Clear your external findings backlog

Novee Exploitability Validation

Clear your external findings backlog

Novee Exploitability Validation
Back to jobs

Application Security Researcher

Tel Aviv Office
Full-time

About The Position

About Us

Novee is the AI penetration testing platform built for a world where attackers operate at machine speed. Founded in Tel Aviv in April 2025 by a team with decades of nation-state offensive security experience - including veterans of Unit 8200, Iron Dome, and elite zero-day research - we're turning that expertise into a platform that thinks like a real attacker, runs continuously, and uncovers the novel vulnerabilities that manual testers and scanners miss.

We raised $51.5M in four months, backed by top investors YL Ventures, Canaan Partners, and Oren Zeev - one of the fastest funding trajectories in offensive security. Our proprietary AI model outperforms frontier LLMs by over 55% on real exploitation benchmarks, and we're just getting started.

We're looking for exceptional people to join our mission: making continuous, intelligent offensive security the new standard.


About the Role

We're looking for an experienced Application Security Researcher to help customers maximize the value of Novee's AI-powered offensive security platform.

In this role, you'll work hands-on with customer environments, validate security findings, investigate complex application vulnerabilities, and help organizations understand, reproduce, and remediate the risks identified by our platform.

You'll collaborate closely with customers, Product, Engineering, AI Research, and Customer Success teams, providing valuable feedback that continuously improves the platform while serving as a trusted technical advisor throughout the customer journey, from complex deployments to production investigations.

This is an ideal role for someone with a strong offensive security background who enjoys combining technical research with customer interaction and wants to help shape the future of AI-driven application security.


Responsibilities

  • Validate vulnerabilities discovered by Novee's AI platform and provide clear technical evidence of successful exploitation.
  • Perform hands-on testing of modern web applications and APIs to verify findings and identify additional attack paths.
  • Analyze complex application security issues, including authentication, authorization, business logic flaws, and API vulnerabilities.
  • Help customers understand security findings, reproduce vulnerabilities, assess risk, and implement remediation recommendations.
  • Investigate cases where the platform missed, misclassified, or incorrectly assessed vulnerabilities and provide actionable feedback to Product and Engineering teams.
  • Collaborate closely with AI Research and Engineering teams to improve detection accuracy, attack coverage, and platform capabilities.
  • Develop new attack methodologies and validation techniques for modern web applications.
  • Stay current on emerging application security trends, offensive techniques, and modern attack methodologies.
  • Support customers during complex deployments, integrations, and production troubleshooting, including BYOM deployments and connectivity to internal applications.

Requirements

  • 3+ years of hands-on experience in Application Security, Web Application Penetration Testing, Bug Bounty, or Red Team operations.
  • Deep expertise in Web Application and API security.
  • Strong understanding of OWASP Top 10, authentication, authorization, business logic vulnerabilities, SSRF, XXE, deserialization, injection flaws, and modern attack techniques.
  • Experience using Burp Suite and other offensive security tools.
  • Ability to clearly communicate complex security findings to both technical and non-technical audiences.
  • Experience writing code or scripts to support security testing and automation (Python, JavaScript, Go, or similar).
  • Strong analytical and problem-solving skills.
  • Comfortable working independently in a fast-paced startup environment with a high degree of ownership.
  • Experience working directly with large enterprise customers, troubleshooting complex technical environments, and supporting production deployments.
  • Solid understanding of enterprise networking, authentication mechanisms, VPNs, proxies, and common application deployment architectures.


Nice to Have

  • Experience performing infrastructure penetration testing, including Active Directory assessments.
  • Familiarity with Mobile or Infrastructure security assessments.
  • Experience reviewing application source code.
  • Experience developing security tooling or automation.
  • Red Team experience.
  • Experience participating in Bug Bounty programs.
  • Familiarity with AI-powered security products or LLM technologies.


What We Offer

  • The opportunity to help shape the future of AI-powered offensive security.
  • Direct impact on a platform protecting enterprise customers worldwide.
  • Close collaboration with world-class security researchers, AI engineers, product leaders, and the founding team.
  • High ownership with the opportunity to influence product direction and customer success.
  • Exposure to cutting-edge AI and offensive security technologies.
  • Competitive compensation package, meaningful equity, and outstanding benefits.
  • The opportunity to join one of the fastest-growing companies in cybersecurity and help define the next generation of autonomous security.

Apply for this position

Apply for this position

Excited to work with us but don't see your position listed?