Silverfort is on a mission to bring identity security everywhere – to every human, machine, and AI agent, both on-prem and in the cloud. Our unique technology secures identities & access at runtime, in ways that weren’t possible before. With the broadest identity security platform in the market, trusted by more than 1,000 customers, including many Fortune 100 companies, Silverfort is uniquely positioned to lead the fast-growing identity security category.
Joining Silverfort means becoming part of a fast-moving team with a culture of innovation and collaboration, that goes above and beyond to help our customers and each other, on a journey to reshape the future of identity security.
We are hiring a Security Researcher to join us. As a Security Researcher, you'll play a crucial role in leading and positioning Silverfort as an identity security leader. By conducting deep original vulnerability research on web applications, SaaS platforms, and identity systems, with focus on Identity for AI, including AI agents, automation, and non-human identities. This role has a direct impact on the product, and the researcher is expected to innovate and conduct thorough vulnerability research by leveraging state-of-the-art tools and methodologies. It is expected to finalize productions and coordinate their execution with multiple departments.
Responsibilities- Initiate and conduct cloud research initiatives: stay current with the threat landscape to identify trends in cloud infrastructure security, threat actors, novel attack techniques, and vulnerabilities in cloud-based and cloud native environments and workloads
- Research sophisticated threats and vulnerabilities in cloud provider infrastructure and containerized applications and workloads, in the context of identity security
- Develop PoCs, tools, and scripts to automate vulnerability discovery and validation
- Collaborate with Product and Engineering teams to turn research into productized features
- Provide cloud security thought leadership: share insights and best practices with the broader security community through publications, conference presentations, and technical blogs
- Conduct offensive simulations to build realistic attack scenarios and assess and communicate their business impact
- 3+ years of experience in Offensive Security, Vulnerability Research, or Web Application Security
- Strong web hacking background with a deep understanding of web application and API vulnerabilities, including server-side, client-side, authentication, and business logic flaws
- Hands-on experience with industry-standard tools such as Burp Suite, fuzzers, debuggers, and reverse engineering frameworks
- Deep understanding of Internet and application protocols (for example, HTTP, TLS, DNS, WebSocket), including hands-on protocol analysis and deep packet inspection (Wireshark, custom dissectors, traffic interception)
- Proven, publicly verifiable track record of vulnerability discovery, such as CVEs, vendor advisories, bug bounty disclosures, or independent findings. Technical details must exist online and be attributable to the researcher
- Strong English communication and writing skills, with the ability to produce clear technical outputs for internal and external audiences
- Public technical writing, including personal blog, guest posts, conference talks, or coverage of the research by others
Advantages
- Knowledge of authentication and authorization protocols (OAuth, OIDC, SAML, Kerberos)
- Familiarity with cloud providers (AWS, GCP, Azure)
- Container and Kubernetes security
- Familiarity with AI systems, AI security, and model behavior
- Knowledge of reverse engineering or malware analysis
- Conference speaking experience
Skills Required
- 3+ years of experience in cloud security research or offensive security research
- Strong programming skills (Python preferred), including the ability to develop research tools
- Proven track record of conducting vulnerability research and responsibly disclosing impactful security vulnerabilities
- Strong understanding of at least one major cloud provider (AWS, GCP, Azure)
- Knowledge of at least one SaaS authentication protocol (SAML, OIDC, OAuth)
Silverfort Compensation & Benefits Highlights
-
Leave & Time Off Breadth — Generous time off spans paid holidays, wellness days, bereavement leave, and paid sick time from day one, with a flexible time off policy and quarterly companywide recharge days creating extended long weekends.
-
Healthcare Strength — Comprehensive healthcare includes medical, dental, and vision coverage, alongside FSA, life and disability insurance, and pet insurance. Wellness support is reinforced with programs, fitness stipends, and a monthly reimbursement for personal care and wellness.
-
Equity Value & Accessibility — Company equity is offered via stock options to all permanent employees, augmenting total rewards beyond base pay. Performance bonuses and a home-office stipend further strengthen the financial package.
Silverfort Insights
What We Do
Fueled by a belief that identity professionals deserve better, we found a way to break down the silos of identity security—eliminating the gaps and blind spots left behind by a patchwork of point solutions. The Silverfort Identity Security Platform is the first to deliver end-to-end identity security, protecting every identity in the cloud, on-prem, humans, machines, and everything in between. Our patented technology—Runtime Access Protection (RAP)—natively integrates with the entire IAM infrastructure, giving businesses visibility into all identities, analyzing every access, and extending active protection to resources that could not be protected previously—including NHIs, legacy systems, command line tools, and IT/OT infrastructure. It is easy to deploy and use, and doesn’t disrupt business operations, resulting in better security outcomes with less work. Silverfort is the identity security platform that both identity and security professionals deserve, earning the trust of more than 1,000 leading organizations, including several Fortune 50 companies.
Why Work With Us
We believe that our high retention rates stem from our employees’ confidence in their ability to develop and progress within the company. We prioritize a supportive and encouraging environment that fosters a positive people culture, enhancing employee satisfaction, engagement, and their desire to stay and grow with us.
Gallery
Silverfort Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Employees engage in a combination of remote and on-site work.









