Some of the people on this page built AppSec Labs. Others spent a few years testing applications here and went on to write tools the industry depends on, or to found companies acquired by some of the largest names in security. Both are worth recording.
We want to be careful about how we say this. None of them owe us their careers. They were talented when they arrived and what they built afterwards they built themselves. But there is a pattern, we are proud of it, and it says something true about the kind of work that happens here.
Israel Chorzevski
At AppSec Labs, 2010-2018
Here: Our first employee, and for eight years a cornerstone of the company. Joined in 2010 as a penetration tester, became a team leader, and then CTO, leading our mobile and IoT security research.
Barak Tawily
At AppSec Labs, 2013-2015
Here: Application security consultant. Wrote Autorize, the Burp Suite extension for detecting broken authorization, which the industry still uses today.
Since: Went on to Wix, then co-founded Enso Security as its CTO – the application security posture management company acquired by Snyk in 2023. The story of Autorize.
Tal Melamed
At AppSec Labs, 2013-2017
Here: Director of Application Security – technical direction of our consultants across web, mobile, desktop and IoT engagements.
Since: Head of security research at Protego Labs (acquired by Check Point, 2019), then co-founded CloudEssence, acquired by Contrast Security in 2020, where he leads cloud-native security research. Led the OWASP Serverless Top 10 and built DVSA, the Damn Vulnerable Serverless Application, which he donated to OWASP.
Chilik Tamir
At AppSec Labs, 2011-2015
Here: Our second employee, and our Chief Scientist. Created iNalyzer, the open-source iOS application analysis framework we published, and taught mobile application hacking alongside our Black Hat courses.
Since: Chief architect for research and development at Mi3 Security, acquired by Zimperium in 2018, where he is now VP of platform research. His SandJacking iOS attack and Su-A-Cyder malware proof-of-concept generator were presented at Black Hat Asia and HITB, and he speaks regularly at Black Hat, HITB and RSA. iNalyzer, and why we retired it.
Why this keeps happening
We think it comes down to what the work is actually like.
- Real applications, constantly changing. A consultancy tests a different system every few weeks — unfamiliar stacks, unfamiliar business logic, someone else’s architectural decisions. You develop range quickly because you have no choice.
- Nowhere to hide behind a tool. The findings that matter here are the ones no scanner produces. That forces genuine understanding of how an application works, which is the same skill that lets someone later spot a gap in the market.
- You have to explain yourself. Every finding gets defended to the engineers who wrote the code. It is a demanding way to learn how to communicate, and it is why several people here have ended up leading research teams.
- A small team means real ownership. Nobody is a cog. If you think a tool should exist, you build it — which is precisely how Autorize came to exist.
The people testing your application today
Expert-led testing of complex authenticated applications – multi-tenant isolation, authorization/BOLA, business-logic and workflow abuse, complex role models – with developer-usable remediation.
The point of this page is not nostalgia. It is that this is the calibre of person who does the work — and the reason we can say that is that we have kept hiring for the same thing for fifteen years. Talk to us about testing your application, or if you recognise yourself in the description above, we are always interested in talking.
More of the same history: Autorize, the Black Hat trainings, the book, and the tools we retired.
