
Security Researchers: Digital Fighters Series
Oak Security: “The change of the industry made us enter an ocean of uncharted waters”
Oryan Perlmutter, Head of Security Research at Oak, describes the necessity of automating "boots work" in a highly competitive landscape, as part of CTech’s Security Researchers series.
“The rapid change and evolution of the industry, especially with the adoption of AI agents, made us enter an ocean of uncharted waters,” says Oryan Perlmutter, Head of Research at cybersecurity company Oak. “As AI revolutionizes the world, the entire landscape is changing at the fastest rate of all time; identity is being rewritten.”
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
Perlmutter’s entry into the security field began with his military service in Unit 8200, where he worked on critical cyber campaigns, taking on roles in reverse engineering and stealth operations, and eventually leading a multidisciplinary group of researchers and security specialists. Today at Oak, Perlmutter explains he’s part of a research team that is “a tight core of experienced superstar specialists, working along multiple tracks and different types of research.”
You can read the entire interview below.
ID Card
Company name: Orca Security
Founders: Shai Morag (CEO), Tal Marom (CPO)
Year of founding: 2026
Current number of employees: ~60
Company Description:
Oak is an AI-native Identity Operating System; a complete stack of identity visibility, intelligence, governance and security tools with a single platform, which replaces many legacy systems and silos. By addressing all identity types, including NHI and AI Agents, as first-class citizens, Oak allows organizations to adapt to the AI era and gain control and governance over their AI agents.
Oak also provides its own AI Agents (”Acorns”) allowing identity and security teams to utilize the full intelligence provided by Oak in order to enhance their teams running their dedicated agents within Oak.
About Oak's Security Research Team:
Oak Research is responsible for Oak’s identity and security subject matter expertise, innovation and technical and scientific research within the space of our problem.
The research team is deliberately small and dense with expertise rather than a large standing team. It’s a tight core of experienced superstar specialists, working along multiple tracks and different types of research in order to provide for all of Oak’s research needs.
The team functions as a strike team of superstars: every researcher owns a thread end-to-end, from hypothesis to a shipped detection, published finding, feature specification and vision. Every piece of work is peer-reviewed to ensure our deliverables are meeting our gold standard. As the team scales, we're protecting that density, not diluting it.
What is your background in cyber, and what led you to specialize in security research?
I’ve been fascinated with deeply understanding how things work, starting from a young age. Technology was a continuation of it, beginning in my high school years.
This led directly to my military service at Unit 8200, where I worked on the unit’s most sensitive and critical cyber campaigns. During my service, I took multiple hands-on roles in R&D, security research, reverse engineering, stealth operations and so on, before being promoted to team leader, and after a couple of years, to head a multidisciplinary group of researchers, R&D, network analysts and security specialists gathered around intelligence-gathering missions.
My entire service led me to deepen my love for cyber security, understanding how technology works, how it’s built, and innovative concepts, while also developing a passion and skills for leading people within the domain to tackle the hardest challenges. From there, working in leading cyber-focused teams, shaping and building products that help people solve real problems, was just a continuation of evolving and practicing within the field I’m passionate about.
Oak was a natural next step. As AI revolutionizes the world, the entire landscape is changing at the fastest rate of all time; identity is being rewritten, and I couldn’t miss out on the opportunity to take a leading part in such a big change.
What does your security research team look like in action?
Research at Oak runs full end-to-end, from raw data and problem statements to the ideas that carry it outward and up to a full PoC.
In reality, this means we define the problem we want to target. Targets can be very broad and high-level, like, “What does ideal identity governance look like for AI agents?” or as tactical and target-focused as, “How do we surface cases where there’s a shadow admin in a specific cloud environment?”
As we mark our target, we start the research work with a first-principles approach to the content and data we gather. We establish what we know and can count on, followed by investigating ways to either put these principles together to build additional foundational truths and solutions, or finding where they break apart. We look for gaps, ideate how we need to discover them, and bring up new solutions.
This involves a lot of knowledge gathering, going through APIs and logs, and challenging what data is accessible and can be gathered. We take combinations of that data and build small systems and automations to achieve and answer our goal – it can be a document describing the way a problem should be approached, a working PoC simulating problematic cases and solutions, or content that will be embedded into the platform so Oak’s product ships the most advanced knowledge and covers the most complex cases across many different assets.
How does the research team influence your company at large?
Research is the department that manufactures Oak's identity expertise. This, at large, influences the company in three ways:
Firstly, content: everything the platform "knows" contextually about identities. Every risk, every score, every insight surfaced to a customer traces back to a research thread: real identity data, studied until we understand exactly how a permission, a token, or an agent works, how their permissions are derived and how they can be abused. This knowledge is then infused into the logic the product ships in order to best serve our customers.
Secondly, strategic direction and positioning. Our thought leadership and innovative approach feed into Oak’s strategy and help steer Oak’s future plans and goals in the direction most suited for the space and the way we envision it.
Finally, shaping the space. Oak’s research innovation, findings, and thought leadership are the ones positioning Oak at the cutting edge of the identity industry, and, among other companies and teams, are the ones shaping the way the identity industry will look in the future.
What has been your team’s most significant security discovery to date?
We recently had multiple discoveries significant to the product and our customers, including a significant security flaw in the way a very large identity provider authenticates. We also found a couple of sophisticated attack paths allowing privilege escalations, which enable users to gain permissions and access to business functionalities and apps they are not supposed to via cross-app authentications. Effectively, this made the identity perimeter even broader than before. We developed a heuristic algorithm with close to perfect results discovering shadow admins within organizations, exposing how standard users can gain admin privileges in environments they are not supposed to.
Who or what is your 'Moby Dick'?
If I had to name one: a full, provable context graph of all identities. An attribution of all actions taken in an organization to actors, and for autonomous AI agents, the ability to say, for any agent, at any moment, exactly who is accountable for what it just did, why that action was taken, and how it serves the goal the agent was supposed to achieve, with zero ambiguity, across any platform it touches.
On top of such a graph, we can have the governance and enforcement to make truly informed decisions for every action, whether it should be allowed and take place or not, and create a truly inline, strictly just-in-time identity model.
How would you characterize the competition between research teams today?
I think it’s very competitive. The rapid change and evolution of the industry, especially with the adoption of AI agents, made us enter an ocean of uncharted waters.
There are a lot of teams working in order to research, map and discover these waters. These are very talented teams, working on real problems, and it’s only natural that this will create a competitive environment where the significant discoveries and innovations are yet to be made and there’s a race towards them.
This highly competitive scenario, in my view, is a healthy sign. We’re working on something real and there’s a big effort invested into it. It just proves how big the prize at the end could be and the influence that could be made.
What is your take on the future of the human security researcher?
AI isn't replacing the security researcher; it's replacing the parts of the job where the boots work is needed: the grinding, repetitive first-pass through data, logs, known patterns, the search for existing research on the topic, summarization, and catching up-to-date.
We live this daily on our own team. We build and run AI agents (an identity research agent helping us find patterns and detections for issues within data pulled for example) to help us do that first-pass across identity data at a scale no human researcher could.
This actually frees the human researcher to invest their time in the true innovation and deep thought, the parts AI still can't do: forming the hypothesis, deciding which anomaly is actually interesting, and knowing when a finding is real versus merely statistically noisy.
The researcher's job thus moves from generating candidates to being the brain generating ideas, and the one holding the taste and judgment to direct which candidates matter and what should be explored further, as well as owning the parts of research: true novel discovery, first-principles reverse engineering, and adversarial thinking that AI can accelerate but not originate.
If anything, in my opinion, the bar for a good human researcher will go up. Once the mechanical work is automated, what's left is pure signal, and the researchers who thrive are the ones who can direct an army of AI agents and still tell, better than the agents can, which of its findings is actually gold while directing and having agents assist them on the way to validation and proof.














