Offensive Security Researcher

  • Full-time
  • CP Department: Exposure Management
  • Office Location: Tel-Aviv
  • Career site Category: R&D

Company Description

At Check Point, what you do matters. Every day, we protect over 100,000 organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation.

Our prevention-first approach safeguards hybrid networks, cloud environments, digital workspaces, and AI systems, stopping attacks before they happen.

This is where innovation meets real-world impact. You’ll help customers across industries operate with confidence in a rapidly changing digital world, working alongside smart, curious people who take ownership, challenge assumptions, and solve complex problems.

We’re proud to be recognized by TIME, Newsweek, and Forbes for excellence and workplace culture.

What really sets Check Point apart is the opportunity to grow, contribute, and help companies navigate their AI transformation securely.

If you’re excited to work at the forefront of AI-driven security on a global scale, this is the place to do it.

Job Description

The Exposure Management Research Group at Check Point Software Technologies is expanding. We are looking for an experienced Offensive Security Researcher to join our newly formed AEV Team and lead the offensive side of our Agentic Exposure Validation (AEV) research.

About the group

The Exposure Management Research Group is the research arm behind Check Point's Exposure Management platform. The platform helps organizations see and reduce their risk from the outside in, across their external attack surface, threat intelligence, and digital risk. The group brings together vulnerability researchers, threat intelligence analysts, phishing researchers, and data scientists. Together, we track threat actors and campaigns, analyze vulnerabilities and active exploitation, and turn that research into detections, intelligence, and validation capabilities that serve thousands of customers worldwide. Our work relies heavily on data science, machine learning, and agentic AI to operate at scale.

About the position

Exposure validation goes beyond identifying that a vulnerability exists. Its purpose is to show whether an attacker could actually exploit that vulnerability, and how far they could get. In this position, you are responsible for bringing real offensive expertise into our AEV capability, which runs on an agentic AI system that validates exposures across our customers' environments.

You conduct hands-on offensive research, define the exploitation methodologies the system follows, and set the standard for what a validated, customer-ready finding looks like. You also work closely with our threat intelligence and detection teams, so that proven attack paths turn into protections for our customers.

This is a research position with direct product impact. It combines practical red team work with shaping how an AI-driven platform conducts, reasons about, and reports offensive activity.

What you'll do

  • Design and run offensive research against external attack surfaces: web applications, APIs, cloud-exposed services, identity, and edge infrastructure
  • Turn single findings into demonstrated impact through exploit chaining, lateral movement, and blast-radius analysis
  • Write and maintain the exploitation methodologies and attack hypotheses our agentic AEV engine runs on
  • Review agent runs and findings. Separate proven impact from claimed impact, and turn the gaps you find into better prompts, methods, and guardrails
  • Set the bar for customer-ready findings: a clear impact story, a reproducible chain, and remediation guidance a security team can act on
  • Work with threat intelligence researchers to turn in-the-wild attacker behavior (named actors, active campaigns, newly exploited vulnerabilities) into validation plays
  • Help close the purple loop by turning proven attack paths into detection and protection logic, and working with detection engineering on coverage
  • Contribute to the team's research output, including internal knowledge sharing and, where it fits, external publications and talks

Qualifications

 

  • 2+ years of hands-on offensive security experience: red teaming, penetration testing, or offensive research
  • Real exploitation depth beyond confirming vulnerabilities, including exploit chaining, privilege escalation, lateral movement, and showing business impact
  • Comfort with the non-deterministic side of offense: business logic flaws, misconfigurations, credential and token abuse, and using information disclosure as an entry point
  • Strong scripting and automation skills (Python preferred)
  • Clear written communication. You can explain a complex attack chain to an engineer and to a CISO

Strong advantage

  • A consulting background covering many customer environments, not one internal estate. You know what customers value in an engagement deliverable and how to present it
  • Broad exposure to defensive technologies, security controls, and vendors, and an understanding of what attacks look like from the defender's side
  • Experience with template-based or automated scanning frameworks (for example, Nuclei)
  • Detection engineering experience (Snort/Suricata, YARA, SIEM detection logic)
  • Experience working with large language models (LLMs) or agentic AI workflows, or a strong interest in shaping how AI systems do offensive work

Nice to have

  • Offensive certifications (OSCP, OSEP, OSWE, CRTO, or similar), public CVEs, conference talks, or published research

Additional Information

Why join us

  • Impact at scale. A technique you capture once runs across thousands of customer environments
  • A new category. Agentic exposure validation is being defined right now, and you help define it
  • A strong research bench. You work next to threat intelligence, vulnerability research, and data science researchers at one of the largest cyber security companies in the world

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy NoticeImprint