Ofir Ziv, Co-Founder & VP Research, Tenzai.
Security Researchers: Digital Fighters Series

Tenzai: “The pace expected from researchers has changed dramatically”

Ofir Ziv, Co-Founder and VP Research at Tenzai, explains why execution is the ultimate differentiator for research teams today, as part of CTech’s Security Researchers series.

“The pace expected from researchers has changed dramatically,” says Ofir Ziv, Co-Founder and VP Research at AI-native cybersecurity startup Tenzai. “Work that might once have remained in research for months must now be proven, evaluated, hardened, and delivered within weeks.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery
Ofir Ziv Tenzai
Ofir Ziv Tenzai
Ofir Ziv, Co-Founder & VP Research, Tenzai.
(Photo: Elad Malka)
Looking ahead, Ziv, who leads a team of 14 researchers, asserts that AI is fundamentally changing the role of the security researcher. As the job requisites evolve, he predicts the focus “will increasingly be to set objectives, guide investigations, develop new techniques, and teach agents how to apply those techniques at scale.”
You can read the entire interview below.
ID Card Company name: Check Point Founders: Gil Shwed, Marius Nacht and Shlomo Kramer Year of founding: 1993 Current number of employees: 7,000 worldwide, 3,000 in Israel
Company Description:
Tenzai is an AI-native cybersecurity company developing an autonomous AI hacker for enterprises. Its platform tests applications the way a real attacker would: mapping the attack surface, identifying vulnerabilities, chaining multiple weaknesses into attack paths, and validating whether they can actually be exploited.
Recently, the company announced two new capabilities that extend beyond vulnerability discovery and validation into remediation: generating immediate mitigation measures to reduce risk until a permanent fix is implemented, and assisting with the permanent remediation of vulnerabilities and validating that the fix effectively prevents exploitation.
About Tenzai's Security Research Team:
The team brings together 14 people with backgrounds in security research, artificial intelligence, and data science, including several whose experience spans all three disciplines.
We operate as one team rather than as a collection of narrow specialists. Everyone contributes across different areas, even though individual team members naturally have deeper expertise in certain topics. We eat together, study together, and work together, with a great deal of knowledge-sharing.
The team’s work can broadly be divided into three parts: creating challenges that our agents cannot solve today, developing the techniques and capabilities required to solve them, and evaluating whether the agents can solve those challenges consistently. People move between these areas, so these are responsibilities rather than rigid sub-teams.
What is your background in cyber, and what led you to specialize in security research?
I have worked in offensive cybersecurity for more than two decades. I started my career in IDF intelligence units, where I also met several of the people who would later become my co-founders. During my military service, I completed a master’s degree in computer science, with a thesis focused on multithreaded algorithms.
After leaving the military, I joined Guardicore as its first employee and led its security research organization. Guardicore was acquired by Akamai in 2021, and I spent the following three and a half years there as a vice president, leading a division responsible for developing and selling security products to large enterprises.
Today, as co-founder and VP of Research at Tenzai, my role is to translate the knowledge, techniques, and intuition of the world’s best hackers into the capabilities of an AI agent, how it explores a system, identifies weaknesses, exploits them, and demonstrates their real-world impact.
What attracted me to security research was the combination of in-depth technical work and creative, adversarial thinking. It requires understanding how a system is supposed to work and then identifying the assumptions its designers never expected anyone to challenge.
What does your security research team look like in action?
Our methodology is driven by four questions: what challenges can we build that the agent cannot solve today, what capabilities are required for the agent to solve them, how do we ensure they work consistently across all our customers and environments, and what else becomes possible once we have this new capability?
Our researchers then take a capability that succeeds in a controlled demonstration and make it work across different customers, applications, technologies, and environments. That transition, from “it worked once” to “it works consistently”, is where much of our most interesting research happens.
How does the research team influence your company at large?
The primary responsibilities of the research team are: building a highly capable and potentially dangerous AI hacker, evaluating that hacker and ensuring that we never consider it good enough, and making sure it can rise to the challenges it encounters in customer environments.
We constantly create the most difficult challenges we can, build agents capable of solving them, and ensure that new capabilities continue to work across the full range of customer use cases. Research and engineering work very closely together. Put simply, engineering makes sure the agent always works; research makes sure it always breaks in.
This relationship directly shapes the product. Every challenge the research team creates can become a new evaluation, every successful technique can become a new agent capability, and every failure in a customer environment becomes an opportunity to improve the system for all customers.
What has been your team’s most significant security discovery to date?
During security testing of a major enterprise IT company that almost everyone has heard of, we discovered an attack path that gave us root-level code execution across its multi-tenant cloud environment.
The exploit combined ideas from our human researchers with capabilities developed by our agent and chained together five sandbox escapes. The agent led the way, discovering the first two.
The finding is still undergoing coordinated disclosure, so unfortunately we cannot yet identify the company or share the technical details.
Who or what is your 'Moby Dick'?
My “Moby Dick” is not one particular vulnerability or service. It is closing the loop between offense and defense.
The goal is to connect our AI hacker to every type of defensive product. When the agent discovers and exploits an attack path, that knowledge should be fed directly into the defensive systems so they can immediately block the next attempt.
If offense can move at the speed of inference, defense should be able to move at that speed as well.
We have begun working toward this with immediate WAF mitigations and through our work with our partners. The broader ambition is to connect the entire security ecosystem and feed the results of every successful attack back into it, creating a continuously improving defensive loop.
How would you characterize the competition between research teams today?
Competition between research teams today is increasingly about execution. Access to advanced models and new ideas is widespread, and many teams can produce an impressive demonstration. The real differentiator is how quickly they can turn a research breakthrough into a reliable capability that delivers results in production.
The pace expected from researchers has changed dramatically. Work that might once have remained in research for months must now be proven, evaluated, hardened, and delivered within weeks. Research teams are expected to make the product leap forward continuously, not once or twice a year, but all the time.
Moving faster does not mean compromising on rigor. It requires strong evaluations, close collaboration with engineering, and constant feedback from real-world environments. The best research teams will combine depth with speed: delivering meaningful results quickly, making them work consistently, and then doing it again.
What is your take on the future of the human security researcher?
AI is changing the role of the security researcher. An AI agent can explore a large attack surface, analyze enormous volumes of code, test access-control combinations, and apply known techniques across new targets with a level of scale and persistence that humans cannot match. This frees researchers to concentrate on the harder questions such as what assumptions should we challenge, and which clues matter.
The researcher’s role will increasingly be to set objectives, guide investigations, develop new techniques, and teach agents how to apply those techniques at scale. A single insight from a great researcher will no longer need to remain in that person’s head or be applied manually, one engagement at a time. It can become a capability used continuously across thousands of applications.
Context will become even more important. AI may identify an authorization failure, but an experienced researcher understands whether it exposes an insignificant object or compromises a critical business process. It may uncover several individual weaknesses, but the person who understands the organization can recognize how they connect into a meaningful attack scenario.
As AI makes testing scalable, organizations will test more systems, more frequently, and in greater depth. The craft is moving up a level. The best researchers will combine technical depth, organizational context, and adversarial creativity with AI’s scale and persistence, enabling work that neither humans nor AI could accomplish as effectively alone.