Experience. 8+ years in security research, vulnerability analysis, or applied security engineering.
Startup DNA. You have worked in an early stage or 0 to 1 environment. Comfortable with ambiguity, shipping without a big org behind you, and changing direction when the data says so. This is a requirement, not a bonus.
Research to product track record. You have turned research into things that shipped: features, tools, detections in production. Not just papers or reports.
Technical depth. Deep expertise in modern application stacks (microservices, containers, cloud platforms). You understand how these systems actually break.
Builder skills. Strong programming ability in at least one modern language (Python, Go, TypeScript). Comfortable writing production quality code.
Data rigor. Experience designing experiments, building datasets or benchmarks, and measuring quality quantitatively. You do not ship on vibes.
LLM fluency. Hands on experience applying LLMs to real problems, whether evaluation, prompting, fine tuning, or agentic systems, or a demonstrated ability to get there fast.
Proven findings. A history of discovering serious vulnerabilities (CVEs welcome) and responsible disclosure.
Communication. You can explain a complex attack and its real impact clearly to engineers, executives, and customers.
Work authorization. Permanent authorization to work in the US for the San Francisco role, or in Israel for the Israel role.