Security Researcher
About The Position
Reflectiz is a fast-growing cybersecurity company specializing in proactive website security. Our unique remote monitoring technology helps organizations reduce security, privacy, and compliance risks-protecting critical digital assets that traditional solutions can’t fully cover.
Since our founding in 2019, we’ve built a global customer base that includes Fortune 500 enterprises and leading brands across North America, EMEA, and APAC. With strong year-over-year growth and a financially solid foundation, Reflectiz offers both stability and exciting opportunities for personal and professional development. Our teams in Israel and the United States foster an inclusive, collaborative culture that combines innovation with professionalism-allowing us to consistently deliver exceptional value to our customers.
We’re looking for a hands-on Security Researcher with a strong understanding of web technologies and a hacker mindset.
In this role, you’ll research real-world web environments, investigate vulnerabilities and attack techniques, analyze suspicious behaviors, and explore how modern websites and browser-based security mechanisms can be bypassed.
You’ll work closely with our Security and R&D teams, turning research findings into security insights and detection capabilities within the Reflectiz platform..
Responsibilities
- Research web security vulnerabilities, attack techniques, and emerging threats
- Investigate real-world websites and web applications to identify security weaknesses and suspicious behavior
- Analyze client-side attacks, malicious scripts, third-party components, and web supply-chain risks
- Research vulnerabilities and attack vectors such as XSS, CSRF, injection techniques, and browser-based attacks
- Analyze JavaScript execution, DOM behavior, network requests, and browser activity from a security perspective
- Investigate security mechanisms such as WAFs, bot protection, authentication mechanisms, fingerprinting, and rate limiting
- Explore bypass techniques and identify weaknesses in existing security controls
- Develop scripts and research tools to support security investigations and automate analysis
- Analyze new vulnerabilities and attack techniques and evaluate their potential impact on web environments
- Translate security research findings into detection methods and security capabilities for the Reflectiz platform
- Collaborate with Security Researchers and R&D teams on complex security investigations
Requirements
- 3+ years of hands-on experience in Security Research, Web Security, Application Security, Offensive Security, or a similar security-focused role
- Strong understanding of web vulnerabilities, attack techniques, and common web security risks
- Strong knowledge of modern web technologies, including JavaScript, HTTP/HTTPS, DOM, browser behavior, APIs, and web application architecture
- Strong investigative mindset and the ability to think like an attacker
- Ability to independently research complex security problems and turn findings into practical insights
Advantage
- Experience with browser security or Chromium
- Experience in penetration testing, vulnerability research, bug bounty, AppSec, or offensive security
- Familiarity with OWASP methodologies and common web security testing tools