Skip to content

Open nowPosted 8 days ago

Senior Offensive Security Engineer

JFrog64 open roles

Where
Tel Aviv/ Netanya, Israel
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Offensive Security EngineerJFrog · Tel Aviv/ Netanya, Israel
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on JFrog's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. JFrog postings stay open a median of 31 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 8 days ago

JFrog median: 31 days open

The posting

At JFrog, we’re reinventing DevSecOps to help the world’s greatest companies innovate. Our team of industry-leading software security experts is a true pioneer, constantly pushing the boundaries with original research and technological innovation. JFrog is a special place with a unique combination of brilliance, spirit, and just all-around great people. Thousands of customers, including the majority of the Fortune 100, trust JFrog to manage, accelerate, and secure their software delivery from code to production – a concept we call “liquid software”. Wouldn't it be amazing if you could join us on our journey?

As an Offensive Security Engineer, you will spearhead JFrog’s offensive security operations and lead advanced threat research initiatives, playing a pivotal role in safeguarding our organization and customers from evolving cyber threats. You will develop and execute Red Team exercises, simulate real-world attacks, and identify security weaknesses in JFrog’s systems and applications. We seek a highly skilled, proactive tech leader who thrives in challenging environments and is passionate about advancing security research and offensive strategies.

As an Offensive Security Engineer, you will…

  • Lead, plan, design, and execute Red Team operations, threat modeling, and adversarial simulations against JFrog’s infrastructure and cloud environments.
  • Drive threat research and intelligence initiatives to stay ahead of emerging cyber threats, attack techniques, and vulnerabilities.
  • Develop and execute advanced attack scenarios to assess security defenses and provide actionable recommendations for improving JFrog’s security posture.
  • Collaborate closely with security engineering, DevOps, and software development teams to implement findings and enhance our defenses.
  • Lead the development of tooling, frameworks, and methodologies to automate and optimize Red Team exercises.
  • Mentor and guide a team of security professionals, fostering a culture of innovation, collaboration, and continuous learning.
  • Participate in incident responses when Red Team exercises reveal vulnerabilities, providing expertise on attack techniques, forensics, and post-attack mitigation.
  • Continuously assess and improve security processes, playbooks, and threat detection mechanisms.

To be an Offensive Security Engineer at JFrog, you need…

  • 7+ years of experience in offensive security operations, Red Teaming, threat hunting, or threat research
  • Deep knowledge of attack techniques, TTPs (Tactics, Techniques, and Procedures), adversary simulations, and threat-hunting methodologies
  • Hands-on experience with Red Team tools, frameworks (e.g., Metasploit, Cobalt Strike, Burp Suite), and custom exploit development
  • Strong experience with cloud platforms (AWS, GCP, Azure) and containerized environments (Kubernetes, Docker)
  • Familiarity with the MITRE ATT&CK Framework and its application in Red Team and threat-hunting scenarios
  • Proficiency with scripting and automation languages for tool development, threat detection, and attack simulation
  • Solid understanding of offensive security best practices, vulnerability management, threat detection, and advanced threat analysis
  • Ability to effectively communicate and collaborate with cross-functional teams, translating complex security concepts into actionable insights
  • A passion for continuous learning, research, and innovation in the fields of offensive security, threat hunting, and cyber threats
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against JFrog's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on JFrog's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    JFrog's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.