עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
Huskeys is building an intelligent security control layer for modern web applications. We work alongside existing WAFs to help security teams understand traffic behavior, reduce false positives, and protect applications without disrupting business.
This is a founding CTO Office role for a security researcher who can operate as an independent technical force multiplier. You will investigate hard web, API, cloud, WAF, and customer-security problems where the path is often unclear. You will turn incomplete signals into evidence, make judgment calls about what matters, build the minimum tooling or proof required, and convert the result into customer impact, product capability, or a clear decision to stop.
This is not a pure research role, a conventional solutions-architect role, or a strategy-only role. You must be equally comfortable reading traffic and infrastructure behavior, writing and running code, speaking with customers, and deciding what should become product versus a one-off solution.
The CTO Office takes on technical problems that cut across customer reality, security research, product direction, and implementation—before they fit cleanly inside a single function.
What You’ll Do- Own ambiguous technical investigations from initial hypothesis to reproducible evidence and a concrete next action.
- Research web, API, cloud, WAF, CDN, network, and application-security behavior in real customer and market environments.
- Build small, working tools, experiments, detectors, integrations, or proofs of concept when they are the fastest way to establish truth.
- Distinguish a technically interesting observation from material customer risk, product opportunity, or noise.
- Work directly with customers and internal teams to understand real deployment constraints, business impact, and operational tradeoffs.
- Decide whether an outcome belongs in product, a customer-specific solution, the research backlog, external tooling, or nowhere.
- Translate validated work into a clear decision and owned next step—such as detection logic, a finding, a product requirement, remediation guidance, a reusable tool, or a decision not to proceed.
- Communicate evidence, uncertainty, and recommendations clearly to engineers, customers, and leadership.
- Move rapidly between research, implementation, customer context, and product decisions; discard work quickly when evidence changes the answer.
- Help shape Huskeys’ technical point of view through clear internal documentation and, where appropriate, external research.
- Build a practical model of the Huskeys product, customer environments, WAF/log data, external scanning, and the security decisions customers need to make.
- Reproduce and document one meaningful web, API, cloud, or WAF security behavior in a local lab or controlled environment.
- Identify a focused investigation with the CTO: the decision it needs to support, the evidence required, the smallest credible experiment, and its expected outcome.
- Drive that investigation independently through data collection, technical validation, and a working artifact: a tool, experiment, detector, integration, or reproducible proof.
- Communicate the evolving evidence, uncertainty, and tradeoffs clearly to the CTO and relevant Engineering or Product partners.
- Make a recommendation grounded in the evidence: ship, investigate further, turn it into a customer-specific solution, escalate, or stop.
- Deliver one concrete, reviewable outcome: a shipped artifact, validated finding, evidence-backed no-go decision, or product-direction recommendation.
- Translate the work into an owned next step—such as detection logic, a finding, a product requirement, remediation guidance, a reusable tool, or a customer technical narrative.
- Demonstrate that you can receive a loosely framed problem, choose the right scope, produce credible technical evidence, and move it to the correct owner or outcome without continuous direction.
- Demonstrated hands-on depth in at least two of: web application security, API security, cloud security, network security, WAF/CDN behavior, attack-surface management, bot/abuse defense, or infrastructure security.
- Strong first-principles understanding of HTTP, DNS, TLS, proxies, load balancers, authentication, web applications, APIs, and cloud networking.
- Evidence of independently taking a vague security problem to a working tool, reproducible proof, detection, investigation, or product outcome.
- Ability to write and operate code for research and technical validation—Python, TypeScript, Go, or equivalent.
- Judgment to decide what requires more investigation, what is ready to ship, what belongs to another team, and what should be killed.
- Comfortable with customer ambiguity: incomplete data, competing priorities, non-technical stakeholders, and real delivery constraints.
- Clear written communication for engineers, security teams, and executives.
- Strong curiosity without confusing breadth of ideas with depth of understanding.
- Research experience in WAF bypasses, origin exposure, cloud misconfiguration, API security, attack-surface discovery, or bot/agent abuse.
- Familiarity with AWS and modern cloud environments.
- Experience building detections, security products, or research tooling.
- Experience working directly with enterprise customers on technical investigations or security outcomes.
- Published research, open-source tools, CTF experience, or an equivalent research portfolio.
You’ll work on difficult, real-world web security problems with direct access to the people building the product. The goal is not research for its own sake: it is to make the internet harder to attack and give security teams a clearer path to action.
You will have unusual ownership, high context, and the ability to turn evidence into product and customer impact. In return, the role demands technical rigor, speed, judgment, and the willingness to own an outcome end to end.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
שאלות ותשובות עבור משרת Solution Architect (Researcher) — CTO Office
התפקיד של Solution Architect (Researcher) במשרד ה-CTO בחברת Huskeys הוא תפקיד יסודי המשלב מחקר אבטחה עם פתרונות מעשיים. הוא כולל חקירת בעיות אבטחה מורכבות ביישומי ווב, API וענן, הפיכת אותות חלקיים לראיות, בניית כלים מינימליים או הוכחות קונספט, ותרגום התוצאות להשפעה על לקוחות, יכולות מוצר או החלטה ברורה להפסיק פרויקט. זהו אינו תפקיד מחקר טהור או תפקיד אדריכל פתרונות קונבנציונלי.
משרות נוספות מומלצות עבורך
-
Senior Penetration Testing Researcher
-
פתח תקווה
Palo Alto Networks
-
-
R&D Engineer — Security Platform
-
תל אביב - יפו
Hex-Rays
-
-
Senior Security Researcher - Enterprise Security Research
-
תל אביב - יפו
Akamai
-
-
Senior / Principal Security Research - Agent ML Team (Cortex)
-
תל אביב - יפו
Cyber Ark Software Ltd
-
-
Senior/Principal Security Researcher - Windows EDR (Cortex - XDR)
-
תל אביב - יפו
Cyber Ark Software Ltd
-
-
Security Research
-
תל אביב - יפו
Transmit Security
-