
"We are digital fighters. That's what we do."
Inside Israel's elite security research teams, where former military cyber specialists race to find vulnerabilities before criminals do, and where AI is reshaping both the attackers' playbook and the defenders' craft.
“Our perspective is really different from a developer's perspective,” says Roi Nisimi, Principal Security Researcher at cloud-native application protection platform Orca Security. “A developer looks at the services in a way that he thinks, ‘How can I use it for my benefit, for my programming, for the product?’. We look at it in a way of ‘How we can abuse these services to actually hack into people's computers, and steal their sensitive data?’”
In the rapidly shifting digital landscape, a specialized elite is emerging from the shadows of traditional software development: the security researcher. Unlike developers who focus on building products, these researchers operate as "digital combat units," looking at services through the lens of how they can be abused, hacked, and exploited to protect sensitive data.
Recent high-profile incidents – such as OpenAI and Anthropic models inadvertently accessing the public internet during evaluations by Israeli security firms – have brought the critical work of these proactive units into the spotlight. Often operating in lean, highly specialized teams of five to seven people, these researchers are tasked with mimicking the tactics of "Black Hat" hackers to expose flaws before they can be exploited by real-world threat actors.
“In a cybersecurity company that has a cybersecurity product, 90, 95% of R&D will be software developers," says Nisimi. “Only 5% are people who actually know cybersecurity in depth in that they can mimic the hacker and find things that the hacker would find. They can follow its tracks because they know how to actually break into systems and find vulnerabilities and attack factors."
In Israel, this sector is uniquely defined by a shared military pedigree, with many researchers hailing from elite IDF units like 8200. This background instills a "can-do" mentality, high-speed execution, and a sense of camaraderie that fuels a "positive rivalry" within the industry.
However, the field is also one of intense pressure and ego, where the "highs are highs and the lows are lows" as researchers race to find the next major vulnerability. "It’s a very mentally heavy kind of work," Nisimi admits. When a researcher experiences a dry spell in findings, "your self-confidence can drop."
"Research is a tool to go deep," explains Ofir Hamam, Head of Offensive Security at agentic AI-powered offensive security platform, Terra Security. "It's a specific tool to use when you want to tackle something from its root.”
Interestingly, the benefits of this investment extend beyond the obvious value of cyber diagnostics. The research unit is often the front-facing arm of the company, whose reports and exposés help garner the prestige that elevates a brand and commands authority in a rather crowded market.
For example, international cyber giant Palo Alto Networks recently published findings from their research division, Unit 42, revealing that attackers are now using advanced AI to detect security vulnerabilities and exploit them in a matter of minutes.
Or likewise, on Tuesday, Israeli DevOps technology company JFrog Security posted on X that their security team identified a supply chain attack targeting the popular npm caching library, Keyv.
"There are many different research fields in cyber simply because there are different levels of protection that one might want to defend against," explains Jonathan Elkabas, Security Researcher at Semperis, whose team conducts very specific research on identity providers in the Microsoft ecosystem.
Security research encompasses a range of specialties, including vulnerability research and exploit development, reverse engineering, cloud and container security, AI and machine learning security, and cryptography, to name a few. And as Elkabas states, "in those areas there are many niches."
This accelerated “new reality” that’s shaking the cyber world is asking ever more of its security research teams who play an integral role in fortifying the defense lines. "The research team, we are a combat unit," says Nisimi, who works in a team of six to seven.
A former professional soccer player, he likens the dynamic of an elite security research team to the Champions League winning team Paris Saint-Germain. "They don't have superstars. The group is so powerful together because everyone likes each other, they respect each other. They are interested in the growth of one another, and that's what builds success."
"The best teams are not the teams with the best players," he says. "They're the teams where everyone works together as a group."
Elkabas, who has a team of five people, notes that “each one of them has a specialty in a different field.” As a task comes in, he describes the first action is to “think about who are the team members that will do it the best way.”
Hamam describes a similar workflow for his team at Terra Security, which also consists of five members. "The first task that we do when we get a question is basically try to explain it ourselves first,” he says. “What is the most we can do here and where in this flow should agents be participating?”
The boutique nature of these lean teams, Nisimi argues, “has its positives and negatives. The positive is we do everything in terms of research within the organization and we grow as individuals greatly.”
Nisimi explains that sustaining the collaboration needed in this high-octane dynamic is aided by cultivating a strong sense of community. "We have dedicated days where we as a group just focus and try to hack the same technology and find vulnerabilities,” he says. “We did it last month and we fetched a few thousands of dollars in bug bounty,” which he notes the team will donate.
However, this goodwill doesn’t necessarily extend to the entirety of the broader sector. In fact, the biggest enemy of a security researcher can be another researcher.
"It’s really about money and ego," Elkabas agrees, commenting on some researchers' compulsion to broadcast their break-ins and exploits. "People want to prove themselves and show that they're productive. They want to publish that LinkedIn post that says ‘look, I made it’.”
That being said, it’s not a universal experience. Hamam argues that such arrogance is few and far between. “I don't feel it, but that's just me,” he says.
To Hamam, those with a penchant to brag are the outliers and not the greatest players in the game. “When I see those people post, they are less technical than the ones that come very humble.”
"What I love about the research community, which is a global one, is that everyone comes so humble to it," Hamam offers. "There is a very open community of learning from each other."
In Israel’s tech sector specifically, the cyber industry is deceptively small and familiar. Despite its massive scale, the country's size and the shared military pathways of its professionals mean this camaraderie is naturally conducive to a friendly rivalry.
Elkabas notes that his team consists of individuals who "have pretty much the same background," coming straight from the IDF as "cyber defenders or cyber attackers." Naturally, the shared military background provides a uniquely advantageous training ground for Israel’s security research teams.
"I think the one thing that the IDF teaches you is to set the bar really high," Elkabas continues. As well, it imbues a sense of agency and competency. “The ability to say, ‘I can accomplish that’, ‘we can do that’” Even in a situation where a vulnerability is published, he describes: “we're like, ‘alright guys, we have a few days to cover it end-to-end, let's do it’."
Nisimi notes that 90 percent of his team hails from military backgrounds, predominantly Unit 8200. “I think what has been installed into my mentality is: you can do everything and you can do everything fast, with minimal resources.”
He continues: “We don't complain, we do things fast. We stay positive and curious.” Ultimately, he adds, “We are digital fighters. That's what we do.”
That being said, the transition into the private sector isn’t foolproof. "You take someone that comes with a lot of technical knowledge and experience, but you also have to make some adaptation into the business world because the army and business don't work the same," explains Hamam.
Needless to say, the business world today has changed immensely in recent years with the advent of AI, supercharging research (and attacker) velocity and ultimately redefining the day-to-day work of security researchers.
"We work faster because of AI," expresses Nisimi. "You need to have a really good reason to grow in personnel."
"I didn't write a line of code in the past I think one and a half to two years. There's no need. AI can write code much better than I can."
As with the general high-tech sector, these changes inevitably raise questions about the future size of security research teams. According to Elkabas, "AI would never be able to replace human interaction." He describes how many organic breakthroughs come from "sitting in a room with a human and just saying, 'Hey, I think I found something.’"
















