jobify_logo ×
  • מִשׁתַמֵשׁ
  • התחברות/הרשמה111
  • עמוד הבית
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות
קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service work_office המקום
jobify_logo
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
דילוג לתוכן

עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!

במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

Offensive Security Specialist / Penetration Tester

Cybear - Track and Expose

Cybear - Track and Expose Cybear - Track and Expose

  • תל אביב - יפו
  • LinkedIn
LinkedIn

Offensive Security Specialist / Penetration Tester

Cybear - Track and Expose

Cybear - Track and Expose Cybear - Track and Expose

  • תל אביב - יפו
  • bag_icon חלקית
  • coins_icon 12,000-18,000 ₪ (הערכה מבוססת AI)
    הערכה מבוססת AI ולא שכר של המעסיק
  • LinkedIn
LinkedIn


Offensive Security Specialist / Penetration Tester — CyBearTrack

Location: Nes Ziona, Israel (on-site) Type: Full-time — Monday to Thursday, 06:30–14:30 (32 hours/week) Compensation: Base ₪12,000/month + performance bonuses on every successful authorised engagement Contact: [email protected]

Who We Are

CyBearTrack is a specialist cyber-investigation firm working cryptocurrency fraud, blockchain forensic tracing, and OSINT. We work directly with scam victims, law enforcement, and enforcement partners to trace stolen funds, unmask threat actors, and build cases that lead to real outcomes. CyBearTrack is an authorised preferred vendor to law-enforcement partners and takes offensive engagements only under lawful tasking granted on a case-by-case basis for specific referred matters.

The Role

We're looking for an Offensive Security Specialist who can go head-to-head with scam infrastructure — the fake trading platforms, phishing kits, admin panels, and command channels that fraud operators run against our clients — and who understands that the difference between an investigator and a criminal is authorisation, scope, and documentation.

The role has two sides. The first is defensive and proactive: designing and running the honeypots — the decoy victims, wallets and instrumented environments that draw fraud operators in and quietly capture how they work. The second is authorised offensive operations: going directly at scam infrastructure, but only ever within the authority granted for that specific matter — a defined target, a defined scope, and a defined objective, signed off before you touch anything. Most weeks you'll move between the two.

If you're the kind of person who reads a scam operator's stack and thinks "I know exactly how that panel is held together," but who also stops dead at the edge of the authorisation without being told twice, this is your seat.

What You'll Be Doing
  • Honeypot design and operation — building and running decoy victims, instrumented environments, decoy wallets and deceptive infrastructure that attract fraud operators and capture their tooling, infrastructure, identifiers and behaviour. This is CyBearTrack's own environment and the core of the role.
  • Authorised offensive engagements — penetration testing and active operations against scam infrastructure, conducted only under the lawful authority granted for each referred matter, within the agreed scope, to a documented, evidence-grade standard.
  • Scam-infrastructure reconnaissance — domain history, hosting, SSL certs, exposed source, panel fingerprinting, kit identification, and passive mapping of operator infrastructure from open sources.
  • Evidence capture and preservation — collecting findings to a standard that survives legal and law-enforcement scrutiny: chain of custody, hashing, contemporaneous notes, reproducible method.
  • Vulnerability assessment of CyBearTrack and client systems — authorised testing of our own and clients' infrastructure under signed scope, to keep the recovery and evidence work defensible.
  • Correlating technical findings with the investigation — feeding infrastructure, identifiers and captures back into the blockchain traces and OSINT attribution that drive our cases and referrals.
  • Tooling — building and maintaining custom scripts and honeypot instrumentation.
What We're Looking For
  • Proven offensive-security experience — penetration testing, red team, CTF, bug bounty, or equivalent professional background.
  • Strong web-application and infrastructure skills: recon, enumeration, web exploitation, panel and CMS internals, network services.
  • A working understanding of the legal boundaries — the Israeli Computer Law, unauthorised-access rules, and why scope and authorisation are load-bearing, not paperwork. You know exactly where the line is and you do not cross it on your own initiative.
  • Honeypot / deception experience, or the ability to build it — instrumented environments, logging, capture pipelines.
  • Comfortable working within a documented, evidence-grade process rather than freelancing.
  • Familiarity with scam infrastructure — phishing kits, fake trading platforms, clone sites, Telegram/WhatsApp operations.
  • Scripting ability (Python, JavaScript, Bash) for custom tooling and automation.
  • Discretion and professionalism — our clients are fraud victims and our matters are sensitive.
  • Hebrew and English.
Bonus Points
  • Experience with honeypot/deception frameworks and malware/tooling analysis.
  • Knowledge of cryptocurrency laundering typologies and VASP disclosure processes.
  • Prior law-enforcement, military intelligence (e.g. 8200/unit background), or private-investigation experience.
  • Reverse-engineering and threat-intelligence experience.
  • Relevant certifications (OSCP, OSWE, or similar).
Compensation
  • Base: ₪12,000 per month.
  • Performance bonuses on every successful authorised engagement — paid on completed operations delivered within scope, and on honeypot captures and actionable intelligence that advance a live matter. Bonuses are tied to lawful, in-scope outcomes; nothing outside a granted authorisation is ever tasked or rewarded.
Why CyBearTrack

This isn't corporate security theatre and it isn't cowboy work either. Every matter has a real victim behind it and a real authorisation in front of it. You get to do the interesting half of offensive security — against people who genuinely deserve the attention — inside a framework that keeps you, and the case, clean. When we get it right, money gets frozen, infrastructure gets exposed, and people get arrested.

How to Apply

Send an email to [email protected] with:

  • A brief intro about yourself and your background.
  • Examples of relevant work (redacted as needed) — offensive engagements, honeypot builds, CTF/bug-bounty results.
  • Your availability.

No formal CV required. Show us how you think — and show us you know where the line is.



במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

שאלות ותשובות עבור משרת Offensive Security Specialist / Penetration Tester

תפקיד Offensive Security Specialist / Penetration Tester בחברת Cybear - Track and Expose כולל שני היבטים עיקריים: תכנון והפעלת מלכודות דבש (honeypots) למשיכת מפעילי הונאה ולכידת פעילותם, וכן ביצוע פעולות התקפיות מורשות נגד תשתית הונאה, הכל במסגרת סמכות חוקית מוגדרת ומתועדת היטב. המטרה היא לחשוף רמאים ולסייע לקורבנות.

לצורך תפקיד Offensive Security Specialist / Penetration Tester ב-CybearTrack, נדרש ניסיון מוכח באבטחת מידע התקפית (כגון בדיקות חדירה, Red Team), הבנה חזקה ביישומי אינטרנט ותשתיות, והיכרות עם הגבולות המשפטיים בישראל. כמו כן, נדרש ניסיון עם מלכודות דבש או יכולת לבנות אותן, היכרות עם תשתיות הונאה ויכולות סקריפטים (Python, JavaScript, Bash).

ההתמודדות עם תשתית הונאה בתפקיד Offensive Security Specialist / Penetration Tester ב-Cybear - Track and Expose מתבצעת באמצעות זיהוי וניתוח פלטפורמות מסחר מזויפות, ערכות פישינג ופאנלים של מנהלים המשמשים רמאים. העבודה כוללת איסוף ראיות, מיפוי תשתית המפעילים ממקורות פתוחים, וביצוע פעולות התקפיות מורשות בלבד, תוך הקפדה על תיעוד קפדני ועמידה בסטנדרטים משפטיים.

משרות נוספות מומלצות עבורך
  • רשימת משאלות

    Penetration Tester

    • map_icon ראשון לציון
    COMBLACK I.T

    COMBLACK I.T

  • רשימת משאלות

    Offensive Security Researcher

    • map_icon תל אביב - יפו
    Check Point Software

    Check Point Software

  • רשימת משאלות

    Penetration Tester

    • map_icon ראשון לציון
    Comblack

    Comblack

  • רשימת משאלות

    Penetration Tester - סוקר/ת PT

    • map_icon תל אביב - יפו
    Peak Innovation

    Peak Innovation

  • רשימת משאלות

    בודק /ת חדירות לצוות Red Team

    • map_icon חיפה
    sqlink

    sqlink

  • רשימת משאלות

    Information Security Assessor

    • map_icon תל אביב - יפו
    Extreme

    Extreme

לכל המשרות של בודק חדירות

הכשרות רלוונטיות

ITSafe

ITSafe

בודק חוסן

  • map_icon אונליין
  • אונליין
  • clk_icon 12 חודשים
אס.קיו.לינק

אס.קיו.לינק

Penetration Testing

  • map_icon רמת גן
  • בוקר
  • clk_icon 1 חודשים
היחידה ללימודי חוץ

היחידה ללימודי חוץ

Certified Ethical Hacker

  • map_icon אונליין
  • אונליין
  • clk_icon 6 חודשים
מכללת האקריו

מכללת האקריו

קורס סייבר ואבטחת מידע Ethical Hacking

  • map_icon רמת גן
  • ערב
  • clk_icon 14 חודשים

ניתן לצפות במשרות שסימנת בכל שלב תחת התפריט הראשי בקטגוריית 'משרות שאהבתי'

המקום קרן עזריאלי טקסט בעברית עם סמל אינסוף
  • מי אנחנו
  • מעסיקים מובילים
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות

2026 Ⓒ ג'וביפיי - כל הזכויות שמורות

קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service israel_innovation_authority work_office המקום
המערכת בונה את הפרופיל התעסוקתי שלך

עוד רגע...

המערכת זיהתה ששינית את הנתונים באזור האישי ומעדכנת את ההמלצות על תפקידים ומשרות בהתאם.

מצטערים, לא הצלחנו לנתח בהצלחה את הנתונים שהזנת.
אתם מוזמנים לנסות להזין שוב או להעלות קובץ קורות חיים במידה ויש לכם.
בהצלחה

הגעת להגבלה היומית של שלושה עדכונים בפרופיל האישי ביום

loader

הבקשה שלך נשלחה בהצלחה!

יש באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות מיועצת קריירה.

באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות

  • בעיה טכנית

  • סיוע בכתיבת קורות חיים או בהכנה לראיון עבודה

  • התאמה של משרות

  • אחר:

פנייתך נשלחה בהצלחה. נציג מטעם ארגון נכי צהל ייצור איתך קשר בהקדם