Roy Itzhaky, Security Researcher in the CTO’s Office, Linx
Security Researchers: Digital Fighters Series

As AI takes over the grunt work, security researchers face a higher bar

CTech’s “Security Researchers: Digital Fighters” series surveyed 30 security researchers from Startup Nation’s cyber landscape, revealing how AI is changing their work and reshaping how these teams approach security to stay ahead of the curve.

“Sloppy thinking used to cost you a slow afternoon,” said Roy Itzhaky, Security Researcher in the CTO’s office at Linx Security. “Now it costs you a fleet of agents running confidently in the wrong direction.”
Across the global cyber landscape, the enterprise attack surface has massively and irrefutably altered as a result of the AI revolution. From the rise of non-human identities inside the organization to the collapse of response times to attacker exploits, protecting the corporate infrastructure today is a different beast entirely than it was only a few years ago.
5 View gallery
Roy Itzhaky Linx
Roy Itzhaky Linx
Roy Itzhaky, Security Researcher in the CTO’s Office, Linx
(Photo: Linx)
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. CTech’s “Security Researchers: Digital Fighters” series surveyed 30 of these security research professionals, gauging the most pertinent themes and concerns from the teams who make up this frontline of cyber.
The collective responses from the cohort exemplified how AI is reshaping the day-to-day craft of the researcher, as well as the operational practices and standards required to stay ahead of the threatscape as the goalpost is pushed ever forward.
Researchers are becoming more “directors” than “diggers”
Ultimately, the security researcher role has changed much for the better, with AI now responsible for much of the manual grunt work. Unsurprisingly, all of the companies surveyed described how AI has absorbed tasks such as log parsing, documentation reviews, and initial code scans, with a quarter explicitly characterizing AI as a ‘force multiplier’ for individual output.
“Every researcher on my team operates at roughly ten times their previous output, because AI agents handle the parts of research that are laborious rather than intellectual,” said Yuval Barak, Founding Research Engineer at Astelia.
According to Barak, AI is further helping to alleviate the historical challenge of institutional memory and knowledge transfer. “Knowledge stops being a property of individuals and becomes a property of the team,” he argued.
5 View gallery
Yuval Barak Astelia
Yuval Barak Astelia
Yuval Barak, Founding Research Engineer, Astelia.
(Photo: Roee Shlomi)
Consequently, most respondents predicted the researcher evolving into more of an orchestrator and judge – the critical intellect holding court over an army of automated assets. “The researcher of the future is less of a digger and more of a director,” said Itzhaky. “The AI does the deep dives, in several directions at once. The human has to be precise about what they actually want, keep several agents synced to the same intent, and judge which of what comes back is real.”
"The researcher of the future isn't competing with agents on speed,” added Ofek Haviv, Cyber Security Researcher at Terra Security. “Their value is in being the standard the agents are held to: the one making sure velocity doesn't come at the cost of the integrity.”
Non-human identities and shadow agents outnumbering humans
Identity management became a major theme of cyber research in the advent of AI as non-human identities like autonomous AI agents are gaining high privileges across cloud environments. As Omer Nissim, Security Researcher at Sweet Security, explained: “An agent with broad permissions and an MCP server nobody threat-modeled is a non-human identity with an unpredictable decision-making process attached to it.”
5 View gallery
Omer Nissim Sweet Security
Omer Nissim Sweet Security
Omer Nissim, Security Researcher, Sweet Security.
(Photo: Sweet Security)
“Agents get created by people, by pipelines, and by other agents,” said Itzhaky. “They hold real permissions, and they almost never carry a name tag that says who's responsible for them.”
In fact, eleven companies detailed AI agents as a major security perimeter shift. This included AI agents, API keys, and service accounts starting to outnumber human employees, and creating unmonitored ‘shadow admin’ risks.
“AI agents and nonhuman identities are now present in larger numbers than humans within some of our customers' organizations, and are projected to be 10 times that in the upcoming years,” warned Tomer Bar, AVP Security Research at Semperis.
The bar is rising for entry-level talent
With AI granting researchers unprecedented access to knowledge and a far greater output capacity, there has likewise come an increase in expectations for junior talent, with a fifth of respondents in the survey referring to the effect AI is having on the upcoming generation of researchers.
“AI has raised the expectations from researchers across all the different levels,” said Roey Vilnai, Director of Cyber Research at Axonius. “The access they have to knowledge is unparalleled, and so not knowing something, or not being knowledgeable enough about something, is no longer an excuse for anything.”
“Prior to joining Zenity, I had no background in cyber. Literally nothing,” said Tamir Ishay Sharbat, Director of Security Research at Zenity. “As a security researcher today, you have to use AI; it has become a requirement... Used correctly, it amplifies human agency rather than replacing it.”
At the same time, four companies warned against an overly reliant class of newcomers who lack the hard skills needed to exercise a proper researcher's judgement. “What worries me is a generation of researchers who can prompt a model but never learned to reverse engineer software,” expressed Idan Revivo, Head of Security Research at Island.
“When the model is confidently wrong, someone needs the skills to inspect the code and challenge it.”
5 View gallery
Idan Revivo Island
Idan Revivo Island
Idan Revivo, Head of Security Research, Island.
(Photo: Noi Arkobi)
Best practice will see the sunset of periodic audits
Finally, a significant outcome of the AI era for security researchers has been the dismantling of cornerstone legacy practices, including the static, point-in-time penetration test. In the survey, a salient takeaway was the transition away from these bi-annual audits of the past in favor of more continuous, autonomous validation.
This becomes especially important in an environment where the threat actors are unceasing. "The reality of autonomous AI agents acting as hacker teams is already here,” said Ido Hoorvitch, Security Researcher at NewCore.
"Offense is getting automated whether defenders like it or not, and that reframes what's at stake,” noted Omri Inbar, Vulnerability Researcher at Novee Security. “The teams pulling ahead are the ones who can take that human tradecraft and turn it into systems that run at a scale and speed no group of individuals can match.”
5 View gallery
Omri Inbar Novee Security
Omri Inbar Novee Security
Omri Inbar, Vulnerability Researcher, Novee Security
(Photo: Eyal Toueg)
In response, four of the companies surveyed have built proprietary “AI hackers” or internal training “gyms” designed to continuously simulate how real-world attacks unfold in production environments, while maintaining a zero-false-positive standard.
“Just as companies have adopted continuous integration and deployment (CI/CD), they must now adopt continuous security assessment as the new standard," emphasized Hoorvitch.
"Work that might once have remained in research for months must now be proven, evaluated, hardened, and delivered within weeks,” echoed Ofri Ziv, Co-Founder and VP Research at Tenzai. “Research teams are expected to make the product leap forward continuously.”