כדי לראות תפקידים מתאימים עליך להוסיף כישורים בפרופיל האישי במערכת COB.
ההרשמה והשימוש חינם!
מעולה, רוצה להירשם

Senior Security Specialist|אבטחת מידע וסייבר|ניהול ביניים
פתח תקווה
היברידי
רמת שכר
20,000
פורסם לפני חודש 1
פורסמה ברשת
We seek a Senior Application Security Engineer to serve as the technical core of our bug bounty program within the Product Security Incident Response Team (PSIRT). This is the senior engineer who owns bug bounty reports from intake through resolution: reproducing and validating the vulnerability, assessing its severity, and seeing it through to a verified fix.
The work is deeply technical. Reproducing a vulnerability is only the starting point. From there you read the underlying code, identify root cause, and either propose the fix or design it alongside engineering before confirming it holds. You are also the person researchers deal with directly, which makes clear, credible communication as central to the role as the technical analysis itself.
As one of the most senior engineers on the team, you will set the standard for how triage is done and mentor earlier-career engineers. Beyond the bug bounty queue, you will conduct variant hunts, perform original platform security research, lead major product security incidents, and run forensic postmortems when a significant issue reaches production.
Key Responsibilities:
Triage and Resolve Bug Bounty Reports:
Own incoming reports end-to-end: intake, reproduction, severity scoring, root cause analysis, fix verification, and final disposition.
Reproduce and validate reported vulnerabilities, building out incomplete proof-of-concept code where needed.
Serve as the technical escalation point for the most complex and highest-severity reports, including multi-step exploit chains and cross-system issues.
Perform code review and root cause analysis to identify the underlying defect rather than the reported symptom.
Propose remediations, or design them with engineering, and verify the fix resolves the issue.
Assign and defend severity ratings using the program's severity framework.
Route issues to owning teams, file and track defects, and keep vulnerability records accurate through closure.
Own Researcher and Stakeholder Communication:
Act as our primary technical point of contact for bug bounty researchers across the full lifecycle of a report.
Handle severity and validity disputes directly, keeping every exchange clear, timely, respectful, and technically credible.
Translate technical findings for internal stakeholders and keep engineering and leadership current on status and risk.
Mentor the Team and Raise Triage Standards:
Provide technical mentorship to earlier-career PSIRT engineers, developing depth in reproduction, code analysis, severity judgment, and communication.
Set and maintain the bar for triage quality and strengthen program practices over time.

Requirements:
8+ years of hands-on experience in product security, application security, penetration testing, or vulnerability research. Depth of expertise matters more than years.
Expertise in:
Common web and application vulnerability classes and exploitation techniques.
Vulnerability reproduction, severity assessment, and defensible risk scoring under ambiguity.
Coordinated vulnerability disclosure.
Code and development fluency:
Strong code comprehension in Java, JavaScript, and Python, with the ability to trace root cause in large, unfamiliar codebases and review pull requests.
Ability to write code and propose concrete fixes. This is not an application-building role, but you reason fluently in code.
Working knowledge of Git, Gradle, Maven, CI/CD pipelines, and secure SDLC.
Proficiency with Claude Code or equivalent AI coding assistant for code comprehension and security research.
Exceptional written communication. You will represent ServiceNow directly to external researchers, frequently in disagreement, and bridge those researchers and internal engineering. This is a core requirement of the role, not a supporting skill.

This position is open to all candidates.
מידת ההתאמה שלי
התאמה למשרה
כישוריםמשקף את הכישורים שמופיעים בפרופיל שלך ביחס לכישורים הנדרשים למשרה.0%
יש לך 0 מתוך 1 הכישורים הנדרשים
כישורים חסרים:
.NET/Java/Node.js/Python
התאמתך למשרה מחושבת על פי כישוריך וניסיונך (כפי שסיפרת לנו עליהם) מול דרישות המעסיק - אין בכך כדי להעיד על קבלתך לעבודה (זה יחליט המעסיק)
מידע על תפקיד
מומחי אבטחת מידע מציעים מומחיות מעמיקה באבטחת מערכות מידע. הם מייעצים בנושאי אבטחה מורכבים, מפתחים פתרונות אבטחה מתקדמים ומובילים מאמצי תגובה לאירועים. מומחיות בארכיטקטורת אבטחה, מידול איומים ותקני תאימות היא קריטית.
קורסים והכשרות להגיע לתפקיד
למד את אמנות האבטחה ההתקפית כדי לחשוף איומי סייבר ופגיעויות לפני שפושעי הסייבר יעשו זאת
כיצד להעריך את הרשת, מערכות ההפעלה ונקודות הקצה לאיתור נקודות תורפה, וכיצד לאבטח את הרשת. כמו כן, תרכוש מיומנויות לשמירה על היושרה, הסודיות והזמינות ברשת שלך ובנתונים שלך
חקור את התחום המרגש של אבטחת סייבר ומדוע אבטחת סייבר היא קריירה מוגנת עתיד.
משרות חדשות במערכת שיכולות לעניין אותך
Malam Team
מלאה
איזור המרכז
פורסם ב-04/08/2026
לחברת Enterprise מובילה דרוש/ה מנהל/ת תקשורת ואבטחת מידע בעל/ת ניסיון מוכח בניהול, תפעול והובלת סביבות תקשורת ואבטחה מורכבות. התפקיד משלב ...
Malam Team
Full timeמלאה
איזור המרכז
פורסם ב-25/02/2026
אנחנו מגייסים עבור לקוח ביטחוני מוביל Cloud Security Architect לתפקיד אסטרטגי בצוות הגנת הענן, המתמקד בתכנון והובלת אבטחה בסביבות Multi-Cloud. ...
מלאה
חיפהטירת כרמלנשר
פורסם לפני יום 1
לארגון מוביל בחיפה, דרוש/ה ראש/ת צוות אבטחת מידע וסייבר. התפקיד כולל: הובלת מדיניות וגיבוש אסטרטגיית אבטחת מידע וסייבר ארגונית להגנה ...
מלאה
באר יעקבראשון לציון
פורסם לפני 2 ימים
חברת Mertens Malam Team מגייסת ארכיטקט.ית אבטחת מידע בענן לארגון פיננסי מוביל בראשון לציון.התפקיד כולל הובלת תכנון ויישום ארכיטקטורת אבטחה ...
מלאה
פורסם לפני 3 ימים
אנחנו מחפשים מהנדס/ת DevOps מנוסה להצטרף לצוות טכנולוגי ולעבוד על הקמה, תחזוקה ואוטומציה של תשתיות ענן וסביבות פיתוח וייצור. התפקיד ...
מלאה
חיפה
פורסם לפני 3 ימים
מערך מחשוב ומערכות מידע בטכניון מגייס אחראי/ת תשתיות סיסטם וענן. תפקיד מפתח רוחבי בסביבה ארגונית גדולה ומגוונת, הכולל אחריות על ...
ראשון לציון
פורסם לפני 3 ימים
ארגון ביטחוני מעולה בראשון לציון מחפש מיישם /ת הגנת סייבר עם התמחות בעולמות הפיתוח ואבטחת יישומים להצטרפות לצוות טכנולוגי, לתפקיד ...
מלאה
פורסם לפני 4 ימים
We're looking for an AI Security Researcher to join us and uncover emerging AI threats, derive detection logic, discover new ...
מלאה
פורסם לפני 4 ימים
We are looking for a Product Manager with a strong cybersecurity background and proven experience building AI-powered products. You will ...
מלאה
פורסם לפני 4 ימים
we are looking for a Lead Security Researcher.You will lead security research. This is not a bug hunting role. Your ...
מלאה
פורסם לפני 4 ימים
We're looking for a Senior Product Manager to own a core area of platform. You'll work closely with engineering, security ...
היברידי
פורסם לפני 4 ימים
we are looking for a Runtime Sensor Developer | eBPF Expert.In this role, youll write low-level code that hooks deep ...
היברידי
פורסם לפני 4 ימים
We're looking for a Product Manager to own Runtime Domain – the engine that powers vulnerability intelligence, attack detection, sensor ...
היברידי
חיפה
פורסם לפני 4 ימים
In this role, you will be responsible for designing, building, and implementing robust, secure, and highly scalable cloud architectures. You ...
מלאה
פורסם לפני 4 ימים
we are looking for a WAF Security Specialist.What You'll Do:Create – Produce production WAF rules across providers for high-impact CVEs ...
הצגת משרות נוספות

שימו לב: זה טווח השכר הממוצע לסוג תפקיד בשוק רק המעסיק יקבע את השכר בפועל.
עדכון הכישורים שלך
להלן הכישורים הקיימים בפרופיל שלך. מומלץ להוסיף כישורים אשר דרושים למשרה או כישורים שלהערכתך רלוונטים לתפקיד.