Skip to content

Open nowPosted 14 hours ago

Security Research

Transmit Security16 open roles

Where
Tel Aviv-Yafo, Gush Dan, Israel
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity ResearchTransmit Security · Tel Aviv-Yafo, Gush Dan, Israel
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Transmit Security's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 14 hours ago

The posting

We offer the industry’s only platform that fuses customer identity and anti-fraud solutions – customer identity management, identity verification, and fraud prevention.

We sell to industries with large, consumer-facing businesses such as: banking, financial services, insurance, fintech, gaming, ecommerce/retail, telco / media, utilities, etc.

About the Role:

Transmit Security is a top player in its field and is heading into an exciting year. In this role, you will take an integral part in researching, designing, and improving advanced fraud and abuse detection capabilities for a cutting-edge SaaS product.

We are looking for a hands-on security researcher who combines an attacker mindset, fraud-domain curiosity, strong technical depth, and data analysis skills. You will investigate real-world fraud patterns, reproduce attacker techniques, analyze telemetry, enrich our data collection capabilities, discover new security signals, and work closely with product, data, and engineering teams to turn research insights into production-grade detection and prevention mechanisms.

This role is especially relevant for researchers with experience in browser technologies, mobile-native applications, or both. You may work on desktop and mobile browsers, browser APIs, browser automation, client-side signals, native mobile applications, Android/iOS behavior, mobile security, emulators, device signals, and mobile automation.

You will help expand our visibility into new signals and patterns that improve fraud detection, model performance, and customer protection.

If you are a talented researcher who enjoys solving complex problems, working with messy real-world data, and building practical defenses against modern fraud and abuse, we want you to join our team.

What you’ll do:

  • Research emerging fraud and abuse techniques across account takeover, bots, automation, phishing, social engineering, device spoofing, emulators, remote access tools, suspicious network infrastructure, and related attack vectors.
  • Identify, design, and validate new data collection opportunities, security signals, behavioral patterns, device indicators, browser indicators, and mobile app indicators.
  • Analyze real-world telemetry, customer-provided labels, behavioral signals, device signals, network indicators, and attack patterns to identify detection opportunities.
  • Reproduce attacker techniques in lab and production-like environments, generate telemetry, identify detection gaps, and translate findings into detection logic.
  • Design, validate, and tune detection and prevention mechanisms with attention to coverage, explainability, false positives, customer impact, and production stability.
  • Build research infrastructure, analysis workflows, and internal tools using Python.
  • Produce robust data features that can later be used by machine learning models, detection logic, rules, dashboards, and customer-facing insights.
  • Work with model training pipelines, evaluate model behavior, compare training and validation results, and help determine whether new features improve detection quality.
  • Collaborate closely with data science, engineering and product, teams to take ideas from research hypothesis through validation, implementation, monitoring, and production feedback.
  • Stay up to date with fraud trends, attacker tooling, automation frameworks, browser abuse techniques, mobile abuse techniques, malware behavior, phishing techniques, and underground ecosystem developments.
  • Communicate findings clearly to technical and non-technical stakeholders, including recommended actions, tradeoffs, expected impact, and model/detection quality considerations.

What you’ll need:

  • At least 3 years of experience in security research, fraud research, detection engineering, threat research, mobile security research, browser security research, or a similar hands-on technical role.
  • Bachelor’s degree in Computer Science, Cybersecurity, Data Science, or a related field or equivalent hands-on experience.
  • Strong hands-on experience with at least one of the following areas:
  • Desktop or mobile browsers, browser APIs, browser automation, browser fingerprinting, web signals, or client-side web security.
  • Native mobile applications for Android or iOS, mobile OS behavior, device signals, emulators, mobile automation, app instrumentation, or mobile security.
  • Strong understanding of web technologies, mobile technologies, APIs, application behavior, and modern attack techniques.
  • Strong Python skills and experience building research tools, automation, data analysis workflows, detection prototypes, or feature engineering pipelines.
  • Experience analyzing messy real-world data, investigating anomalies, validating hypotheses, and drawing practical conclusions from incomplete information.
  • Familiarity with machine learning training and validation concepts, such as train/test split, validation sets, overfitting, leakage, feature quality, precision/recall, false positives, false negatives, and model evaluation.
  • Ability to produce data features in a structured, reliable, and model-friendly way.
  • Ability to think like an attacker while designing reliable, scalable, and explainable defenses.
  • Strong problem-solving skills, independence, persistence, and a “getting things done” attitude.
  • Excellent communication and interpersonal skills.
  • Ability to work closely with engineering, product, and data science teams and translate research insights into practical product capabilities.

Advantages:

  • Experience with both browser-based and mobile-native research.
  • Experience with fraud domains such as account takeover, new account fraud, identity theft, money mule activity, payment fraud, or first-party fraud.
  • Knowledge of bots, automation frameworks, credential stuffing, scraping, and anti-detection techniques.
  • Experience with browser internals, JavaScript runtime behavior, DOM APIs, WebView behavior, browser automation, headless browsers, or browser anti-detection techniques.
  • Experience with mobile app lifecycle, permissions, sensors, networking, storage, mobile identifiers, rooted/jailbroken devices, hooking, instrumentation, repackaging, or anti-tampering techniques.
  • Experience with browser fingerprinting, mobile fingerprinting, device intelligence, behavioral biometrics, or client-side telemetry.
  • Experience with malware analysis, phishing kits, remote access tools, proxy/VPN infrastructure, or underground fraud ecosystems.
  • Experience with detection quality measurement, false-positive analysis, rule tuning, model evaluation, feature evaluation, or production monitoring.
  • Experience using notebooks, pandas, SQL, data visualization tools, or other analysis environments for research and validation.
  • Experience working with data scientists, ML engineers, or ML training pipelines.

#LI-TL1 #LI-Hybrid

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Transmit Security's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Transmit Security's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Transmit Security's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.