כדי לראות תפקידים מתאימים עליך להוסיף כישורים בפרופיל האישי במערכת COB.
ההרשמה והשימוש חינם!
מעולה, רוצה להירשם

Senior Security Specialist|אבטחת מידע וסייבר|ניהול ביניים
פתח תקווה
היברידי
רמת שכר
20,000
פורסם לפני 2 ימים
פורסמה ברשת
We seek a Senior Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.
The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.
As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.
Key Responsibilities:
Triage and Resolve Bug Bounty Reports:
Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition.
Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed.
Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues.
Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom.
Propose remediations, or design them with engineering, and verify the fix resolves the issue.
Assign and defend severity ratings using the program's severity framework.
Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure.
Own Researcher and Stakeholder Communication:
Act as our primary technical point of contact for bug bounty researchers across the full lifecycle of a report.
Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible.
Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk.
Mentor the Team and Raise Triage Standards:
Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication.
Set and maintain the bar for triage quality and strengthen program practices over time.

Requirements:
8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.
Expertise in:
Common web and application vulnerability classes and exploitation techniques.
Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity.
Coordinated vulnerability disclosure.
Code and development fluency:
Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests.
Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code.
Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC.
Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research.
Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill.

This position is open to all candidates.
מידת ההתאמה שלי
התאמה למשרה
כישוריםמשקף את הכישורים שמופיעים בפרופיל שלך ביחס לכישורים הנדרשים למשרה.0%
יש לך 0 מתוך 5 הכישורים הנדרשים
כישורים חסרים:
.NET/Java/Node.js/Python'דרייב' אישי מוכח'ראש גדול' - יכולת פתרון בעיות'ראש גדול' נמרץ ודינמי[יתרון] תכנות Python
התאמתך למשרה מחושבת על פי כישוריך וניסיונך (כפי שסיפרת לנו עליהם) מול דרישות המעסיק - אין בכך כדי להעיד על קבלתך לעבודה (זה יחליט המעסיק)
מידע על תפקיד
מומחי אבטחת מידע מציעים מומחיות מעמיקה באבטחת מערכות מידע. הם מייעצים בנושאי אבטחה מורכבים, מפתחים פתרונות אבטחה מתקדמים ומובילים מאמצי תגובה לאירועים. מומחיות בארכיטקטורת אבטחה, מידול איומים ותקני תאימות היא קריטית.
קורסים והכשרות להגיע לתפקיד
למד את אמנות האבטחה ההתקפית כדי לחשוף איומי סייבר ופגיעויות לפני שפושעי הסייבר יעשו זאת
כיצד להעריך את הרשת, מערכות ההפעלה ונקודות הקצה לאיתור נקודות תורפה, וכיצד לאבטח את הרשת. כמו כן, תרכוש מיומנויות לשמירה על היושרה, הסודיות והזמינות ברשת שלך ובנתונים שלך
חקור את התחום המרגש של אבטחת סייבר ומדוע אבטחת סייבר היא קריירה מוגנת עתיד.
משרות חדשות במערכת שיכולות לעניין אותך
מלאהמשמרות
חדרהכרמיאלנתניהראשון לציון
פורסם לפני 3 שעות
לחברה קמעונאית בפריסה ארצית דרוש/ה קב"ט/ית.במסגרת התפקיד :  יישום תכנית למניעת אובדן בכפיפות לקבט ראשי. הכרת אמצעים טכניים במערך האבטחה. חקירה ותשאול עובדים.  ביצוע הדרכות ...
מלאה
חיפהטירת כרמלנשר
פורסם לפני 6 שעות
לארגון מוביל בחיפה, דרוש/ה ראש/ת צוות אבטחת מידע וסייבר. התפקיד כולל: הובלת מדיניות וגיבוש אסטרטגיית אבטחת מידע וסייבר ארגונית להגנה ...
היברידי
איזור ירושלים
פורסם לפני 2 ימים
We are seeking an experienced and highly skilled Global IT Director to manage and actively drive the technology infrastructure for ...
מלאה
פורסם לפני 2 ימים
דרוש מומחה הגנה בסייבר, כמומחה הגנה בסייבר תעבוד בשיתוף פעולה הדוק עם צוותי התשתיות והפיתוח בכדי לוודא את אבטחת הרשת ...
מלאה
פורסם לפני 2 ימים
חברתנו מגייסת מנהל פרויקט טכנולוגי לניהול תהליך החיבור וההטמעה של מערכות אבטחה מבוססות AI במצלמות ובבתי חב"ד בעלי מוקד לקצה, ...
היברידי
פתח תקווה
פורסם לפני 2 ימים
We seek an experienced offensive security leader to build and lead the Product Red Team. This newly established function emulates ...
היברידי
פתח תקווה
פורסם לפני 2 ימים
We are looking for a Sr. Staff Security Engineer to be a technical anchor on this team.Security R&D operates in ...
היברידי
פתח תקווה
פורסם לפני 2 ימים
We are looking for a Staff Security Engineer to be a core contributor on this team.Security R&D operates in two ...
מלאה
פתח תקווה
פורסם לפני 2 ימים
Our SaaS platform leverages AI to make information accessible, actionable, and measurable, driving productivity and satisfaction for enterprises worldwide. As ...
מלאה
פורסם לפני 3 ימים
As a Security Researcher, you will be responsible for leading in-depth research into emerging blockchain threats and vulnerabilities and developing ...
היברידי
פורסם לפני 5 ימים
השתלבות בצוות מקצועי האחראי על תפעול, תחזוקה ואבטחת תשתיות ענן בסביבה ארגונית מורכבת, תוך עבודה עם מערכות אבטחת מידע מתקדמות ...
מלאה
איזור המרכז
פורסם לפני 6 ימים
חברת hms מגייסת DevOps Engineer להשתלבות בפרויקט טכנולוגי בתחום האשראי בארגון פיננסי מוביל. התפקיד כולל הקמה, ניהול ותחזוקה שוטפת של ...
מלאה
חיפהכרמיאלנשר
פורסם לפני 6 ימים
חברה ביטחונית באזור הצפון מגייסת מומחה/ית יישום טכנולוגיית סייברהתפקיד כולל: עבודה עם צוותי IT, הובלת פרויקטים בתחום תשתיות הגנת סייבר ...
מלאהמשמרות
פתח תקווהראש העין
פורסם לפני 6 ימים
לחברה בפתח תקווה דרוש/ה אחראי/ת ביטחון לתפקיד מגוון הכולל בקרות לוגיסטיקה ועובדים, הטמעת תהליכים, הדרכות, בקרות סמויות וגלויות ותחקור מערכות.תפקיד ...
הצגת משרות נוספות

שימו לב: זה טווח השכר הממוצע לסוג תפקיד בשוק רק המעסיק יקבע את השכר בפועל.
עדכון הכישורים שלך
להלן הכישורים הקיימים בפרופיל שלך. מומלץ להוסיף כישורים אשר דרושים למשרה או כישורים שלהערכתך רלוונטים לתפקיד.