Roy Itzhaky, Security Researcher, CTO's office, Linx Security.
Security Researchers: Digital Fighters Series

Linx: “The future of security researchers is the same future where we treat AI agents like people”

Linx Security's Roy Itzhaky discusses how the future of security research will be less about digging and more about directing, as part of CTech’s Security Researchers series.

“Sloppy thinking used to cost you a slow afternoon,” says Roy Itzhaky, Security Researcher in the CTO’s office at Linx Security. “Now it costs you a fleet of agents running confidently in the wrong direction.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery
Roy Itzhaky Linx
Roy Itzhaky Linx
Roy Itzhaky, Security Researcher, CTO's office, Linx Security.
(Photo: Linx)
Itzhaky was introduced to the security field at an early age, completing a computer science degree through a high school program at just 14. He later joined a red team for the Ministry of Defense, where a three-week marathon of research earned him his first remote code execution at age 23.
Looking ahead, Itzhaky believes “the future of security researchers is the same future where we treat AI agents like people.” In that future, he says, the researcher will be “less of a digger and more of a director.”
You can read the entire interview below.
ID Card Company name: Linx Security Founders: Israel Duanis (CEO), Niv Goldenberg (CPO) Year of founding: 2023 Current number of employees: 100
Company Description:
Organizations today run on three kinds of identities: people, machines, and AI agents, and most have lost track of who can access what, who is actually using that access, and who is accountable for it. Linx Security gives them that answer in one place. The platform continuously maps every identity and every access path in the organization, surfaces the risks that matter, and lets security and identity teams act on them, from access reviews and lifecycle management to just-in-time access and governance of AI agents. The result is an organization that knows exactly who and what is operating inside it, and can prove it.
About Linx's Security Research Team:
Linx’s security research team is a small, highly experienced team (true superstars), with backgrounds spanning both offensive and defensive security. We work on the most advanced problems in identity security, in a field where technology evolves extremely quickly. Everyone here has a track record of taking on problems that require width and depth at the same time: the product, the customer's pain, and the technology. There are no lanes. Whatever matters most to the company right now is what we are doing, and each of us can do it all, from research to production code. The hiring bar is a mindset more than a skill set.
What is your background in cyber, and what led you to specialize in security research?
I started young. At 14, I began studying for a degree in computer science through a high school program, and there, as part of my studies, I was first introduced to the world of security. I was that kid obsessed with computers and drawn to hackers, and once I saw the field up close, I knew this was what I wanted to do, both during my military service and later in my career.
From there, I joined a red team within the Ministry of Defense, where our role was to test systems against sophisticated attack scenarios and use what we learned to strengthen their defenses. I started as a researcher; later, I was team lead, and eventually I led a broader group.
The milestone I still measure myself against is my first remote code execution. I was 23. For three weeks, weekends and holidays included, fourteen hours a day, it was me and the specific vulnerability. I can't say what the target was. What I can say is that the only thought in my head was "if anyone can do this, you can," and it carried me to the moment I had system permissions on the target and walked over to tell my commanders. Some people hit a wall and stop. Researchers hit it until it breaks. That is what those three weeks taught me, and it is the first thing I look for in a researcher.
After I finished my army service and my reserves, a friend called and asked me to join a cybersecurity startup as one of the first engineers in the core team. I led features end-to-end: the hands-on research, the low-level engine underneath, and weekly syncs with Product and the rest of engineering. From there I continued to research, architecture, product, and innovation in one place, just like in the MOD.
What does your security research team look like in action?
We work very closely with our customers and pay close attention to how the market and technology are evolving. When something changes, we move. For example, one of our customers began adopting a new AI platform. We pointed the team in the specific direction, and within a few days we understood from end-to-end how the platform works, what risks an attacker could exploit, and how to protect it. That understanding went straight back to the customer, and then it was integrated into the product for everyone else.
That is the pattern. We start from what the customers' environments actually show and what customers tell us hurts; we choose the topic with the biggest impact right now, and we go. Nobody here is only a researcher. When the right answer is production code, we write it. When it is sitting with a customer, we do that.
How does the research team influence your company at large
Research is where we question every assumption. Every day we ask how to bring the most advanced identity security capabilities to our customers, whether that is algorithms that detect vulnerabilities and risky access, methods that identify AI agents and other identities nobody has registered, or new ways to protect an identity once it is found. Ideas are born and tested in the research team, and the ones that hold up mature into the Linx platform, so every customer gets the value, not only the one whose environment raised the question.
We hold ourselves to the same standard we hold the data to. We test every idea against real environments before engineering builds it, so research is a measured result, not an opinion.
What has been your team’s most significant security discovery to date?
We have developed the ability to identify who owns an AI agent. It sounds simple. It isn't. Agents get created by people, by pipelines, and by other agents. They hold real permissions, and they almost never carry a name tag that says who's responsible for them. That capability recently made the difference for an organization that came close to being attacked. With it, they could see every agent and identity they didn't know existed, decide who owned each one, and take control of all of them without breaking the business that depended on them.
The pattern behind it repeats everywhere we look. A meaningful share of an organization's real access sits in identities nobody governs, and nobody would notice if one of them started doing something new. You can't surface them by asking who created them. You surface them by looking at what they actually do.
Who or what is your 'Moby Dick'?
Every system in this industry, ours included, re-reads the world everyday to find out what happened. It pulls everything, compares it to yesterday, and works out what moved. My white whale is a platform that thinks in changes from the start: what moved, who moved it, and what went silent. Silence is the part everyone misses. An identity that stops doing what it used to do is a signal, and almost nobody treats it as one today. Getting there means changing how a company processes information at its foundations, which is exactly why it is the whale and not next quarter's ticket.
How would you characterize the competition between research teams today?
Research teams are competitive by nature. We are people who want to solve the problem and show how big the impact was. What changed is what we compete on. It used to be who had the deepest knowledge of some niche technology. Today it is who can direct their AI tools best and turn their working hours into the most results. Depth is still required. It is just no longer the scarce thing.
What is your take on the future of the human security researcher?
The future of security researchers is the same future where we treat AI agents like people. If you want an agent to truly understand what you mean, you have to do what you would do with a person: explain the goal, the constraints, what one looks like, and why. That has a consequence people underestimate. Your ceiling with AI is set by how well you can communicate your thinking to another human.
So the researcher of the future is less of a digger and more of a director. The AI does the deep dives, in several directions at once. The human has to be precise about what they actually want, keep several agents synced to the same intent, and judge which of what comes back is real. That makes the job harder in the way that matters. Sloppy thinking used to cost you a slow afternoon. Now it costs you a fleet of agents running confidently in the wrong direction.