Live opening · Posted 5 days ago

Offensive Security Specialist / Penetration Tester

Cybear - Track and Expose · Center District, Israel (On-site)
Linkedin No
You are 5 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 5 days ago
CompanyCybear - Track and Expose
LocationCenter District, Israel (On-site)
Work modeNo
SourceLinkedin
Listed5 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
10 min from Linkedin publishing this role to us finding it
12 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,381 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Offensive Security Specialist / Penetration Tester — CyBearTrack
Location: Nes Ziona, Israel (on-site) Type: Full-time — Monday to Thursday, 06:30–14:30 (32 hours/week) Compensation: Base ₪12,000/month + performance bonuses on every successful authorised engagement Contact: contact@cybeartrack.com.au
Who We Are
CyBearTrack is a specialist cyber-investigation firm working cryptocurrency fraud, blockchain forensic tracing, and OSINT. We work directly with scam victims, law enforcement, and enforcement partners to trace stolen funds, unmask threat actors, and build cases that lead to real outcomes. CyBearTrack is an authorised preferred vendor to law-enforcement partners and takes offensive engagements only under lawful tasking granted on a case-by-case basis for specific referred matters.
The Role
We're looking for an Offensive Security Specialist who can go head-to-head with scam infrastructure — the fake trading platforms, phishing kits, admin panels, and command channels that fraud operators run against our clients — and who understands that the difference between an investigator and a criminal is authorisation, scope, and documentation.
The role has two sides. The first is defensive and proactive: designing and running the honeypots — the decoy victims, wallets and instrumented environments that draw fraud operators in and quietly capture how they work. The second is authorised offensive operations: going directly at scam infrastructure, but only ever within the authority granted for that specific matter — a defined target, a defined scope, and a defined objective, signed off before you touch anything. Most weeks you'll move between the two.
If you're the kind of person who reads a scam operator's stack and thinks "I know exactly how that panel is held together," but who also stops dead at the edge of the authorisation without being told twice, this is your seat.
What You'll Be Doing
Honeypot design and operation — building and running decoy victims, instrumented environments, decoy wallets and deceptive infrastructure that attract fraud operators and capture their tooling, infrastructure, identifiers and behaviour. This is CyBearTrack's own environment and the core of the role.
Authorised offensive engagements — penetration testing and active operations against scam infrastructure, conducted only under the lawful authority granted for each referred matter, within the agreed scope, to a documented, evidence-grade standard.
Scam-infrastructure reconnaissance — domain history, hosting, SSL certs, exposed source, panel fingerprinting, kit identification, and passive mapping of operator infrastructure from open sources.
Evidence capture and preservation — collecting findings to a standard that survives legal and law-enforcement scrutiny: chain of custody, hashing, contemporaneous notes, reproducible method.
Vulnerability assessment of CyBearTrack and client systems — authorised testing of our own and clients' infrastructure under signed scope, to keep the recovery and evidence work defensible.
Correlating technical findings with the investigation — feeding infrastructure, identifiers and captures back into the blockchain traces and OSINT attribution that drive our cases and referrals.
Tooling — building and maintaining custom scripts and honeypot instrumentation.
What We're Looking For
Proven offensive-security experience — penetration testing, red team, CTF, bug bounty, or equivalent professional background.
Strong web-application and infrastructure skills: recon, enumeration, web exploitation, panel and CMS internals, network services.
A working understanding of the legal boundaries — the Israeli Computer Law, unauthorised-access rules, and why scope and authorisation are load-bearing, not paperwork. You know exactly where the line is and you do not cross it on your own initiative.
Honeypot / deception experience, or the ability to build it — instrumented environments, logging, capture pipelines.
Comfortable working within a documented, evidence-grade process rather than freelancing.
Familiarity with scam infrastructure — phishing kits, fake trading platforms, clone sites, Telegram/WhatsApp operations.
Scripting ability (Python, JavaScript, Bash) for custom tooling and automation.
Discretion and professionalism — our clients are fraud victims and our matters are sensitive.
Hebrew and English.
Bonus Points
Experience with honeypot/deception frameworks and malware/tooling analysis.
Knowledge of cryptocurrency laundering typologies and VASP disclosure processes.
Prior law-enforcement, military intelligence (e.g. 8200/unit background), or private-investigation experience.
Reverse-engineering and threat-intelligence experience.
Relevant certifications (OSCP, OSWE, or similar).
Compensation
Base: ₪12,000 per month.
Performance bonuses on every successful authorised engagement — paid on completed operations delivered within scope, and on honeypot captures and actionable intelligence that advance a live matter. Bonuses are tied to lawful, in-scope outcomes; nothing outside a granted authorisation is ever tasked or rewarded.
Why CyBearTrack
This isn't corporate security theatre and it isn't cowboy work either. Every matter has a real victim behind it and a real authorisation in front of it. You get to do the interesting half of offensive security — against people who genuinely deserve the attention — inside a framework that keeps you, and the case, clean. When we get it right, money gets frozen, infrastructure gets exposed, and people get arrested.
How to Apply
Send an email to contact@cybeartrack.com.au with:
A brief intro about yourself and your background.
Examples of relevant work (redacted as needed) — offensive engagements, honeypot builds, CTF/bug-bounty results.
Your availability.
No formal CV required. Show us how you think — and show us you know where the line is.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App