Senior Offensive Security Engineer
Tel Aviv/ Netanya, Israel·Posted today
kubernetesdockerawsgcp
<p>At JFrog, we’re reinventing DevSecOps to help the world’s greatest companies innovate. Our team of industry-leading software security experts is a true pioneer, constantly pushing the boundaries with original research and technological innovation. JFrog is a special place with a unique combination of brilliance, spirit, and just all-around great people. Thousands of customers, including the majority of the Fortune 100, trust JFrog to manage, accelerate, and secure their software delivery from code to production – a concept we call “liquid software”. Wouldn't it be amazing if you could join us on our journey?</p> <p>As an Offensive Security Engineer, you will spearhead JFrog’s offensive security operations and lead advanced threat research initiatives, playing a pivotal role in safeguarding our organization and customers from evolving cyber threats. You will develop and execute Red Team exercises, simulate real-world attacks, and identify security weaknesses in JFrog’s systems and applications. We seek a highly skilled, proactive tech leader who thrives in challenging environments and is passionate about advancing security research and offensive strategies.</p> <h5><strong>As an </strong><strong>Offensive Security Engineer,</strong><strong> you will…</strong></h5> <ul> <li>Lead, plan, design, and execute Red Team operations, threat modeling, and adversarial simulations against JFrog’s infrastructure and cloud environments.</li> <li>Drive threat research and intelligence initiatives to stay ahead of emerging cyber threats, attack techniques, and vulnerabilities.</li> <li>Develop and execute advanced attack scenarios to assess security defenses and provide actionable recommendations for improving JFrog’s security posture.</li> <li>Collaborate closely with security engineering, DevOps, and software development teams to implement findings and enhance our defenses.</li> <li>Lead the development of tooling, frameworks, and methodologies to automate and optimize Red Team exercises.</li> <li>Mentor and guide a team of security professionals, fostering a culture of innovation, collaboration, and continuous learning.</li> <li>Participate in incident responses when Red Team exercises reveal vulnerabilities, providing expertise on attack techniques, forensics, and post-attack mitigation.</li> <li>Continuously assess and improve security processes, playbooks, and threat detection mechanisms.</li> </ul> <h5><strong>To be an </strong><strong>Offensive Security Engineer</strong><strong> at JFrog, you need…</strong></h5> <ul> <li>7+ years of experience in offensive security operations, Red Teaming, threat hunting, or threat research</li> <li>Deep knowledge of attack techniques, TTPs (Tactics, Techniques, and Procedures), adversary simulations, and threat-hunting methodologies</li> <li>Hands-on experience with Red Team tools, frameworks (e.g., Metasploit, Cobalt Strike, Burp Suite), and custom exploit development</li> <li>Strong experience with cloud platforms (AWS, GCP, Azure) and containerized environments (Kubernetes, Docker)</li> <li>Familiarity with the MITRE ATT&CK Framework and its application in Red Team and threat-hunting scenarios</li> <li>Proficiency with scripting and automation languages for tool development, threat detection, and attack simulation</li> <li>Solid understanding of offensive security best practices, vulnerability management, threat detection, and advanced threat analysis</li> <li>Ability to effectively communicate and collaborate with cross-functional teams, translating complex security concepts into actionable insights</li> <li>A passion for continuous learning, research, and innovation in the fields of offensive security, threat hunting, and cyber threats</li> </ul>