Island logo

Senior Security Researcher

Island

Tel Aviv-Yafo, Tel Aviv District, IsraelFull-timeNo compensation foundPosted 4mo agoVerified open 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Tel Aviv-Yafo, Tel Aviv District, Israel
Schedule
Full-time
Work Authorization
Not specified

Job overview

Island is hiring a Senior Security Researcher. Island is seeking a Senior Security Researcher to join their security research team, dedicated to identifying and mitigating threats across browser, network, and endpoint landscapes. The role involves developing offensive tradecraft to discover new attack vectors and exploits, then engineering robust, product-level mitigations. The ideal candidate thrives on both offensive and defensive security, contributing to the security capabilities of Island's enterprise platform.

Key focus areas include Discover new attack vectors, abuse patterns, and security gaps in browsers, web applications, OS internals, and enterprise workflows, Design and implement detections, mitigations, and security policies informed by offensive findings, and Perform reverse engineering on malware, exploits, and obfuscated code across Windows, macOS, and browser environments.

Successful candidates bring 5+ Years Security Research Experience, 5+ Years Vulnerability Research Experience, and 5+ Years Malware Analysis Experience. Important skills include Offensive Research, Defensive Engineering, Vulnerability Analysis, Malware Analysis, Reverse Engineering, and Web Security. Preferred (not required): Browser Internals, Endpoint Security, EDR, and DLP.

Skills & qualifications

RequiredNice to have

Skills

Offensive ResearchDefensive EngineeringVulnerability AnalysisMalware AnalysisReverse EngineeringWeb SecurityBrowser SecuritySupply-Chain SecurityThreat IntelligenceTechnical Blog PostsPublic ResearchPresent at ConferencesOffensive Security MindsetAnalytical SkillsOperating System InternalsDynamic Analysis ToolsStatic Analysis ToolsCode for AutomationCode for ToolingCode for Proof-of-ConceptsCommunicationBrowser InternalsEndpoint SecurityEDRDLPSemgrepCodeQLJoernSoftware Supply-Chain Attack PatternsPublished Security Research

Qualifications

5+ Years Security Research Experience5+ Years Vulnerability Research Experience5+ Years Malware Analysis Experience5+ Years Threat Intelligence Experience5+ Years Detection Engineering Experience

Full job description

Description We’re a team of hungry, high-character professionals from all backgrounds who came together to reinvent work for the modern enterprise.

Island, the Enterprise Browser is the ideal enterprise workplace where work flows freely while remaining fundamentally secure. With the core needs of the enterprise naturally embedded in the browser itself, Island gives organizations complete control, visibility, and governance over the last mile, while delivering the same smooth Chromium-based browser experience users expect.

What we’re building now - it’s not another solution. It’s a whole new chapter for enterprise work.

About the Team

We are Island's security research team, dedicated to identifying and mitigating threats across the browser, network, and endpoint landscape. Our research directly shapes the security capabilities of Island's enterprise platform—from detection logic to protective controls.

We operate with a purple team mindset : we think like attackers to build superior defenses. At Island, the cycle is complete—the same researcher who discovers a novel vulnerability or attack technique is the one who designs the detections and product features to neutralize it.

The Role

We are looking for a Security Researcher who thrives on both sides of the fence. You will develop offensive tradecraft—discovering new attack vectors and writing exploits—then use that perspective to engineer robust, product-level mitigations. If you’re energized by finding a novel browser attack on Monday and shipping the defense for it by Friday, this role is for you.

Key Responsibilities

  • Offensive Research: Discover new attack vectors, abuse patterns, and security gaps in browsers, web applications, OS internals, and enterprise workflows.

  • Defensive Engineering: Design and implement detections, mitigations, and security policies informed by your offensive findings; close the loop from attack to protection.

  • Vulnerability & Malware Analysis: Perform reverse engineering on malware, exploits, and obfuscated code across Windows, macOS, and browser environments.

  • Web & Browser Security: Research techniques ranging from classic vulnerabilities (XSS, SSRF) to browser-specific primitives (extension abuse, DOM manipulation, same-origin bypasses).

  • Supply-Chain Security: Investigate threats in software supply chains, including browser extension marketplaces and package registries.

  • Threat Intelligence: Correlate signals across multiple sources to identify malicious infrastructure and adversary TTPs.

  • Public Impact: Write technical blog posts, publish research, and represent Island at major security conferences (Black Hat, DEF CON, etc.). Requirements Requirements:

  • 5+ years of experience in at least one of the following: security research, vulnerability research, malware analysis, threat intelligence, or detection engineering

  • Offensive security mindset with the ability to flip to the defensive side — finding attacks and building mitigations

  • Strong analytical skills — comfortable digging into unfamiliar code, protocols, or systems and figuring out how they break

  • Familiarity with operating system internals (Windows and/or macOS)

  • Hands-on experience with reverse engineering or dynamic/static analysis tools

  • Ability to write code for automation, tooling, and proof-of-concepts

  • Strong written and verbal communication — ability to write compelling research and present at conferences Nice to have:

  • Solid understanding of web and browser security fundamentals

  • Experience with browser internals or browser extension security

  • Background in endpoint security, EDR, or DLP

  • Experience with static analysis tools (Semgrep, CodeQL, Joern, or similar)

  • Knowledge of software supply-chain attack patterns

  • Published security research — blog posts, CVEs, or conference talks (Black Hat, DEF CON, BSides, etc.)

You've read the whole posting — now see how you match it.