Case Study: How HiBob Scaled Its Internal Red Team and Closed Gaps Across Every Environment
When HiBob's Global CISO Tamir Ronen needed a solution that could catch complex business logic flaws across their cloud environments, he knew he needed continuous, attacker-grade testing that could extend his internal red team, not another tool generating noise.
HiBob is a global, cloud-native HR technology company. Its platform manages the entire employee lifecycle — onboarding, time and attendance, compensation, payroll, performance reviews, and offboarding — which means it handles sensitive employee data every single day. At that scale, and with development moving as fast as it does, security can’t be a point-in-time exercise.
When Tamir Ronen, Global CISO at HiBob, set out to strengthen his security testing program, he needed assurance that the hardest-to-find risks were being found and proven continuously, across every environment his team ships to.
Hear from Tamir why HiBob partnered with Novee, and what’s changed since.
The vulnerabilities pattern-matching tools can’t reach
HiBob ships fast, and the pace only climbs as new development tools enter the stack. For Tamir, the risks that mattered most were precisely the ones a known-pattern tool isn’t built to find.
“Our main challenge is to keep pace with the rapid development of new technologies, such as vibe-coded tools, which create increasingly complex security risks that are extremely difficult to mitigate in real time. Tools that flag known patterns do not reveal the real critical security gaps in the platform itself.”
HiBob wasn’t looking for more findings — they were looking for the right ones.
“We were looking for solutions that were easier to use and delivered more high quality findings, which means fewer false positives.”
A pentesting platform with a purpose-built offensive model behind it
As one of Novee’s earliest adopters, Tamir’s team went deep on the distinction between an offensive AI trained on real attacker tradecraft and a general-purpose LLM bolted onto an existing scanner.
“Novee trains a purpose-built offensive AI model from the ground up on real attacks and exploits, rather than wrapping an LLM around an existing scanner. That distinction was fundamental for us. The main benefit was the option to train Novee on our tech stack to identify real vulnerabilities in our business logic, extending the capabilities of an internal red team, while working 24/7.”
Novee focused on delivering results that the HiBob team didn’t need to double-check, streamlining work and giving them a partner they could trust.
Trained on HiBob’s environment, testing continuously
HiBob’s platform is complex; multi-tenant, with an intricate permission model spanning fields, categories, and tables across parent-child company structures. Novee learned it, then kept testing against it on every change.
“The first complete run took roughly 48 hours to map everything, such as cloud resources, repos, environments, and the attack surface itself. My team trained it on our complex permission model. It now automatically checks permission enforcement on every pull request and endpoint. We run Novee across all our environments.”
Permission enforcement testing that used to be slow, manual work now runs automatically on every pull request, freeing the team to focus on the risks that need human judgment.
Context-aware findings the team can trust
A finding is only worth acting on if it’s real. Novee reasons about context the way an attacker would, and closes its own gaps as fast as they surface.
“Novee is context-aware in ways scanners are not. When it finds a secret, it verifies against our cloud account before flagging, so rotated honey pot keys don’t turn into a false critical. Every gap we identified early on, they have closed, such as WAF handling (which now performs tests both with and without the WAF, including bypass), as well as native mobile testing and a redirect looping issue.”
Because each customer’s environment feeds how Novee’s model improves, the gaps HiBob raised were closed quickly.
Novee becomes an extension of the HiBob team
HiBob’s attack surface keeps expanding as it opens its platform to external AI tools — and continuous coverage has to keep pace with it.
“HiBob is opening an MCP server for the product, and that surface continues to grow as more tools are introduced.”
“Novee continuously scans it through its CI/CD and CLI capabilities, so new tools and agentic endpoints are tested as they are deployed.”
After a year and a half, the relationship delivers added capacity to the HiBob team:
“Every gap we have brought to Novee over the last year and a half, they have closed. Novee feels more like an extension of my team than a pen testing tool we bought.”
See for yourself the continuous offensive and defensive cybersecurity platform that proves real exploitability and automatically retests every fix. Get a demo.