Cyber Security Architect and Researcher

Eran Atias

Cyber security professional with 13 years of experience in various technical, methodological, and management roles — with a particular focus on building teams, operations, and services from the ground up, while staying business-driven and customer-oriented.

Specializing in the design of secure architectures and end-to-end security solutions, from HLD/LLD and policy to deployment and operational monitoring, alongside in-depth cyber security and privacy risk assessments for organizations, systems, and processes.

Trusted advisor to CISOs, C-Level executives, Boards of Directors, and Risk Committees on security strategy, governance, and program design.

13+
Years in Cyber Security
15+
Publications
4
Frameworks
4
Certifications
2
Academic Degrees
Major
IDF Rank
Eran Atias

Building cyber security from scratch.

I'm a senior cyber security expert with a rare combination of deep technical hands-on experience and architectural, methodological, legal, compliance regulation and business fluency. My work spans InfoSec management, cyber security architecture, security research, SOC/IR operations, cloud security, and Web Application and API Protection — with a consistent throughline: building things from scratch that provide value.

Previously at PwC NEXT (part of PwC Israel), I designed and delivered security architecture and consulting services, advising CISOs, C-Level executives, and Risk Committees, guiding organizations through complex compliance landscapes and building security programs that are both solid and practical.

I hold a B.Sc. in Computer Science and an M.A. in Law (Technology Track), as well as CISO and DPO certifications, giving me an edge at the intersection of technical risk and legal and regulatory exposure.

Security Architecture Cloud Security Web Application and API Security SOC Operations Incident Response Security Engineering Security Research Information Security Management GRC Risk Management Threat Modeling SSDLC Malware Analysis Consulting Privacy & Data Protection Supply Chain Risk SIEM Engineering

What I can do
for your organization.

From a targeted architecture review to a full security program — I bring a practitioner's precision and a consultant's structure.

🛡️

CISO and vCISO Advisory

Security leadership for organizations that need a full-time or part-time CISO — security strategy, ongoing security program ownership, risk management, regulatory liaison, policy writing, vendor evaluation, team building, and board-level risk reporting.

🧭

Executive Security Advisory

Strategic security counsel for CISOs, C-Level executives, and Boards of Directors. Translating complex technical risk into clear business language — supporting security governance decisions, board-level reporting, risk appetite discussions, and security investment prioritization.

⚖️

Risk Assessment

Structured risk assessments for organizations, systems, and processes — building a threat profile, analyzing likelihood and impact, and producing a residual risk report with actionable treatment recommendations.

NIST CSF
📋

Compliance Readiness Assessment

Assessing where an organization stands against a target framework, identifying gaps, and producing a prioritized remediation roadmap.

ISO 27001 SOC 2 NIS2 DORA Bank of Israel Regulation Israeli MoF Cyber Regulation PCI DSS
🎯

Certification Preparation

End-to-end guidance through the certification process — scoping, policy writing, control implementation, evidence collection, and working alongside auditors to achieve certification.

ISO 27001 SOC 2 PCI DSS
🔄

Business Continuity and Disaster Recovery

Designing and implementing BC/DR programs, covering policy and procedure development, RTO/RPO definition, business impact analysis, tabletop exercises, backup architecture, failover design, and recovery testing.

🏗️

Security Architecture Design

HLD/LLD design of secure systems, cloud environments, and hybrid infrastructures — from policy and procedures to deployment and operational monitoring.

☁️

Cloud Security

AWS security architecture, configuration review, incident response, and maturity assessment.

AWS Security Maturity Model
⚙️

Security Engineering

Design, deployment, and configuration of security solutions. Bridging the gap between architecture decisions and operational implementation.

CSPM EDR IAM MDM NGFW SIEM
🔭

Vulnerability & Attack Surface Management

Conducting vulnerability assessments and external attack surface analysis, identifying and prioritizing exposure across systems and applications. Designing and implementing ongoing vulnerability management and attack surface management programs.

🔗

Web Application and API Security

Web and API security architecture design and testing — covering WAF design, tuning and bypass testing, web security architecture review, and OWASP ASVS assessments.

OWASP ASVS
🧱

AppSec Program Design & Assessment

Building AppSec programs from scratch — defining policy, selecting tooling, and embedding security into the SDLC. Also assessing existing programs against OWASP SAMM to identify gaps and prioritize improvements.

OWASP SAMM
🔒

Privacy & Data Protection

Regulatory advisory covering GDPR and the Israeli Protection of Privacy Regulations. DPO advisory, privacy impact assessments, and data protection program design.

GDPR Israel Protection of Privacy Regulations
🚨

SOC/IR Advisory

SOC design, buildout, and maturity assessment — covering IR readiness, AWS incident response, SIEM engineering, and threat hunting.

🔬

Security Research

Conducting original cyber security research, investigating threat actors, attack techniques, and emerging attack vectors, and translating findings into published technical reports, white papers, and case studies.

Notable milestones.

🏢
Innovation

PwC NEXT Security Practice

Designed and developed new security architecture and consulting services within a new PwC technology company, while building methodology, optimizing for efficiency and customer value, and driving go-to-market and sales processes.

Industry First

API Security SOC Founder

Established Salt Security's API Security SOC from scratch, overseeing the Salt API Security SaaS platform — monitoring and investigating API attacks, tuning detection mechanisms, and leading API incident response and threat hunting operations.

Eran Atias - Global SOC Manager at Salt Security
Industry First

AWS DDoS Test Partner

Led Red Button to become the 3rd AWS DDoS Test Partner globally — a rare designation held by only a handful of companies worldwide at the time.

Industry First

Founding DDoS Protection Analyst

As the 2nd person in the DDoS Protection Expert role at Red Button, played a key part in building the practice from scratch, establishing Red Button's technical capabilities and methodology in DDoS protection.

Research

Air-Gap Covert Channel Research

Co-authored the LED-it-GO academic paper on covert data exfiltration from air-gapped computers via hard drive LEDs, published by the BGU Cyber Security Research Center.

Leadership

Established IDF Intelligence DFIR Lab

Founded and built a DFIR lab within the Directorate of Military Intelligence from the ground up, leading digital forensics and incident response operations.

IDF Intelligence

Writing at the intersection of theory and practice.

15 publications across technical reports, case studies, and academic research.

Sep 2026
Technical Report · Red Button
CVE-2026-20349: Analysis and WAAP Implications
Sep 2026
Framework · Medium
Lifecycle and Layers: A Framework for API Security Assessment
Apr 2026
Framework · Medium
From Threat Profile to Residual Risk: A Practitioner's Approach to Cyber Risk Assessment
Mar 2026
Framework · Medium
Three-Dimensional AWS Incident Response Maturity Assessment
Feb 2026
Industry Analysis · Medium
NIS2 Directive: Insights from the Field
Mar 2025
Research Paper · Medium
Malicious and Suspicious HTTP Request Detection using Suspicious User-Agent Detection
Jul 2024
Lecture · Google and Reichman AI Tech School
The Ins & Outs of the SOC Analyst Role
Jun 2023
Technical Guide · Red Button
How to Know When a DDoS Attack is on Its Way
Mar 2023
Case Study · Medium
The Slack GitHub Security Breach Under a Risk Management-based IR-oriented Analysis
Jan 2023
Case Study · Salt Security
Salt Customer Attack Case Study: Blocking a Low-rate-per-bot HTTP DDoS Attack
Dec 2022
Technical Report · Salt Security
Successful SQLi WAF Bypass Shows (Again) how WAFs Cannot Stop API-based Attacks
Jun 2021
Technical Guide · Red Button
How to Protect Against an HTTPS Bomb DDoS Attack
Jun 2021
Case Study · Red Button
Strengthening the DDoS Protection Infrastructure of a Large Israeli Bank
Jun 2021
Case Study · Red Button
Protecting a Gaming Company Against DDoS Attacks on AWS
Feb 2017
Academic Paper · BGU Cyber Security Research Center
LED-it-GO: Leaking (a lot of) Data from Air-Gapped Computers via the (small) Hard Drive LED

13 years of cyber security
builder experience.

2026 – Present
Upcoming Role
Details coming soon
2023 – 2026
Customer-facing Cyber Security Architect
PwC NEXT

Design and development of new architecture and consulting services within a new PwC technology company, while developing methodology, optimizing for better efficiency and customer value, and performing marketing and sales processes.

  • Design of secure architectures and security solutions, from HLD/LLD, policy and procedures to deployment, and operational monitoring.
  • Cyber security and privacy risk assessment for organizations, systems, and processes.
  • Preparing organizations for, and conducting assessments according to, AWS Security Maturity Model, Bank of Israel's Cyber Security Regulation, CIS, CSA STAR, Cyber Essentials, DORA, GDPR, Israeli Ministry of Finance Cyber Regulation, Israeli Securities Authority Open Banking, Israel Protection of Privacy Regulations, ISO 27001, ISO 27017, NIS2 Directive, MITRE ATT&CK, NIST CSF, NIST SP 800-53, PCI DSS, OWASP ASVS, OWASP SAMM, SOC 2 Type 2.
  • Advisory to CISOs, C-Level executives, Boards of Directors, and Risk Committees on security strategy, program maturity, and regulatory posture.
  • AWS security and incident response.
  • Web application and API security.
  • Design and deployment of Secure SDLC processes, tooling, and secure coding standards.
  • Risk management and supply chain risk management.
  • External attack surface analysis.
2021 – 2023
API Security SOC Manager
Salt Security

Establishment and management of Salt Security's API Security SOC.

  • Management of Salt API Security SaaS Platform by monitoring, investigating API attacks, providing mitigation recommendations, configuring detection mechanisms to fix false positives/negatives, and creating detection rules.
  • API incident response and threat hunting.
  • API security testing and attack research.
  • Management of analysts and team leaders in Israel and the US.
2019 – 2021
DDoS Protection Expert
Red Button

As the 2nd person in this role, I took a major part developing it.
I led Red Button to become an AWS DDoS Test Partner — the third one in the world.

  • Security architecture of web and DDoS protection.
  • DDoS incident response, penetration testing and threat research.
  • Security engineering of WAF, DDoS protection solutions, SIEM, and AWS security services.
2019 – 2021
Deputy CISO
Innovid (via Red Button)
  • Implemented, configured, operated, and monitored security solutions as part of IT security responsibilities.
  • Created and maintained information security policies and procedures.
  • Implemented secure development methodologies based on OWASP Top 10, trained R&D and QA engineers, reproduced vulnerabilities identified in penetration testing reports, and guided remediation efforts.
  • Conducted phishing simulation campaigns to assess and improve security awareness.
  • Responded to Request for Information (RFI) questionnaires as part of contract processes.
2018 – 2019
MSSP SOC Analyst (Student position)
Dell EMC
  • Monitored and investigated cyber security incidents, produced detailed reports with findings, conclusions, and mitigation recommendations.
  • Operated, monitored, configured, and developed rules and dashboards for SIEM platforms.
  • Conducted proactive threat hunting to identify indicators of attack and potential security threats.
2016 – 2017
Cyber Security Researcher (Student position)
Deutsche Telekom Innovation Labs @ Ben-Gurion University of the Negev

Academic research in the field of cyber security.

  • Malware analysis and research.
  • Research and development of covert data exfiltration from air-gapped networks.
2011 – 2015
Information Security Officer
Israel Defense Forces, Directorate of Military Intelligence
  • Establishment of DFIR lab.
  • Design and implementation of information security policies and procedures for systems, projects, and infrastructure.
  • Security engineering, SOC, DFIR, and malware analysis.

Certified where it counts.

🔐
Chief Information Security Officer (CISO)
2015
🛡️
Data Protection Officer (DPO)
2024
AWS Certified Security - Specialty
2021
AWS Certified Cloud Practitioner
2021

Where tech meets law.

M.A. Law (Technology Track)
Bar-Ilan University
Years
2021-2022
GPA
92 - Honors
Bar-Ilan University
B.Sc. Computer Science
Ben-Gurion University of the Negev
Years
2015-2019
GPA
84
BGU

Hands-on with the stack.

Application Security & SSDLC
Checkmarx Cycode GitGuardian Jfrog XRay Mend Ox Security Semgrep
Cloud Security
Amazon Detective Aqua Security AWS CloudTrail AWS GuardDuty AWS Security Hub Defender for Cloud Orca Upwind Wiz
DDoS Protection
Akamai Kona Site Defender Akamai Routed (Prolexic) F5 Silverline Radware DefensePro
DLP
CoSoSys Endpoint Protector MyDLP
DNS & Web Filtering
Barracuda Web Security Gateway Cisco Umbrella DNSFilter NextDNS OpenDNS TitanHQ WebTitan
Data Analysis
MongoDB Redash
EDR & Endpoint Security
Avast Business Anti-Virus CrowdStrike Falcon Defender for Endpoint ESET Endpoint Security McAfee ePolicy Orchestrator SentinelOne Sophos Intercept X
Email Security
Barracuda Email Security Gateway
Firewall
Fortinet Fortigate Palo Alto Networks NGFW
GRC & Compliance
Anecdotes Sprinto
IDS & IPS
OSSEC Snort Suricata
Identity & Access Management
Okta
Malware Analysis & Sandboxing
Any.Run Cuckoo Sandbox Hybrid Analysis Intezer Analyze Joe Sandbox
Mobile Device Management
Fleet Device Management Intune Jamf JumpCloud Miradore
Network & Traffic Analysis
Burp Suite cURL CyberChef Fiddler hping Nmap nping OpenVPN Postman Tcpdump Wireshark
Password Management
LastPass Enterprise
Productivity & Collaboration
Google Workspace Jira OpsGenie
SIEM & Log Management
Datadog Elastic SIEM IBM QRadar Microsoft Sentinel RSA NetWitness Splunk
SOAR & Automation
Demisto Tines
SSPM
Wing
Vault & Secrets Management
HashiCorp Vault Piiano
Vulnerability Management
Qualys Tenable Nessus
Web Application & API Security
Akto APIsec AWS WAF Cloudflare WAF F5 ASM Imperva Cloud Security (Incapsula) Imperva SecureSphere Salt Security
XDR
Wazuh