
Security Researchers: Digital Fighters Series
Salt: “Truly innovative research comes from freedom of thought and as few boundaries as possible”
Yaniv Balmas, VP Research at Salt Security, explores how a strong research team operates several steps ahead of its own product as part of CTech’s Security Researchers series.
“We often don't know exactly what we are looking for when starting a research project,” explains Yaniv Balmas, VP Research at API and AI security platform Salt Security. “This is a broad field,” he continues, “and I personally believe that truly innovative research comes from freedom of thought and as few boundaries as possible.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
Balmas describes himself as “a bit of a strange bird in this field,” having bypassed the traditional military-to-startup pipeline to learn the industry independently before eventually “leading global research teams at large companies such as Check Point.” Today, as VP Research at Salt, he works alongside a five-member team with extensive experience across various cybersecurity disciplines. “Our real strength comes from sharing that knowledge,” he notes. “Our biggest findings usually emerge from collaboration.”
You can read the entire interview below.
ID Card
Company name: SALT Security
Founders: Roey Eliyahu and Michael Nicosia
Year of founding: 2018
Current number of employees: 170
Company Description:
Salt is designed to secure the entire agentic path, from AI-generated code to runtime, across models, MCPs, APIs, data, and actions. Through its Agentic Security Graph, the platform provides a living map of agents, MCPs, APIs, data flows, posture gaps, runtime behavior, and business context, giving security teams breadth across every component in the agentic path.
About Salt's Security Research Team:
Our security research team has five members with extensive experience across cybersecurity, from web security to low-level and embedded security. Many are internationally recognized conference speakers and vulnerability researchers who have found and helped address numerous security issues throughout their careers.
Our researchers draw on principles developed through years of finding security issues, each bringing a unique perspective and area of expertise. But our real strength comes from sharing that knowledge: our biggest findings usually emerge from collaboration. For us, knowledge sharing and joint work are key to producing strong research.
What is your background in cyber, and what led you to specialize in security research?
I have a long background in security research. When I started in this field, “cyber” was not yet a common term, and the internet was still in its early days. I am a bit of a strange bird in this field. I did not follow the “normal” path of military training followed by a role at a startup, but learned the field on my own with the help of the global research community and its shared knowledge. I have worked in various cybersecurity and research roles, ranging from malware research, incident response, vulnerability research and security consulting to management roles building and leading global research teams at large companies such as Check Point.
What does your security research team look like in action?
Our company's focus on API and agentic security shapes our research activities. This is a broad field, and I personally believe that truly innovative research comes from freedom of thought and as few boundaries as possible. Our researchers therefore have considerable freedom to choose their research topics and targets. This can lead to dead ends, but that is part of research. We often don't know exactly what we are looking for when starting a research project. This becomes clear as the project progresses and often leads to amazing results.
How does the research team influence your company at large?
In my mind, a research team is, by definition, several steps ahead of the product and its features. This allows us to help direct our product toward more relevant areas and identify where to focus development to deliver greater value to our customers.
What has been your team’s most significant security discovery to date?
It's really hard for me to single out one discovery as the most important. Our team uncovers dozens of security issues across the internet. Whenever possible, we publish them to educate and help others build more secure and robust solutions, but some remain unpublished and are shared privately with the relevant parties.
Of the research we have published over the years, our OAuth security series stands out. It explored a broad range of real vulnerabilities using established techniques, novel techniques we refined, and combinations of both. The series highlighted critical issues in familiar online services such as Booking.com, Grammarly, ChatGPT and many others.
OAuth is a widely used framework for granting access to online resources. It is often part of the process behind options such as “Log in with Google, Meta or Apple.” While these options are easy to use, implementing them securely is much harder. Implementation flaws can allow attackers to take over user accounts, steal sensitive information such as payment details, or act on a user's behalf.
Our findings help developers understand how to avoid these issues and highlight the safeguards our product offers when implementation flaws remain.
Who or what is your 'Moby Dick'?
I’m not a captain, and I don't believe in “Moby Dicks”. Throughout my career, my teams and I have faced many challenges that were believed to be “far too complex to solve”, and we managed to crack many of them. Every time we succeed, we choose a bigger and more complex “Moby Dick”. That's what motivates me and our researchers: there is always a bigger fish!
How would you characterize the competition between research teams today?
Throughout my career, I have never felt a sense of competition between research teams at different companies, even when the companies themselves compete and closely guard their information. In my experience, research teams take a different approach. There has always been great cooperation and knowledge sharing between research teams. This is what helps drive the entire research community forward. In my mind, sharing information and working together play a huge role in that progress.
What is your take on the future of the human security researcher?
This is a very tough question to answer. We are still learning about AI and how it comes into play in almost every field, including research. I can describe how AI assists our research today, but it's still very hard to foresee its impact two or five years from now.
I do believe that it will dramatically change how we approach research projects. A junior researcher taking their first steps in this field today will probably follow a significantly different path from mine. The tools, knowledge and capabilities AI provides are changing how we learn, analyze and conduct research.
However, it's very hard for me to imagine a day when research projects no longer need human involvement. AI is a powerful tool, but you still need to know how to use it, interpret its results and validate them.














