת מידע וסייבר ארגונית להגנה ...
היברידימלאה
חיפה
פורסם לפני 2 ימים
מערך מחשוב ומערכות מידע בטכניון מגייס אחראי/ת מערכות ניהול זהויות וגישה ארגונית (IDM/IAM). בתפקיד משמעותי בליבת הזהות הדיגיטלית של הטכניון, ...
מלאה
פורסם לפני 4 ימים
We are seeking an experienced Data Protection Lead to join the Cyber Security organization. This role combines hands-on Data Leakage ...
מלאה
פורסם לפני 4 ימים
We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll ...
מלאה
איזור תל אביב
פורסם לפני 4 ימים
This is a hands-on role that balances deep technical work along with building and running the function: the Lead drives ...
מלאה
פורסם לפני 4 ימים
The role is responsible for anticipating relevant threats, challenging defenses, identifying exploitable weaknesses, hunting for adversary activity that may evade existing controls, and converting findings ...
מלאה
פורסם לפני 4 ימים
we are looking for a Head of Security Reliability to establish and lead the Security Reliability pillar. Reporting directly to ...
היברידימלאה
פורסם לפני 4 ימים
This role is responsible for leading the organizations security architecture across corporate networks and cloud environments, ensuring secure design and ...
מלאה
פורסם לפני 4 ימים
We are looking for a skilled Security Automation Engineer to join our SOC Automation team and play a key role ...
הצגת משרות נוספות

שימו לב: זה טווח השכר הממוצע לסוג תפקיד בשוק רק המעסיק יקבע את השכר בפועל.
עדכון הכישורים שלך
להלן הכישורים הקיימים בפרופיל שלך. מומלץ להוסיף כישורים אשר דרושים למשרה או כישורים שלהערכתך רלוונטים לתפקיד.