כדי לראות תפקידים מתאימים עליך להוסיף כישורים בפרופיל האישי במערכת COB.
ההרשמה והשימוש חינם!
מעולה, רוצה להירשם

Senior Security Specialist|אבטחת מידע וסייבר|ניהול ביניים
מלאה
רמת שכר
25,000
פורסם לפני 2 ימים
פורסמה ברשת
we are looking for a WAF Security Specialist.
What You'll Do:
Create – Produce production WAF rules across providers for high-impact CVEs and customer findings – driving the Copilot harness on most of them, writing the expression yourself on the hard ones (no public PoC, exploitable path reasoned out of a patch diff, urgent customer coverage). Your rules ship, and they set the bar generated rules are measured against.
**Optimize -**Tighten generated rules for real production constraints: WCU and rule-capacity budgets, latency, provider expression limits, and the anchoring required for a rule that fires against all traffic behind a shared Web ACL – not just the vulnerable app.
Validate – Own the adversarial pass. Build exploit variants the PoC doesn't cover, hunt bypasses in our own rules, and run the false-positive side seriously – verifying against how the legitimate client actually behaves on the wire, not against an assumption.
Monitor – Watch deployed rules in production: false-positive signals, hit patterns, coverage drift as managed rulesets shift underneath us, and the log→block promotion decision. Retire what no longer earns its capacity.
Make it reproducible – Turn every finding into a regression test. Build and curate the golden CVE datasets and scoring rubrics that gate whether a new Copilot version ships.
Set the coverage line. Judge which CVEs are genuinely WAF-mitigatable and which aren't, and make the call on what enters and leaves our managed rulesets – with the reasoning written down.

Requirements:
Deep, hands-on WAF expertise across multiple major providers – you've written, tuned, and operated real rules in production on several of: AWS WAFv2, Cloudflare, F5, Imperva, Akamai, Azure, GCP, Fortinet, ModSecurity/CRS. Not "managed a WAF vendor relationship" – written the rules.
You know the caveats cold. Body-inspection limits and oversize handling, text transformations and normalization order, encoding and unicode evasion, parameter pollution, chunked and multipart edge cases, rule precedence and evaluation order, WCU/capacity economics, and how each provider's expression language quietly differs from the others.
Strong security research background – application security, vulnerability research, or offensive security. You can read an advisory, build the PoC, derive the variants nobody published, and explain exactly which request component carries the exploit primitive.
A real feel for the false-positive tradeoff. You've had to defend a blocking decision to someone whose production traffic you broke, and you know why "block everything suspicious" is not a security posture.
Comfortable in code. Enough Python (or similar) to automate replay, build variant generators, and query exploit and traffic data yourself rather than waiting on someone.
Fast under pressure, systematic afterward. You can get a solid rule out the door when a customer needs one today – and your instinct once it ships is to build the check that catches the whole class, not just the instance you fixed.
Advantage: virtual patching / vulnerability-mitigation experience, or time on a WAF vendor's rules or research team.
Advantage: hands-on with LLMs and agentic tooling – you'll be shaping an AI system's output, and it helps to understand how it fails.

This position is open to all candidates.
מידת ההתאמה שלי
התאמה למשרה
כישוריםמשקף את הכישורים שמופיעים בפרופיל שלך ביחס לכישורים הנדרשים למשרה.0%
יש לך 0 מתוך 7 הכישורים הנדרשים
כישורים חסרים:
Exploit Variant DevelopmentPythonSecurity ResearchTraffic Data AnalysisVirtual PatchingWaf OptimizationWaf Rule Creation
התאמתך למשרה מחושבת על פי כישוריך וניסיונך (כפי שסיפרת לנו עליהם) מול דרישות המעסיק - אין בכך כדי להעיד על קבלתך לעבודה (זה יחליט המעסיק)
מידע על תפקיד
מהנדס אבטחת מידע מגן על תשתית ה-IT של הארגון מפני איומי סייבר על ידי יישום וניהול פתרונות אבטחה, ביצוע הערכות וקידום מודעות לאבטחה. תחומי האחריות כוללים הערכת פרצות אבטחה, תכנון מסגרות אבטחה, תחזוקת אמצעי הגנה וחינוך צוות בנוגע לפרוטוקולי אבטחה. מיומנויות חיוניות כוללות רקע טכני חזק, מיומנויות אנליטיות, הבנה מעמיקה של איומי סייבר ויכולת להעביר מושגי אבטחה מורכבים בצורה ברורה.
קורסים והכשרות להגיע לתפקיד
תוכנית המיועדת להכשיר את המשתתפים במיומנויות מתקדמות בניהול רשתות מחשבים ופריסת תשתיות ענן. התוכנית כוללת תכנים על תכנון רשתות, אבטחת ... Read more
למד את אמנות האבטחה ההתקפית כדי לחשוף איומי סייבר ופגיעויות לפני שפושעי הסייבר יעשו זאת
קורס זה מכסה דרכים לנטר את הרשת שלך וכיצד להעריך התראות אבטחה
משרות חדשות במערכת שיכולות לעניין אותך
מלאה
פורסם לפני 22 שעות
אנחנו מחפשים מהנדס/ת DevOps מנוסה להצטרף לצוות טכנולוגי ולעבוד על הקמה, תחזוקה ואוטומציה של תשתיות ענן וסביבות פיתוח וייצור. התפקיד ...
מלאה
חיפה
פורסם לפני 22 שעות
מערך מחשוב ומערכות מידע בטכניון מגייס אחראי/ת תשתיות סיסטם וענן. תפקיד מפתח רוחבי בסביבה ארגונית גדולה ומגוונת, הכולל אחריות על ...
מלאה
פורסם לפני 2 ימים
We're looking for an AI Security Researcher to join us and uncover emerging AI threats, derive detection logic, discover new ...
מלאה
פורסם לפני 2 ימים
We are looking for a Product Manager with a strong cybersecurity background and proven experience building AI-powered products. You will ...
מלאה
פורסם לפני 2 ימים
we are looking for a Engineering Team Lead.Responsibilities:Lead, mentor, and grow a cross-functional team of backend, frontend, and research engineers.Act ...
מלאה
פורסם לפני 2 ימים
we are looking for a Lead Security Researcher.You will lead security research. This is not a bug hunting role. Your ...
מלאה
פורסם לפני 2 ימים
We're looking for a Senior Product Manager to own a core area of platform. You'll work closely with engineering, security ...
היברידי
פורסם לפני 2 ימים
we are looking for a Runtime Sensor Developer | eBPF Expert.In this role, youll write low-level code that hooks deep ...
היברידי
פורסם לפני 2 ימים
We're looking for a Product Manager to own Runtime Domain – the engine that powers vulnerability intelligence, attack detection, sensor ...
מלאה
חיפה
פורסם לפני 2 ימים
This is a full-time on-site role located in Haifa for a SecOps professional. The responsibilities include maintaining and optimizing security ...
היברידי
חיפה
פורסם לפני 2 ימים
In this role, you will be responsible for designing, building, and implementing robust, secure, and highly scalable cloud architectures. You ...
מלאה
פורסם לפני 2 ימים
Tech is at the center of everything we do and we're looking for people who are builders at their core. ...
Malam מערכות
מלאה
איזור המרכזהוד השרוןחדרהנתניהפתח תקווהראש העיןראשון לציון
פורסם לפני 5 ימים
אנחנו מגייסים עבור לקוח ביטחוני מוביל Cloud Security Architect לתפקיד אסטרטגי בצוות הגנת הענן, המתמקד בתכנון והובלת אבטחה בסביבות Multi-Cloud.מדובר ...
Logica-IT
היברידי
איזור המרכזהוד השרוןנתניהפתח תקווהראש העיןראשון לציון
פורסם לפני 5 ימים
ארגון גדול ומוביל בתחומו בתל אביב מגייס Cyber Security Engineer התפקיד כולל:הטמעה, תפעול ותחזוקה שוטפת של מוצרי ופלטפורמות הגנת הסייבר  ביצוע התקנות, ...
youcc טכנולוגיות
היברידימלאה
איזור המרכזהוד השרוןחדרהיבנהנתניהפתח תקווהראש העיןראשון לציון
פורסם לפני 5 ימים
לחברה מובילה ומתפתחת דרוש/ה מנתח/ת מערכות עם ניסיון משמעותי בעולמות הבנקאות/הפיננסים, COBOL ו-Mainframe, להצטרפות לצוות מנתחי מערכות ומפתחים. מה כולל ...
הצגת משרות נוספות

שימו לב: זה טווח השכר הממוצע לסוג תפקיד בשוק רק המעסיק יקבע את השכר בפועל.
עדכון הכישורים שלך
להלן הכישורים הקיימים בפרופיל שלך. מומלץ להוסיף כישורים אשר דרושים למשרה או כישורים שלהערכתך רלוונטים לתפקיד.