Reflectiz logo

Offensive Web Security Researcher / Penetration Tester

Reflectiz

On-site
Ramat Gan, IL
Full-time
Mid Level
Senior
3+ yrs
Salary not listedPosted 2h ago

Real job — pulled straight from Reflectiz’s careers page · Verified September 30, 2026 · No reposts.

Job description

Reflectiz is hiring a Offensive Web Security Researcher / Penetration Tester — a full-time, based in Ramat Gan, IL role. Apply directly on Reflectiz's careers page below.

Offensive Web Security Researcher / Penetration Tester

Location: Ramat Gan, Israel (IL)

Description

Reflectiz is a fast-growing cybersecurity company specializing in proactive website security. Our unique remote monitoring technology helps organizations reduce security, privacy, and compliance risks-protecting critical digital assets that traditional solutions can’t fully cover.

Since our founding in 2019, we’ve built a global customer base that includes Fortune 500 enterprises and leading brands across North America, EMEA, and APAC. With strong year-over-year growth and a financially solid foundation, Reflectiz offers both stability and exciting opportunities for personal and professional development. Our teams in Israel and the United States foster an inclusive, collaborative culture that combines innovation with professionalism-allowing us to consistently deliver exceptional value to our customers.

We’re looking for a sharp, passionate, hands-on Security Researcher with a strong understanding of web technologies, a hacker mindset, and a genuine drive to explore, challenge, and advance security technology.

In this role, you’ll research real-world web environments, investigate vulnerabilities and attack techniques, analyze suspicious behaviors, and explore how modern websites and browser-based security mechanisms can be bypassed.

You’ll work closely with our Security and R&D teams, turning research findings into security insights and detection capabilities within the Reflectiz platform..

Responsibilities

  • Research web security vulnerabilities, attack techniques, and emerging threats
  • Pen testing - Investigate real-world websites and web applications to identify security weaknesses and suspicious behavior
  • Analyze client-side attacks, malicious scripts, third-party components, and web supply-chain risks
  • Research vulnerabilities and attack vectors such as XSS, CSRF, injection techniques, and browser-based attacks
  • Analyze JavaScript execution, DOM behavior, network requests, and browser activity from a security perspective
  • Investigate security mechanisms such as WAFs, bot protection, authentication mechanisms, fingerprinting, and rate limiting
  • Explore bypass techniques and identify weaknesses in existing security controls
  • Develop scripts and research tools to support security investigations and automate analysis
  • Analyze new vulnerabilities and attack techniques and evaluate their potential impact on web environments
  • Translate security research findings into detection methods and security capabilities for the Reflectiz platform
  • Collaborate with Security Researchers and R&D teams on complex security investigations

Requirements

  • 3+ years of hands-on experience in Pen testing, Security Research, Web Security, Application Security, Offensive Security, or a similar security-focused role
  • Strong understanding of web vulnerabilities, attack techniques, and common web security risks
  • Strong knowledge of modern web technologies, including JavaScript, HTTP/HTTPS, DOM, browser behavior, APIs, and web application architecture
  • Strong investigative mindset and the ability to think like an attacker
  • Ability to independently research complex security problems and turn findings into practical insights
  • Hands-on experience with AI-assisted and agentic coding workflows, using AI tools effectively

Advantage

  • Experience with browser security or Chromium
  • Experience in penetration testing, vulnerability research, bug bounty, AppSec, or offensive security
  • Familiarity with OWASP methodologies and common web security testing tools
  • Degree in Computer Science or a related technical field

Get Offensive Web Security Researcher / Penetration Tester jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
SAP Fioneer logo

Graduate AI Engineer

Munich, Germany
✓ From careers page· 20h ago
Web Summit logo

Senior Quality Engineer

Lisbon
✓ From careers page· 20h ago
Web Summit logo

Senior Quality Engineer

Dublin
✓ From careers page· 20h ago
Web Summit logo

Lead Engineer, Attendee Experience

Lisbon
✓ From careers page· 20h ago

Frequently asked questions

What skills are required for Offensive Web Security Researcher / Penetration Tester at Reflectiz?

The required skills for Offensive Web Security Researcher / Penetration Tester at Reflectiz include: JavaScript, HTTP, API, AI.

What is the seniority level for Offensive Web Security Researcher / Penetration Tester at Reflectiz?

Offensive Web Security Researcher / Penetration Tester at Reflectiz is a Mid Level / Senior level position.

How do I apply for Offensive Web Security Researcher / Penetration Tester at Reflectiz?

You can view the full description and apply for Offensive Web Security Researcher / Penetration Tester at Reflectiz on EchoJobs: https://echojobs.io/job/reflectiz-offensive-web-security-researcher-penetration-tester-mq16a.