Roi Nisimi, Security Researcher, Orca Security.
Security Researchers: Digital Fighters Series

Orca: “The attack surface is evolving faster than the security models around it”

Roi Nisimi, Security Researcher at Orca Security, details the discovery of a vulnerability that exposed hundreds of thousands of Google cloud clusters, as part of CTech’s Security Researchers series.

“The attack surface is evolving faster than the security models around it and there are still many assumptions waiting to be challenged,” says Roi Nisimi, Security Researcher at cloud and AI security company Orca Security, listing “AI infrastructure” as his ‘Moby Dick’ of the security research landscape. “I’m especially interested in finding the flaws that emerge where AI systems, cloud infrastructure, identities, and data all intersect,” he says.
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery
Roi Nisimi Orca Security
Roi Nisimi Orca Security
Roi Nisimi, Security Researcher, Orca Security.
(Photo: Orca Security)
Nisimi, who works as part of a team of seven at Orca, served as an officer in Unit 81, Unit 8200, and the Israeli Ministry of Defense after graduating from the elite Silan cyber program. His work on complex national security projects earned him multiple commendations from the IDF Chief of Staff, the Prime Minister, and the President of Israel, while his private sector research has uncovered critical vulnerabilities in AWS, Microsoft, and Google.
“We believe that good research is fun research,” he continues. “One can’t research something they aren’t curious about.” One of his team’s most significant discoveries to date, he describes, was sys:all, a GKE vulnerability that exposed hundreds of thousands of vulnerable clusters, including environments belonging to Fortune 100 companies. As Nisimi explains: “The severity of the findings led Phil Venables, then CISO of Google Cloud, to step in and take part in the investigation directly.”
You can read the entire interview below.
ID Card Company name: Orca Security Founders: Gil Geron (CEO), Avi Shua Year of founding: 2019 Current number of employees: 400 (150 of whom are based in Israel)
Company Description:
Orca Security is a cloud and AI security company that provides a unified platform designed to protect organizations across their cloud environments, applications, workloads, data, identities, and AI systems. The Orca Platform provides visibility across the cloud estate, identifies and correlates security risks, and uses attack path analysis and risk prioritization to help security teams focus on the issues that pose the greatest risk to critical business assets. Its capabilities include cloud security posture management, vulnerability management, identity and entitlement security, container and Kubernetes security, data security, application security, and AI security across code, cloud posture, and runtime.
About Orca’s Security Research Team:
We are a small team of seven. Unlike many traditional security research teams, our foundation is collaboration. Each researcher brings a different set of strengths and owns a specific security discipline, but we work closely together, share knowledge, and combine our expertise across projects. This structure gives us room to specialize while still making the team stronger as a whole, helping us connect ideas across different domains, uncover new attack paths, and make discoveries that might otherwise be missed.
What is your background in cyber, and what led you to specialize in security research?
I was selected for a gifted class in high school that included an early cybersecurity track. In my senior year, our teacher nominated the entire class for a highly competitive military selection process. I was the only one who made it through and was ultimately accepted.
Over the course of seven years, I graduated from Silan, an elite cybersecurity program, was commissioned as an officer, and served in Unit 81, Unit 8200, and the Israeli Ministry of Defense. I worked on complex national security projects and received multiple commendations from the IDF Chief of Staff, the Prime Minister, and the President of Israel.
Throughout my career, I’ve discovered critical vulnerabilities in major technology companies such as AWS, Microsoft and Google. I’ve also had the privilege of being among a select group of speakers invited to present at leading global cybersecurity conferences, including RSAC, BSides, and BlueHat.
What does your security research team look like in action?
We operate as a combat unit – fast, efficient, and focused on research that drives the most business impact, with a high standard of execution. Our methodology is simple but effective. We believe that good research is fun research. Which means, we align the business goals with our own curiosity and fields of interest. One can’t research something they aren’t curious about.
AI is a major component in how we initiate, triage and document research endeavors. For each project, we automatically build a journal and a ‘research tree’ that accompany the process from start to finish. Both serve as critical tools for identifying dead ends, stepping back to reflect, and sparking new ideas through structured brainstorming. A huge amount of credit for this tool goes to Yoav Alon and Omer Rosenbaum, who guided and coached us throughout the process.
How does the research team influence your company at large?
Product, strategy and visibility. Our findings often turn directly into new detections, product improvements and a better understanding of emerging techniques. We also help identify where the market is heading and which security problems are worth solving next. At the same time, our research supports the company’s external voice through publications, conference talks, and industry discussions, helping position Orca at the forefront of cloud and AI security.
What has been your team’s most significant security discovery to date?
Our most significant discovery was sys:all, a GKE vulnerability that exposed hundreds of thousands of vulnerable clusters, including environments belonging to Fortune-100 companies. The severity of the findings led Phil Venables, then CISO of Google Cloud, to step in and take part in the investigation directly.
We discovered that GKE’s system:authenticated group could include any Google user, not just members of the organization. By scanning exposed clusters and testing their permissions, we found cases where attackers could access secrets, cloud credentials, and critical workloads, potentially leading to full cluster or broader organizational compromise.
Who or what is your 'Moby Dick'?
AI infrastructure. The attack surface is evolving faster than the security models around it, and there are still many assumptions waiting to be challenged. I’m especially interested in finding the flaws that emerge where AI systems, cloud infrastructure, identities, and data all intersect.
How would you characterize the competition between research teams today?
The competition is strong, but mostly healthy. Great research travels fast, so teams are constantly pushing each other to go deeper, move faster, and find something genuinely new. At the same time, the security research community is relatively small, and there is a lot of mutual respect, knowledge sharing, and collaboration between researchers, both locally and globally.
What is your take on the future of the human security researcher?
AI will make security researchers faster, but not replace them. It is already changing how we brainstorm, triage, document, and test ideas, but the real value of a researcher is still curiosity, intuition, and the ability to ask the right question.
I think the best researchers will become those who know how to use AI as a force multiplier while still understanding the systems deeply enough to recognize when something simply does not make sense.