כדי לראות תפקידים מתאימים עליך להוסיף כישורים בפרופיל האישי במערכת COB.
ההרשמה והשימוש חינם!
מעולה, רוצה להירשם

Senior Security Specialist|אבטחת מידע וסייבר|ניהול ביניים
מלאה
רמת שכר
25,000
פורסם לפני 4 ימים
פורסמה ברשת
we are looking for a WAF Security Specialist.
What You'll Do:
Create – Produce production WAF rules across providers for high-impact CVEs and customer findings – driving the Copilot harness on most of them, writing the expression yourself on the hard ones (no public PoC, exploitable path reasoned out of a patch diff, urgent customer coverage). Your rules ship, and they set the bar generated rules are measured against.
**Optimize -**Tighten generated rules for real production constraints: WCU and rule-capacity budgets, latency, provider expression limits, and the anchoring required for a rule that fires against all traffic behind a shared Web ACL – not just the vulnerable app.
Validate – Own the adversarial pass. Build exploit variants the PoC doesn't cover, hunt bypasses in our own rules, and run the false-positive side seriously – verifying against how the legitimate client actually behaves on the wire, not against an assumption.
Monitor – Watch deployed rules in production: false-positive signals, hit patterns, coverage drift as managed rulesets shift underneath us, and the log→block promotion decision. Retire what no longer earns its capacity.
Make it reproducible – Turn every finding into a regression test. Build and curate the golden CVE datasets and scoring rubrics that gate whether a new Copilot version ships.
Set the coverage line. Judge which CVEs are genuinely WAF-mitigatable and which aren't, and make the call on what enters and leaves our managed rulesets – with the reasoning written down.

Requirements:
Deep, hands-on WAF expertise across multiple major providers – you've written, tuned, and operated real rules in production on several of: AWS WAFv2, Cloudflare, F5, Imperva, Akamai, Azure, GCP, Fortinet, ModSecurity/CRS. Not "managed a WAF vendor relationship" – written the rules.
You know the caveats cold. Body-inspection limits and oversize handling, text transformations and normalization order, encoding and unicode evasion, parameter pollution, chunked and multipart edge cases, rule precedence and evaluation order, WCU/capacity economics, and how each provider's expression language quietly differs from the others.
Strong security research background – application security, vulnerability research, or offensive security. You can read an advisory, build the PoC, derive the variants nobody published, and explain exactly which request component carries the exploit primitive.
A real feel for the false-positive tradeoff. You've had to defend a blocking decision to someone whose production traffic you broke, and you know why "block everything suspicious" is not a security posture.
Comfortable in code. Enough Python (or similar) to automate replay, build variant generators, and query exploit and traffic data yourself rather than waiting on someone.
Fast under pressure, systematic afterward. You can get a solid rule out the door when a customer needs one today – and your instinct once it ships is to build the check that catches the whole class, not just the instance you fixed.
Advantage: virtual patching / vulnerability-mitigation experience, or time on a WAF vendor's rules or research team.
Advantage: hands-on with LLMs and agentic tooling – you'll be shaping an AI system's output, and it helps to understand how it fails.

This position is open to all candidates.
מידת ההתאמה שלי
התאמה למשרה
כישוריםמשקף את הכישורים שמופיעים בפרופיל שלך ביחס לכישורים הנדרשים למשרה.0%
יש לך 0 מתוך 7 הכישורים הנדרשים
כישורים חסרים:
Exploit Variant DevelopmentPythonSecurity ResearchTraffic Data AnalysisVirtual PatchingWaf OptimizationWaf Rule Creation
התאמתך למשרה מחושבת על פי כישוריך וניסיונך (כפי שסיפרת לנו עליהם) מול דרישות המעסיק - אין בכך כדי להעיד על קבלתך לעבודה (זה יחליט המעסיק)
מידע על תפקיד
מהנדס אבטחת מידע מגן על תשתית ה-IT של הארגון מפני איומי סייבר על ידי יישום וניהול פתרונות אבטחה, ביצוע הערכות וקידום מודעות לאבטחה. תחומי האחריות כוללים הערכת פרצות אבטחה, תכנון מסגרות אבטחה, תחזוקת אמצעי הגנה וחינוך צוות בנוגע לפרוטוקולי אבטחה. מיומנויות חיוניות כוללות רקע טכני חזק, מיומנויות אנליטיות, הבנה מעמיקה של איומי סייבר ויכולת להעביר מושגי אבטחה מורכבים בצורה ברורה.
קורסים והכשרות להגיע לתפקיד
תוכנית המיועדת להכשיר את המשתתפים במיומנויות מתקדמות בניהול רשתות מחשבים ופריסת תשתיות ענן. התוכנית כוללת תכנים על תכנון רשתות, אבטחת ... Read more
למד את אמנות האבטחה ההתקפית כדי לחשוף איומי סייבר ופגיעויות לפני שפושעי הסייבר יעשו זאת
קורס זה מכסה דרכים לנטר את הרשת שלך וכיצד להעריך התראות אבטחה
משרות חדשות במערכת שיכולות לעניין אותך
Malam Team
מלאה
איזור המרכז
פורסם ב-27/08/2026
לצוות SOC של קבוצת Malam Team דרוש/ה SOC Tier 2  התפקיד כולל חקירה מעמיקה ותגובה לאירועי סייבר מורכבים, טיפול באירועים ...
Malam Team
מלאה
איזור המרכז
פורסם ב-04/08/2026
לחברת Enterprise מובילה דרוש/ה מנהל/ת תקשורת ואבטחת מידע בעל/ת ניסיון מוכח בניהול, תפעול והובלת סביבות תקשורת ואבטחה מורכבות. התפקיד משלב ...
Malam Team
מלאה
איזור המרכז
פורסם ב-04/08/2026
לארגון ציבורי מוביל בירושלים מחפשים מפתחי DEVOPS לתכנון, הקמה, פיתוח, הפצה אוטומציה תחזוקה ושיפור מתמיד של פלטפורמת DEVOPS .  התפקיד ...
Malam Team
Full timeמלאה
איזור המרכז
פורסם ב-25/02/2026
אנחנו מגייסים עבור לקוח ביטחוני מוביל Cloud Security Architect לתפקיד אסטרטגי בצוות הגנת הענן, המתמקד בתכנון והובלת אבטחה בסביבות Multi-Cloud. ...
מלאה
חיפהטירת כרמלנשר
פורסם לפני יום 1
לארגון מוביל בחיפה, דרוש/ה ראש/ת צוות אבטחת מידע וסייבר. התפקיד כולל: הובלת מדיניות וגיבוש אסטרטגיית אבטחת מידע וסייבר ארגונית להגנה ...
מלאה
ראשון לציון
פורסם לפני יום 1
התפקיד כולל ביצוע סקרי סיכונים וקביעת מתודולוגיות לניהול סיכוני IT וסייבר, זיהוי חשיפות והצעת דרכים למניעתן, ביצוע סקרים למוצרים טכנולוגיים ...
משמרות
רעננה
פורסם לפני יום 1
Location: RaananaShift-Based: Includes night shifts, weekends and holidays Responsibilities: Continuously track security alerts and logs from NG-SIEM, EDR, FW, NAC, ...
פורסם לפני יום 1
אנו מחפשים איש אבטחת מידע ברמת גוניור-ביניים להצטרף לצוות אבטחת המידע שלנו, במסגרת תפקיד משולב הכולל תחומי GRC לצד עבודה ...
מלאה
באר יעקבראשון לציון
פורסם לפני יום 1
חברת Mertens Malam Team מגייסת ארכיטקט.ית אבטחת מידע בענן לארגון פיננסי מוביל בראשון לציון.התפקיד כולל הובלת תכנון ויישום ארכיטקטורת אבטחה ...
היברידימלאה
פורסם לפני יום 1
ארכיטקט/ית Enterpriseאם אתם/ן חיים ארכיטקטורה, אוהבים לפתור אתגרים מורכבים ורוצים להשפיע על התכנון של מערכות ליבה בסביבה טכנולוגית מתקדמת- זו ...
פתח תקווה
פורסם לפני יום 1
חברת Mertens Malam Team מגייסת איש.ת רשתות תקשורת ואבטחת מידע לחברה טכנולוגית במרכז הארץ. תיאור במסגרת התפקיד אחריות מקצה לקצה על ...
מלאה
פורסם לפני 3 ימים
אנחנו מחפשים מהנדס/ת DevOps מנוסה להצטרף לצוות טכנולוגי ולעבוד על הקמה, תחזוקה ואוטומציה של תשתיות ענן וסביבות פיתוח וייצור. התפקיד ...
מלאה
חיפה
פורסם לפני 3 ימים
מערך מחשוב ומערכות מידע בטכניון מגייס אחראי/ת תשתיות סיסטם וענן. תפקיד מפתח רוחבי בסביבה ארגונית גדולה ומגוונת, הכולל אחריות על ...
ראשון לציון
פורסם לפני 3 ימים
ארגון ביטחוני מעולה בראשון לציון מחפש מיישם /ת הגנת סייבר עם התמחות בעולמות הפיתוח ואבטחת יישומים להצטרפות לצוות טכנולוגי, לתפקיד ...
מלאה
פורסם לפני 4 ימים
We're looking for an AI Security Researcher to join us and uncover emerging AI threats, derive detection logic, discover new ...
הצגת משרות נוספות

שימו לב: זה טווח השכר הממוצע לסוג תפקיד בשוק רק המעסיק יקבע את השכר בפועל.
עדכון הכישורים שלך
להלן הכישורים הקיימים בפרופיל שלך. מומלץ להוסיף כישורים אשר דרושים למשרה או כישורים שלהערכתך רלוונטים לתפקיד.