Security Researcher

Posted Yesterday
Be an Early Applicant
Tel Aviv, ISR
In-Office
Senior level
Software • Cybersecurity
The Role
Lead original offensive security research focused on identity providers, authentication and authorization protocols, federation, directory services, and related infrastructure. Identify vulnerabilities, build proofs of concept, manage responsible disclosure through CVE assignment, publish technical research, and present at major security conferences. Translate findings into product security features and conduct periodic internal penetration tests.
Summary Generated by Built In

We are hiring a Senior Security Researcher to join the CTO Office and lead original research in identity security, bringing that work to the broader security community.

You'll have the autonomy to set your own research agenda and the visibility to shape product strategy with what you find.

The core of the role is offensive research targeting identity systems and protocols - identity providers, SSO, authentication and authorization standards (OAuth/OIDC/SAML, WebAuthn/FIDO2, etc.), MFA implementations, directory services, federation, session management, etc. When you find something, you'll drive responsible disclosure with the affected vendors and turn the work into technical write-ups and talks at conferences like Black Hat, DEF CON, CCC, and similar.

Building a public research presence is a central part of this role, not a side effect of it.

Alongside the research work, you'll contribute security feature ideas back into our product and periodically audit and pentest our own platform.

Responsibilities
  • Hunt for novel vulnerabilities, design flaws, and attack techniques across identity providers, authentication and authorization protocols, and related infrastructure. Build proofs-of-concept that prove real-world impact.

  • Run responsible disclosure end-to-end with affected vendors, from initial report through patch validation and CVE assignment.

  • Publish your research as technical blog posts and whitepapers, and present it at top-tier security conferences. Represent the company on stage and in the community.

  • Feed what you learn from breaking things into our product — concrete security features, detections, and design improvements.

  • Periodically turn the same scrutiny on our own platform through internal pentests.

Requirements
  • 5+ years of hands-on offensive security or vulnerability research experience.

  • Strong grasp of identity, authentication, and authorization technologies: OAuth 2.0, OIDC, SAML, Kerberos, WebAuthn/FIDO2, session and token security, federation, and directory services (Active Directory, Entra ID, Okta, or equivalent).

  • A track record of published research - CVEs, technical write-ups, conference talks, bug bounty findings, or comparable public work.

  • Experience driving responsible disclosure with vendors.

  • Excellent technical writing and presentation skills in English. You can take a deep technical finding and make it land with both researchers and executives.

Nice to Have
  • Speaking experience at conferences such as Black Hat, DEF CON, CCC, or similar events.
  • Reverse engineering experience using tools such as IDA, Ghidra, Frida, or equivalent.
  • Familiarity with AWS IAM, Entra ID, GCP IAM, and modern cloud identity architectures.
  • Background in red teaming or identity-focused offensive security operations.
  • Contributions to open-source security projects.

Skills Required

  • 5+ years of hands-on offensive security or vulnerability research experience
  • Strong knowledge of OAuth 2.0, OIDC, SAML, Kerberos, WebAuthn/FIDO2, session and token security, federation, and directory services
  • Published security research, including CVEs, technical write-ups, conference talks, bug bounty findings, or comparable public work
  • Experience managing responsible disclosure with vendors
  • Excellent technical writing and English presentation skills for both technical and executive audiences
  • Conference speaking experience at Black Hat, DEF CON, CCC, or similar events
  • Reverse engineering experience with IDA, Ghidra, Frida, or equivalent tools
  • Familiarity with AWS IAM, Entra ID, GCP IAM, and modern cloud identity architectures
  • Background in red teaming or identity-focused offensive security operations
  • Contributions to open-source security projects
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
50 Employees
Year Founded: 2026

What We Do

NewCore develops a security-first identity platform for the agentic enterprise. Its single architecture discovers, secures, enables, and governs human, machine, and AI-agent identities, helping organizations reduce identity-related risk while supporting secure authentication, access, lifecycle management, and governance. Founded by cybersecurity and enterprise-IT veterans, the company serves enterprise customers and is building infrastructure for workforces where agentic identities increasingly outnumber humans.

Similar Jobs

Clover Security Logo Clover Security

Security Researcher

Artificial Intelligence • Software • Cybersecurity • Automation
In-Office
Tel Aviv, ISR
79 Employees
In-Office
Tel Aviv, ISR
109 Employees
In-Office
Tel Aviv, ISR
109 Employees
In-Office
Tel Aviv, ISR
109 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account