# CTO Office Solutions Architect (Researcher)

[Huskeys](https://gurify.com/jobs?q=Huskeys) · Tel Aviv · Posted 5 days ago

Executive

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/huskeys/e10af15f-a797-4436-bd30-9554be63f018)

## Job description

Huskeys is building an intelligent security control layer for modern web applications. We work alongside existing WAFs to help security teams understand traffic behavior, reduce false positives, and protect applications without disrupting business.

This is a founding CTO Office role for a security researcher who can operate as an independent technical force multiplier. You will investigate hard web, API, cloud, WAF, and customer-security problems where the path is often unclear. You will turn incomplete signals into evidence, make judgment calls about what matters, build the minimum tooling or proof required, and convert the result into customer impact, product capability, or a clear decision to stop.

This is not a pure research role, a conventional solutions-architect role, or a strategy-only role. You must be equally comfortable reading traffic and infrastructure behavior, writing and running code, speaking with customers, and deciding what should become product versus a one-off solution.

The CTO Office takes on technical problems that cut across customer reality, security research, product direction, and implementation—before they fit cleanly inside a single function.

### What You’ll Do

- Own ambiguous technical investigations from initial hypothesis to reproducible evidence and a concrete next action.

- Research web, API, cloud, WAF, CDN, network, and application-security behavior in real customer and market environments.

- Build small, working tools, experiments, detectors, integrations, or proofs of concept when they are the fastest way to establish truth.

- Distinguish a technically interesting observation from material customer risk, product opportunity, or noise.

- Work directly with customers and internal teams to understand real deployment constraints, business impact, and operational tradeoffs.

- Decide whether an outcome belongs in product, a customer-specific solution, the research backlog, external tooling, or nowhere.

- Translate validated work into a clear decision and owned next step—such as detection logic, a finding, a product requirement, remediation guidance, a reusable tool, or a decision not to proceed.

- Communicate evidence, uncertainty, and recommendations clearly to engineers, customers, and leadership.

- Move rapidly between research, implementation, customer context, and product decisions; discard work quickly when evidence changes the answer.

- Help shape Huskeys’ technical point of view through clear internal documentation and, where appropriate, external research.

1.

### Your First 90 Days

First 30 days — learn the terrain and establish technical credibility

- Build a practical model of the Huskeys product, customer environments, WAF/log data, external scanning, and the security decisions customers need to make.

- Reproduce and document one meaningful web, API, cloud, or WAF security behavior in a local lab or controlled environment.

- Identify a focused investigation with the CTO: the decision it needs to support, the evidence required, the smallest credible experiment, and its expected outcome.

### Days 31–60 — own a real investigation

- Drive that investigation independently through data collection, technical validation, and a working artifact: a tool, experiment, detector, integration, or reproducible proof.

- Communicate the evolving evidence, uncertainty, and tradeoffs clearly to the CTO and relevant Engineering or Product partners.

- Make a recommendation grounded in the evidence: ship, investigate further, turn it into a customer-specific solution, escalate, or stop.

### Days 61–90 — turn evidence into impact

- Deliver one concrete, reviewable outcome: a shipped artifact, validated finding, evidence-backed no-go decision, or product-direction recommendation.

- Translate the work into an owned next step—such as detection logic, a finding, a product requirement, remediation guidance, a reusable tool, or a customer technical narrative.

- Demonstrate that you can receive a loosely framed problem, choose the right scope, produce credible technical evidence, and move it to the correct owner or outcome without continuous direction.

### Requirements

- Demonstrated hands-on depth in at least two of: web application security, API security, cloud security, network security, WAF/CDN behavior, attack-surface management, bot/abuse defense, or infrastructure security.

- Strong first-principles understanding of HTTP, DNS, TLS, proxies, load balancers, authentication, web applications, APIs, and cloud networking.

- Evidence of independently taking a vague security problem to a working tool, reproducible proof, detection, investigation, or product outcome.

- Ability to write and operate code for research and technical validation—Python, TypeScript, Go, or equivalent.

- Judgment to decide what requires more investigation, what is ready to ship, what belongs to another team, and what should be killed.

- Comfortable with customer ambiguity: incomplete data, competing priorities, non-technical stakeholders, and real delivery constraints.

- Clear written communication for engineers, security teams, and executives.

- Strong curiosity without confusing breadth of ideas with depth of understanding.

### Especially Valuable

- Research experience in WAF bypasses, origin exposure, cloud misconfiguration, API security, attack-surface discovery, or bot/agent abuse.

- Familiarity with AWS and modern cloud environments.

- Experience building detections, security products, or research tooling.

- Experience working directly with enterprise customers on technical investigations or security outcomes.

- Published research, open-source tools, CTF experience, or an equivalent research portfolio.

### Why Huskeys

You’ll work on difficult, real-world web security problems with direct access to the people building the product. The goal is not research for its own sake: it is to make the internet harder to attack and give security teams a clearer path to action.

You will have unusual ownership, high context, and the ability to turn evidence into product and customer impact. In return, the role demands technical rigor, speed, judgment, and the willingness to own an outcome end to end.

**Live in Huskeys’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- VE [Solutions Architect, CTO Office](https://gurify.com/job/solutions-architect-cto-office-at-vega-aaa744522c66) Vega · Tel Aviv-Yafo, Israel · 7 weeks ago
- AL [Salesforce Solutions Architect](https://gurify.com/job/salesforce-solutions-architect-at-allcloud-36a2a93f46dd) Allcloud · Ra'anana, Israel · 3 days ago
- CA [Office Coordinator](https://gurify.com/job/office-coordinator-at-candex-cef12156914f) Candex · Israel · last week
- ON [Office Manager](https://gurify.com/job/office-manager-at-onyxsecurity-42a25c9eda9d) Onyxsecurity · Tel Aviv, Israel · 2 weeks ago
- AL [AWS Data Architect](https://gurify.com/job/aws-data-architect-at-allcloud-8487793152ba) Allcloud · Ra'anana, Israel · 2 weeks ago
- CL [Quantum Error Correction Researcher](https://gurify.com/job/quantum-error-correction-researcher-at-classiq-8ac684ce0db1) Classiq · Tel Aviv-Yafo, Israel · 3 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"CTO Office Solutions Architect (Researcher)","description":"\u003Cp\u003EHuskeys is building an intelligent security control layer for modern web applications. We work alongside existing WAFs to help security teams understand traffic behavior, reduce false positives, and protect applications without disrupting business.\u003C/p\u003E\u003Cp\u003EThis is a founding CTO Office role for a security researcher who can operate as an independent technical force multiplier. You will investigate hard web, API, cloud, WAF, and customer-security problems where the path is often unclear. You will turn incomplete signals into evidence, make judgment calls about what matters, build the minimum tooling or proof required, and convert the result into customer impact, product capability, or a clear decision to stop.\u003C/p\u003E\u003Cp\u003EThis is not a pure research role, a conventional solutions-architect role, or a strategy-only role. You must be equally comfortable reading traffic and infrastructure behavior, writing and running code, speaking with customers, and deciding what should become product versus a one-off solution.\u003C/p\u003E\u003Cp\u003EThe CTO Office takes on technical problems that cut across customer reality, security research, product direction, and implementation\u2014before they fit cleanly inside a single function.\u003C/p\u003E\u003Ch3\u003EWhat You\u2019ll Do\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EOwn ambiguous technical investigations from initial hypothesis to reproducible evidence and a concrete next action.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EResearch web, API, cloud, WAF, CDN, network, and application-security behavior in real customer and market environments.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild small, working tools, experiments, detectors, integrations, or proofs of concept when they are the fastest way to establish truth.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDistinguish a technically interesting observation from material customer risk, product opportunity, or noise.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork directly with customers and internal teams to understand real deployment constraints, business impact, and operational tradeoffs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDecide whether an outcome belongs in product, a customer-specific solution, the research backlog, external tooling, or nowhere.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETranslate validated work into a clear decision and owned next step\u2014such as detection logic, a finding, a product requirement, remediation guidance, a reusable tool, or a decision not to proceed.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECommunicate evidence, uncertainty, and recommendations clearly to engineers, customers, and leadership.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMove rapidly between research, implementation, customer context, and product decisions; discard work quickly when evidence changes the answer.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp shape Huskeys\u2019 technical point of view through clear internal documentation and, where appropriate, external research.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E1.\u003C/p\u003E\u003Ch3\u003EYour First 90 Days\u003C/h3\u003E\u003Cp\u003EFirst 30 days \u2014 learn the terrain and establish technical credibility\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EBuild a practical model of the Huskeys product, customer environments, WAF/log data, external scanning, and the security decisions customers need to make.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReproduce and document one meaningful web, API, cloud, or WAF security behavior in a local lab or controlled environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentify a focused investigation with the CTO: the decision it needs to support, the evidence required, the smallest credible experiment, and its expected outcome.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EDays 31\u201360 \u2014 own a real investigation\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDrive that investigation independently through data collection, technical validation, and a working artifact: a tool, experiment, detector, integration, or reproducible proof.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECommunicate the evolving evidence, uncertainty, and tradeoffs clearly to the CTO and relevant Engineering or Product partners.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMake a recommendation grounded in the evidence: ship, investigate further, turn it into a customer-specific solution, escalate, or stop.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EDays 61\u201390 \u2014 turn evidence into impact\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDeliver one concrete, reviewable outcome: a shipped artifact, validated finding, evidence-backed no-go decision, or product-direction recommendation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETranslate the work into an owned next step\u2014such as detection logic, a finding, a product requirement, remediation guidance, a reusable tool, or a customer technical narrative.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDemonstrate that you can receive a loosely framed problem, choose the right scope, produce credible technical evidence, and move it to the correct owner or outcome without continuous direction.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDemonstrated hands-on depth in at least two of: web application security, API security, cloud security, network security, WAF/CDN behavior, attack-surface management, bot/abuse defense, or infrastructure security.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong first-principles understanding of HTTP, DNS, TLS, proxies, load balancers, authentication, web applications, APIs, and cloud networking.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEvidence of independently taking a vague security problem to a working tool, reproducible proof, detection, investigation, or product outcome.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to write and operate code for research and technical validation\u2014Python, TypeScript, Go, or equivalent.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EJudgment to decide what requires more investigation, what is ready to ship, what belongs to another team, and what should be killed.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComfortable with customer ambiguity: incomplete data, competing priorities, non-technical stakeholders, and real delivery constraints.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EClear written communication for engineers, security teams, and executives.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong curiosity without confusing breadth of ideas with depth of understanding.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EEspecially Valuable\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EResearch experience in WAF bypasses, origin exposure, cloud misconfiguration, API security, attack-surface discovery, or bot/agent abuse.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with AWS and modern cloud environments.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience building detections, security products, or research tooling.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working directly with enterprise customers on technical investigations or security outcomes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPublished research, open-source tools, CTF experience, or an equivalent research portfolio.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhy Huskeys\u003C/h3\u003E\u003Cp\u003EYou\u2019ll work on difficult, real-world web security problems with direct access to the people building the product. The goal is not research for its own sake: it is to make the internet harder to attack and give security teams a clearer path to action.\u003C/p\u003E\u003Cp\u003EYou will have unusual ownership, high context, and the ability to turn evidence into product and customer impact. In return, the role demands technical rigor, speed, judgment, and the willingness to own an outcome end to end.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"cto-office-solutions-architect-researcher-at-huskeys-2c66062c449a"},"url":"https://gurify.com/job/cto-office-solutions-architect-researcher-at-huskeys-2c66062c449a","datePosted":"2026-09-17","validThrough":"2026-11-06T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Huskeys","sameAs":"https://jobs.ashbyhq.com/huskeys"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"IL","addressLocality":"Tel Aviv"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Israel","item":"https://gurify.com/jobs/israel"},{"@type":"ListItem","position":3,"name":"CTO Office Solutions Architect (Researcher)","item":"https://gurify.com/job/cto-office-solutions-architect-researcher-at-huskeys-2c66062c449a"}]}
```
