Spectrum Labs logo

Application Security Researcher

Spectrum Labs

Ramat Gan, Tel Aviv District, IsraelFull-timeNo compensation foundPosted 2mo agoVerified open 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Ramat Gan, Tel Aviv District, Israel
Schedule
Full-time
Work Authorization
Not specified

Job overview

Spectrum Labs is hiring an Application Security Researcher. Spectrum Labs is seeking a highly motivated and technically proficient Senior Penetration Tester to join their security research division. This role focuses on performing advanced offensive security assessments against major global companies. The ideal candidate will be independent, detail-oriented, organized, eager to learn, and skilled in research and problem-solving.

Key focus areas include Lead and execute comprehensive penetration tests targeting complex web applications, modern API architectures, and enterprise systems., Engage in sophisticated Red Team projects, including identifying undisclosed API endpoints and developing novel bypass techniques., and Contribute to the design, development, and maintenance of proprietary internal security tools and automation frameworks..

Important skills include Independent, Attentive To Details, Organized, Eager To Learn New Things, Research And Solve Problems, and Lead Penetration Tests. Preferred (not required): OSCP, OSWE, eWPTXv2, and CRTP.

Skills & qualifications

RequiredNice to have

Skills

IndependentAttentive to DetailsOrganizedEager to Learn New ThingsResearch and Solve ProblemsLead Penetration TestsExecute Penetration TestsComplex Web Application Penetration TestingModern API Architecture Penetration TestingEnterprise System Penetration TestingRed Team ProjectsIdentification of Undisclosed API EndpointsDevelopment of Novel Bypass TechniquesLateral Movement Within Target EnvironmentsDesign Internal Security ToolsDevelop Internal Security ToolsMaintain Internal Security ToolsDesign Automation FrameworksDevelop Automation FrameworksMaintain Automation FrameworksComplex API Penetration TestingOWASP Top 10PythonJavaScriptGoStatic Analysis of Android ApplicationsDynamic Analysis of Android ApplicationsStatic Analysis of IOS ApplicationsDynamic Analysis of IOS ApplicationsDetoursHookingRuntime Code ManipulationAdvanced Penetration Testing TTPsNetwork Analysis TTPsAuthor Comprehensive ReportsAuthor Technically Rigorous ReportsJADXGhidraIDA ProOSCPOSWEeWPTXv2CRTPOnline AchievementsWrite-UpsHackTheBox ContributionsPwn2Own ContributionsTryHackMe ContributionsBug Bounty Programs ContributionsPublished Security Research

Qualifications

3+ Years Application Security Analysis ExperienceHigh-Level Offensive Certifications

Full job description

Description We are seeking a highly motivated and technically proficient Senior Penetration Tester to join our security research division. This role is dedicated to performing advanced offensive security assessments against the biggest companies in the world

You need to be independent, attentive to details, organized, eager to learn new things, and like to research and solve problems

What you’ll do:

  • Lead and execute comprehensive, technically rigorous penetration tests targeting complex web applications, modern API architectures, and enterprise systems for organizations with significant global presence.

  • Engage in sophisticated Red Team projects, including the identification of undisclosed API endpoints, development of novel bypass techniques for established security controls, and lateral movement within target environments.

  • Contribute substantively to the design, development, and maintenance of proprietary internal security tools and automation frameworks to enhance the efficacy and efficiency of offensive operations. Requirements Requirements:

  • Minimum of 3 years of proven, hands-on experience in application security analysis, with a heavy emphasis on complex API penetration testing and a mastery of the OWASP Top 10 landscape.

  • Proficiency in developing and automating tasks using at least one language like Python, JavaScript, or GoLang.

  • Strong experience with static and dynamic analysis of Android and iOS applications, including hands-on experience with techniques like detours, hooking, and runtime code manipulation

  • Deep, hands-on knowledge of the latest tactics, techniques, and procedures (TTPs) used in advanced penetration testing and network analysis.

  • Ability to author comprehensive and technically rigorous reports detailing identified vulnerabilities and research outcomes.

  • Hands-on experience with industry-standard reversing tools like JADX, Ghidra, or IDA Pro. Nice to have:

  • OSCP, OSWE, eWPTXv2, CRTP, or other high-level offensive certifications.

  • Demonstrated online achievements, write-ups, or contributions on platforms such as HackTheBox, Pwn2Own, TryHackMe, Bug Bounty programs, or published security research. About Alice Alice is a trust, safety, and security company built for the AI era. We safeguard the communicative technologies people use to create, collaborate, and interact—whether with each other or with machines.

In a world where AI has fundamentally changed the nature of risk, Alice provides end-to-end coverage across the entire AI lifecycle. We support frontier model labs, enterprises, and UGC platforms with a comprehensive suite of solutions: from model hardening evaluations and pre-deployment red-teaming to runtime guardrails and ongoing drift detection.

You've read the whole posting — now see how you match it.