JFrog

Senior Offensive Security Engineer

JFrog
Apply
1 day ago
Netanya, Israel or Tel Aviv-Yafo, IsraelSenior

Responsibilities

  • Lead, plan, design, and execute Red Team operations, threat modeling, and adversarial simulations against infrastructure and cloud environments.
  • Conduct threat research and intelligence initiatives focused on emerging cyber threats, attack techniques, and vulnerabilities.
  • Develop advanced attack scenarios, custom tooling, frameworks, and methodologies to assess defenses and automate Red Team exercises.
  • Collaborate with security engineering, DevOps, and software development teams to implement findings and strengthen defenses.
  • Mentor and guide security professionals while fostering innovation, collaboration, and continuous learning.
  • Participate in incident response, forensics, post-attack mitigation, and improvements to security processes, playbooks, and threat detection mechanisms.

Requirements

  • 7+ years of experience in offensive security operations, Red Teaming, threat hunting, or threat research.
  • Deep knowledge of attack techniques, TTPs, adversary simulations, and threat-hunting methodologies.
  • Hands-on experience with Metasploit, Cobalt Strike, Burp Suite, Red Team frameworks, and custom exploit development.
  • Strong experience with AWS, GCP, Azure, Kubernetes, and Docker.
  • Familiarity with the MITRE ATT&CK Framework and its use in Red Team and threat-hunting scenarios.
  • Proficiency with scripting and automation languages for tool development, threat detection, and attack simulation.
  • Understanding of offensive security practices, vulnerability management, threat detection, and advanced threat analysis.
  • Strong communication and collaboration skills, with the ability to translate complex security concepts into actionable insights.
  • Passion for continuous learning, research, and innovation in offensive security, threat hunting, and cyber threats.
JFrog

About JFrog

1,001-5,000 employees

JFrog builds a software supply chain platform used by developers and DevOps teams to store, secure, and distribute software artifacts and releases. Its subscription-based SaaS and self-managed products include Artifactory, Xray, Pipelines, and Distribution, and the company, founded in 2008 and headquartered in Sunnyvale, CA, went public on NASDAQ in 2020, serving large enterprises including many Fortune 100 firms.

Contact me