Yuval Avrahami

Vulnerability Researcher at Wiz

Israel
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
Yuval Avrahami is a vulnerability researcher with seven years of hands-on experience in offensive and defensive security, currently focused on cloud and container risk at Wiz. He has a proven track record from the Israeli Air Force to industry-leading teams at Twistlock and Palo Alto Networks, and spent time as an independent bug bounty hunter honing real-world exploit discovery. Yuval contributes to open-source security tooling—most notably adding Kubernetes RBAC checks to the widely used Checkov project—to reduce misconfigurations and privilege escalation risks in infrastructure-as-code. Comfortable working from low-level research to production-ready detection, he blends exploit creativity with pragmatic, test-driven mitigations.
code7 years of coding experience
job7 years of employment as a software developer
languagesEnglish
github-logo-circle

Github Skills (11)

rbac10
it-security10
kubernetes10
static-analysis10
python10
kubernetes-pods10
security10
terraform9
terraformer9
compliance9
aws8

Programming languages (7)

ShellCRustOpen Policy AgentGoHTMLPython

Github contributions (5)

github-logo-circle
bridgecrewio/checkov

Apr 2022 - May 2022

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Role in this project:
userSecurity Engineer
Contributions:1 review, 10 commits, 3 PRs in 26 days
Contributions summary:Yuval primarily contributed to enhancing the security posture of the project by introducing and refining Kubernetes RBAC checks. They implemented multiple checks that specifically address vulnerabilities related to overly permissive roles and cluster roles, specifically focusing on controlling webhooks, approving certificate signing requests, and binding or escalating roles. These changes involved defining RBAC operations and creating corresponding test cases to ensure proper functionality. The user also made minor updates to the project's versioning.
gcppolicy-as-codecomplianceaws-securityaws
twistlock/sa-hunter

Jan 2022 - May 2022

Contributions:20 commits, 1 push in 4 months
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial