Tel Aviv-Yafo
US, Remote

Senior Security Researcher

Full-time
|

Description

Zafran is looking for an experienced Security Researcher to join our growing research team. The team's responsibility is vulnerability research for both PR purposes and research for Zafran’s product. In this role, you will focus on vulnerability research of open-source projects and reverse engineering of low-level binaries. The team also focuses on AI security and low-level product security research.

A key part of your work will include analyzing internal code and identifying security risks to improve Zafran’s overall security posture and support our PR efforts.


About Zafran

The Zafran Threat Exposure Management Platform is the first and only consolidated platform that integrates with your security tools to reveal, remediate, and mitigate the risk of exposures across your entire infrastructure. Backed by Sequoia, Zafran uses an agentless approach to reveal what is truly exploitable, while reducing manual prioritization and remediation through automated response workflows


What you will do

  • Vulnerability Discovery: Research and discover vulnerabilities across AI applications, low-level products, and cloud environments, including the development of functional Proof-of-Concepts (PoCs).
  • Public Research & PR: Publish technical blogs and present your research at major security conferences.
  • Technical Product Research: Produce in-depth technical research and conduct reverse engineering of security products to directly support the development of Zafran’s product and platform.
  • Stay up to date with newly discovered CVEs, attack techniques, and threat trends
  • Cross-Functional Collaboration: Partner with product and engineering teams to help improve Zafran’s security.

About Zafran

What you will do

Requirements

  • 5+ years of hands-on experience in security research, including a track record of finding vulnerabilities in complex systems..
  • Strong understanding of vulnerabilities, exploit techniques, and attack vectors.
  • Experience in reverse engineering binaries, security products, and complex low-level systems.
  • Hands-on experience with Linux systems, networking, and cloud environments
  • Ability to analyze complex systems and think like an attacker
  • Strong written communication skills in English, including technical documentation. 
  • Self-driven, curious, and passionate about security research


Experience with the following is a plus

  • Experience contributing to blogs, public research, conference talks, or media-facing security content
  • Familiarity with AI systems, AI security, and model behavior.
  • Experience in software development.

Apply for this position