--- title: 'Senior Vulnerability Researcher at Oak' canonical: 'https://feeny.ai/job/senior-vulnerability-researcher-oak-tel-aviv-cx61z77zkxss' type: 'job' last_seen: '2026-09-12' --- # Senior Vulnerability Researcher at Oak - **Company:** Oak - **Location:** Tel Aviv, Israel - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-07-15 - **Last confirmed live:** 2026-09-12 - **Apply:** https://jobs.ashbyhq.com/oak/c05294f9-089d-4d0d-9ba7-47730652156f ## Job description We're reimagining enterprise Identity and Access Management from the ground up. Founded by serial entrepreneurs Shai Morag and Tal Marom and backed by a $60M seed round from Greylock, Accel, and CRV, we're building the next generation of identity security. Identity is the gateway to everything- who's let in, who's kept out, and it's now the number one attack vector in the enterprise. The tools built to govern it were designed for a slower world of human users and static environments. That world is gone. Identities are exploding across human, machine, and AI agents faster than legacy systems can track, and security teams are left patching together five disconnected tools that still can't answer "who has access to what, right now." We think the answer isn't another point solution- it's a new foundation. Oak is the AI-native Identity Operating System: an AI connector framework that reaches any application, a live identity graph built from raw evidence, and a team of AI agents that governs the full lifecycle of every identity in one platform. We're building Oak's AI-native core from day one-engineered for what enterprise identity is becoming, not patched onto what it used to be. And we're just getting started. About the Role: Oak's Vulnerability Research is the sharpest edge of our technical work - the team that takes systems apart to learn how they truly work, and where they break. We go deep into the mechanisms, protocols, and architectures that modern technology is built on, and we pressure-test the assumptions the rest of the industry takes for granted. Sometimes that work sharpens the platform, sometimes it stands entirely on its own, as an original research novelty. As a Vulnerability Researcher, you'll build first-principles understanding of the technologies and systems you investigate, then go looking for what's wrong with them: the flawed assumptions baked into established paradigms, the gap between how a system is meant to behave and how it actually behaves, and the novel vulnerabilities and exploitation techniques no one has named yet. This is hands-on, deep technical work - reverse-engineering, breaking, and finding what's exploitable before an attacker does. You'll have the room to follow the research where it leads, and the backing of an ecosystem created to set you up for success by providing every tool and access that could help. Some threads will feed directly into how Oak understands what's genuinely exploitable, grounding the platform in real attacker reality rather than theoretical risk. Others will be pure discovery, pursued because the problem is hard and the finding truly matters, and published to move the field forward. Either way, your work establishes Oak's authority in the field. Through original research, disclosures, and technical thought leadership, you'll build a body of work that earns the respect of the security community and sharpens how the industry thinks about what's truly secure. What you will Do: - Hunt for what established security paradigms miss: flawed assumptions, gaps between specified and actual behavior, and novel vulnerability classes and exploitation techniques that don't yet have names. - Reverse-engineer and deeply understand systems, protocols, and architectures at the implementation level - developing a precise understanding of how they actually work, rather than what their designers intended. - Develop hypotheses and convert them into working proof-of-concept exploits that demonstrate real-world risk before attackers do. - Own research threads end-to-end, from an early exploration, developing and following hunches all the way through to a proof of concept, responsible disclosure or publication, following the evidence wherever it leads without waiting for a defined playbook. - Ground Oak's understanding of exploitability in attacker reality - when research surfaces findings relevant to how the platform models identity attack surface across human and non-human identities, bring that signal in. - Promote Oak's standing in the security community through original research, CVEs, and technical thought leadership that advances the field and earns trust on its merits. What you will bring: - 6+ years of hands-on vulnerability research, reverse engineering, or offensive security, with a proven track record of finding non-trivial flaws and the depth in systems, protocols, and architectures to understand precisely why they exist. - A first-principles approach to how things actually work, not how they're documented to work: you pull the thread until you hit ground truth, and you're not satisfied until you do. - The instinct and ability to see what others overlook - the unquestioned assumptions in established systems, the edges no one has tested, the failure modes that live in the gap between spec and implementation. - End-to-end ownership of research: you drive hypotheses to conclusions through dead ends, changes of directions and reach hard proofs - Strong hands-on expertise, converting theories and research into a working chain and proof of concept. - Result driven depth: you go as far as a problem deserves, because the result is worth it, and you know when it is. - A track record of original significant discoveries - published CVEs, novel vulnerability classes or exploitation techniques, research that named a problem the field didn't have words for yet. Nice to have: - History of presenting original research at Black Hat, DEFCON, OffensiveCon, Hexacon or a comparable security conference. - Significant CVEs (CVSS High or Critical) under your name. ## About Oak ## Company Overview - **One-liner**: Oak provides an AI-driven identity security platform that helps enterprises manage, protect, and govern employee identities across their digital ecosystem. - **Entity Type**: Private (funding stage not publicly disclosed) - **Headquarters**: Not publicly available (likely United States based on privacy policy references to California law) - **Founded**: Not publicly available - **Founders**: Not publicly available ## Core Business - Primary industry: Identity Security / Identity and Access Management (IAM) - Target customers: B2B; enterprises and mid-market organizations looking to centralize identity management, particularly for workforce identity (employees, contractors) - Mission or purpose statement: “One AI-Driven platform for all your identity needs” – aiming to simplify and secure identity lifecycle management through artificial intelligence. ## Products & Services - **Oak Identity Security Platform**: A SaaS platform that uses AI to automate and secure identity processes such as onboarding, role management, access certifications, and offboarding. The platform is SOC 2 Type II certified and ISO 27001 aligned, emphasizing a holistic approach covering engineering, infrastructure, and operational layers. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed - **Key Metric**: Total funding and annual revenue are not publicly available; the company is actively hiring (via Ashby) and mentions working with “design partners”, suggesting an early to growth-stage trajectory. - **Notable Investors/Partners**: Not publicly disclosed - **Growth Signals**: SOC 2 Type II certification indicates maturity in security compliance; active hiring via modern ATS (Ashby) suggests scaling team; AI-driven positioning taps into growing demand for automated identity security. ## Competitive Advantages - **AI-driven automation** that differentiates from traditional IAM tools by reducing manual identity administration. - **Holistic security posture** with SOC 2 Type II certification and ISO 27001 alignment – a strong trust signal for enterprise buyers. - **Platform approach** covering identity needs in one place, reducing tool sprawl. ## Strategic Focus - Expanding the AI capabilities of the platform to cover end-to-end identity lifecycle. - Growing enterprise customer base and scaling the team (as shown by an active careers page). - Deepening compliance and security certifications to meet enterprise procurement requirements. ## Why Work Here - **Engineering & security culture**: The company describes itself as taking “a holistic approach to security, covering engineering, infrastructure, and process layers” – appealing to engineers passionate about building secure, scalable systems. - **Growth-stage opportunity**: With private status and active hiring, early employees may have significant impact on product direction and culture. - **Modern tech stack**: Likely uses cloud infrastructure and AI/ML technologies; roles appear on Ashby, a popular ATS for tech startups. - **Remote/hybrid policy**: Not explicitly stated; candidates should inquire during the interview process. ## Sources 1. [oak.id](https://www.oak.id/) 2. [Privacy Policy | Oak ID](https://www.oak.id/privacy-policy) ## Other roles at Oak - [Product Marketing Manager](https://feeny.ai/job/product-marketing-manager-oak-tel-aviv-gedtnsj71hbf) — Tel Aviv, Israel - [Senior AI Engineer](https://feeny.ai/job/senior-ai-engineer-oak-tel-aviv-4vxz1dz8vt4r) — Tel Aviv, Israel - [Enterprise Solutions Engineer - West](https://feeny.ai/job/enterprise-solutions-engineer-west-oak-san-francisco-stb7xarhh4qm) — San Francisco, CA - [Enterprise Solutions Engineer - East](https://feeny.ai/job/enterprise-solutions-engineer-east-oak-new-york-r5vrrq9jx623) — New York, NY - [Enterprise Solutions Engineer - Central](https://feeny.ai/job/enterprise-solutions-engineer-central-oak-chicago-c6ypb2x4n73t) — Chicago, IL - [Enterprise Account Executive - East Coast](https://feeny.ai/job/enterprise-account-executive-east-coast-oak-new-york-j8ky9r8wqcbd) — New York, NY - [Senior Product Security Researcher](https://feeny.ai/job/senior-product-security-researcher-oak-tel-aviv-hz1ckd4q7z4r) — Tel Aviv, Israel - [Senior Backend Engineer](https://feeny.ai/job/senior-backend-engineer-oak-tel-aviv-k295f0qqdrhx) — Tel Aviv, Israel - [Senior DevOps Engineer](https://feeny.ai/job/senior-devops-engineer-oak-tel-aviv-55wakxv1t47x) — Tel Aviv, Israel - [Senior Product Manager](https://feeny.ai/job/senior-product-manager-oak-tel-aviv-vtm6ytw8r5xm) — Tel Aviv, Israel