Mid-Senior Pentest- Offensive Security

Momentum
Momentum

Tel Aviv-Yafo, Israel

Posted on Oct 8, 2026

he Experience
Join our Offensive Security Pentest team in Israel as a hands-on Mid-Senior Offensive Security Engineer. You think like an attacker and find weaknesses across our products, platforms and enterprise environment. You turn those findings into lasting security improvements, including for AI-powered features.

What You'll Actually Be Doing

  • Lead deep, manual penetration tests of web applications, APIs, cloud and container environments, and identity systems. Show the real-world impact of what you find.
  • Uncover systemic and design-level weaknesses, not just isolated bugs, and chain them across trust boundaries to push secure-by-default improvements.
  • Deliver clear, detailed reports with exploitation paths and practical, prioritized fixes. Help engineers understand root causes and close gaps.
  • Work with engineering, security architecture, product security, detection and response, and incident response teams to improve designs, alerts and response. Build tools and automation that make testing faster and more consistent.



You're Our Person If...

  • You have about 4 years of hands-on experience in penetration testing, application security, red teaming or vulnerability research.
  • You have run complex offensive security engagements in production or production-like environments, using manual exploitation, vulnerability chaining and proof-of-concept development.
  • You understand application vulnerabilities, authentication and authorization attacks, and cloud and hybrid attack surfaces. You can write scripts or tools to support your testing.
  • You explain risk, exploitation techniques and remediation clearly to engineers, security teams and leaders.
  • Degree or equivalent relevant experience required. Experience will be evaluated based on the core competencies for the role (e.g. extracurricular leadership roles, military experience, volunteer roles, work experience, etc.)



Even Better If...

  • You have published security research, conference talks, advisories or publicly disclosed vulnerabilities.
  • You have experience with adversary emulation, long-running red team campaigns, or working alongside detection and response teams.
  • You know AI and large language model security, or identity-focused cloud architectures and large-scale distributed systems.
  • You have led secure-by-design initiatives and balance security rigor with product speed and developer experience.