posting velocity //
Based on 67 events over 73 days. Green days had more opens than closes, red vice-versa. The dark line is the 7-day rolling average.
Window: 180 days back. Don't read the mean — the long tail biases it. Median and percentiles are the honest summary.
Republish rate
20.7%
23 / 111 of closed jobs reposted within 60 days
Tenable's primary product line consists of Tenable.io (cloud-delivered vulnerability management), Tenable.sc (on-premise vulnerability management, formerly SecurityCenter), Tenable OT Security (formerly Tenable.ot, derived from the Indegy acquisition), and the overarching Tenable One Exposure Management Platform. These products address different deployment preferences and asset classes but share a common underlying data engine and CVE database.
The specific problem Tenable solves is the vulnerability prioritization crisis: large enterprises are exposed to tens of thousands of known CVEs at any given moment, and their security teams cannot patch everything simultaneously. Tenable provides the data — severity scores, active exploitation status in the wild, business context — to determine which vulnerabilities represent the highest real-world risk and should be remediated first. For OT environments, the problem is compounded by industrial equipment (PLCs, SCADA systems, HMIs) that cannot tolerate aggressive scanning and requires passive monitoring techniques to assess safely.
Tenable's buyers are predominantly enterprise and government organizations — financial institutions, energy companies, critical infrastructure operators, defense contractors, and federal agencies. The typical purchasing decision-maker is the CISO or VP of Security Operations, while the day-to-day users are vulnerability management teams and SOC analysts. The company has limited presence in the SMB segment; enterprise contracts often run to hundreds of thousands of dollars annually per customer.
Tenable sells primarily through a direct Sales-Led model, supported by a broad ecosystem of channel partners including MSSPs (Managed Security Service Providers), value-added resellers, and system integrators. The company lists its products on AWS Marketplace and Azure Marketplace for ease of procurement, but large enterprise transactions are handled through direct sales teams. Federal transactions often go through specialized government-focused resellers with the appropriate clearances.
Tenable's pricing for Tenable.io is based on a per-asset model — organizations pay according to the number of IP addresses, cloud instances, or OT devices they scan. Tenable Lumin, a module for exposure scoring and industry benchmarking, is an add-on priced separately. Tenable One pricing is not publicly disclosed and is negotiated on an enterprise contract basis. Nessus Professional, the entry-level scanner, is priced at approximately $3,990 per year per scanner.
Tenable's technical moat rests primarily on three pillars. First, its vulnerability database — built on more than 25 years of Nessus telemetry and supplemented by the Tenable Research team, which identifies and publishes hundreds of original CVEs annually. Second, the breadth of its plugin library: Nessus contains over 180,000 plugins covering known vulnerabilities across virtually every vendor and platform. Third, its OT-specific protocol expertise, acquired through Indegy, including deep knowledge of Modbus, DNP3, EtherNet/IP, and Profinet — industrial protocols that most IT-security vendors cannot natively analyze.
Tenable's engineering teams work primarily in Python and C/C++ for scanning engines, with cloud infrastructure built on AWS. The platform uses Elasticsearch for large-scale vulnerability data indexing and Kubernetes for orchestrating cloud workloads. The Israeli R&D team specifically focuses on OT protocol analysis, cloud security posture management (derived from Ermetic's technology stack), and identity security for Active Directory and Azure AD environments.
Nessus is the foundational product — the vulnerability scanner originally created by Renaud Deraison in 1998 as an open-source project, which Tenable closed-sourced in 2005 and converted into a commercial offering. Nessus Professional is the current commercial product aimed at individual security practitioners and small teams, priced at approximately $3,990 per year. Nessus Expert, launched in 2022, extended the scanner to include cloud infrastructure scanning and Infrastructure-as-Code (IaC) analysis for Terraform and CloudFormation templates, at a higher price point of approximately $5,990 per year per scanner.
Tenable.io is the flagship cloud-delivered vulnerability management platform, launched in 2016. It handles continuous asset discovery and vulnerability scanning for enterprise environments ranging from a few thousand to millions of assets. Sub-modules within Tenable.io include Web Application Scanning, Container Security (for Docker and Kubernetes environments), and Tenable Lumin for benchmarking exposure scores against industry peers. As of 2023, Tenable.io had more than 40,000 customers globally across all license tiers.
Tenable.sc (SecurityCenter) is the on-premise equivalent of Tenable.io, designed for regulated industries and government agencies that cannot deploy SaaS solutions due to data residency or classification requirements. It includes a full API and integrates natively with Tenable's compliance reporting templates, which cover frameworks including PCI-DSS, HIPAA, NIST 800-53, and DISA STIGs.
Tenable OT Security (formerly branded as Tenable.ot, prior to that as the Indegy product) addresses security for industrial control systems and operational technology networks. It uses a combination of passive network monitoring and safe active queries to inventory OT assets and identify vulnerabilities without risking disruption to live production equipment — a critical constraint for power grids, water treatment facilities, and manufacturing lines. This product line is developed primarily by the Israeli team in Tel Aviv.
Tenable One is the unified Exposure Management Platform, initially launched in 2022 and significantly enhanced through 2023 and 2024. It aggregates findings from Tenable.io, OT Security, Identity Exposure, and Cloud Security into a single Exposure Score, designed to be consumed by executive leadership and board-level audiences rather than purely by technical teams. Tenable One represents the company's strategic vision for moving up the value chain from tactical vulnerability scanning to strategic risk quantification.
Tenable Identity Exposure (formerly Alsid, acquired in 2021 for approximately $98 million) provides continuous monitoring of Active Directory and Azure Active Directory configurations for misconfigurations and attack paths. This is particularly relevant given that Active Directory compromise is a standard early step in ransomware attacks. The product was integrated into the Tenable One platform in 2023.
Tenable holds FedRAMP Authorization at the High baseline — achieved in 2020 — as well as SOC 2 Type II and ISO 27001 certifications. The FedRAMP High authorization is particularly significant as it enables deployment within classified and sensitive government environments, including DoD agencies and intelligence community systems.
Qualys (NASDAQ: QLYS) is Tenable's closest direct competitor. Founded in 1999, Qualys offers a cloud-native vulnerability management and compliance platform, and the two companies compete head-to-head for the same CISO budgets. The primary differentiation is that Qualys positions itself more broadly across GRC (Governance, Risk, and Compliance) workflows, while Tenable has invested more heavily in OT security and the Exposure Management narrative. In competitive evaluations, Qualys is frequently perceived as stronger on compliance reporting, while Tenable is considered stronger on vulnerability depth and OT coverage.
Rapid7 (NASDAQ: RPD) represents a distinct competitive archetype — its InsightVM product competes directly with Tenable.io on vulnerability management, but Rapid7's broader platform (InsightIDR for SIEM and SOAR, InsightAppSec for application security) gives it a more integrated security operations pitch. Organizations choosing between the two often weigh Tenable's deeper vulnerability data against Rapid7's unified detection and response capabilities. Both companies appeared in the Leaders quadrant of the Gartner Magic Quadrant for Vulnerability Assessment in 2023.
CrowdStrike (NASDAQ: CRWD) represents the most significant emerging competitive threat. CrowdStrike launched Falcon Exposure Management in 2023, leveraging its endpoint telemetry to offer vulnerability data with native agent integration. Because CrowdStrike already has agents on endpoint devices for EDR purposes, its vulnerability data can be richer on those assets than an agentless scanner like Nessus. The broader trend of platform consolidation — where CISOs want XDR, CNAPP, and VM from a single vendor — is a structural headwind for Tenable as a pure-play exposure management company.
Tenable's pricing occupies a mid-to-premium position in the market. It is not the cheapest option — open-source alternatives like OpenVAS exist, and Wiz or Orca Security can cover cloud environments at competitive price points — but Tenable commands a premium justified by the depth of its plugin library, the breadth of its compliance templates, and its OT coverage. The company does not compete on price and has not publicly pursued a freemium go-to-market strategy beyond the existing free tier of Nessus Essentials (limited to 16 IPs).
On the government side, Tenable secured a significant multi-year contract with CISA under the Continuous Diagnostics and Mitigation (CDM) program, which provides vulnerability management tools to U.S. civilian federal agencies. This contract, renewed and expanded in the 2020–2023 period, represented a material revenue contributor and a strong reference for international government sales. In terms of trajectory, Tenable is broadly defending and growing its installed base in enterprise and government, while also pursuing expansion through Tenable One's upsell potential to existing customers.
Sector tailwinds are favorable: the total number of CVEs published annually has grown from under 10,000 in 2016 to over 25,000 in 2022, creating an ever-larger problem for vulnerability management teams. Additionally, the European NIS2 Directive, which came into effect in October 2024, mandates formal vulnerability management practices for critical infrastructure operators across EU member states — expanding Tenable's addressable market in Europe materially. The proliferation of connected OT devices (Industry 4.0) continues to grow the addressable market for Tenable OT Security.
Tenable's Israeli operations are based in Tel Aviv and Ramat Gan. The Tel Aviv office serves as the primary Israeli hub, with additional space in Ramat Gan that was expanded following the Ermetic acquisition in 2023. The offices are positioned within easy proximity of the cluster of cybersecurity companies and startup ecosystem that concentrates in the Tel Aviv metro area.
Israel hosts approximately 300 Tenable employees, representing roughly 15% of the global workforce. Almost all of these positions are in R&D, product management, and security research. Core Israeli functions include: development and maintenance of Tenable OT Security (the former Indegy product), cloud security engineering (the former Ermetic team building CIEM and CSPM capabilities), vulnerability research as part of the global Tenable Research group, and core platform engineering for Tenable One.
In the last 24 months, Tenable's Israeli headcount has grown significantly. The Ermetic acquisition, closed in October 2023, added approximately 80 to 100 Israeli employees to Tenable's rolls. Rather than integrating those employees and then downsizing — a common pattern in acquisitions — Tenable retained the core Ermetic engineering team in Israel to continue developing CIEM and cloud identity security capabilities. This represents a counter-cyclical investment in Israel at a time when many tech companies were reducing headcount through 2023 and 2024.
The founders of Tenable — Ron Gula, Jack Huffard, and Renaud Deraison — are not Israeli. Gula and Huffard are American, and Deraison is French. However, the Israeli DNA of Tenable comes directly from its acquisitions: Indegy was founded in 2014 by Barak Perelman and Mille Gandelsman, both of whom are veterans of Israeli intelligence and military technology units. Ermetic was co-founded by Shai Morag, Arick Goomanovsky, and Or Aspir — all of whom came out of Israeli technology backgrounds, with Morag having previously served as Vice President of Products at Dome9 Security, itself an Israeli cloud-security company acquired by Check Point.
Typical roles that Tenable recruits for in Israel include backend engineers (Python, Go, C++), OT/ICS security researchers, cloud security engineers focused on AWS and Azure entitlements, vulnerability researchers, and senior product managers with domain expertise in security operations. Given the Ermetic heritage, there is particular demand for engineers familiar with cloud-native identity systems, Kubernetes security, and multi-cloud access governance.
The cultural and hiring pipeline in Israel draws heavily from IDF intelligence and technology units. Indegy's founders and initial team were connected to Unit 8200 and related signals intelligence communities, and this lineage has influenced the research-first, protocol-deep culture of the OT team. Ermetic's team similarly came from elite IDF technology backgrounds. Tenable benefits from Israel's strong pipeline of cybersecurity talent emerging from national service — a structural advantage that is difficult to replicate in other geographies and that the company has explicitly leaned into through its Israeli acquisition strategy. No specific notable Israeli investors hold named stakes in Tenable's public filings, but Marker LLC and Accel Partners were among the investors in Indegy prior to its acquisition.
news feed
<p><strong>טנאבל</strong> (Tenable) ישראל מרחיבה את פעילותה בארץ ומגייסת בימים אלה כ-40 עובדים חדשים למרכז הפיתוח והמטה בתל אביב – תוספת של כ-15% לכוח האדם הקיים. זאת נוסף על יותר מ- 60 עובדים חדשים שהצטרפו לחברה מתחילת השנה. החברה מעסיקה כיום כ-300 עובדים במרכז הפיתוח והמטה הישראלי שלה, בבניין לנדמרק בת"א. המרכז, שמתבסס על שש רכישות של סטארט-אפים ישראלים שביצעה טנאבל העולמית ב-6 השנים האחרונות, מנוהל על ידי <strong>ולאד קורסונסקי</strong>, שמכהן גם כסמנכ"ל טכנולוגיות ראשי של טנאבל העולמית.</p> <p>הגיוס הנוכחי נועד לתמוך בגידול פעילות המחקר, הפיתוח והמוצר של טנאבל, ענקית סייבר אמריקנית המפתחת בישראל חלק גדול מטכנולוגיות הליבה שלה. חברת טנאבל, שנוסדה ב-2002 בארה"ב ונסחרת בנסדא"ק, משרתת יותר מ-40 אלף לקוחות ברחבי העולם, בהם כ-65% מחברות פורצ'ן 500, עם הכנסות של מיליארד דולר בשנת 2025.</p> <p>בין המשרות הפתוחות כרגע: מפתחים, מהנדסי תוכנה, מהנדסי AI, ענן ו-OT, חוקרי סייבר, מנהלי מוצר, משרות במחלקת ה-HR ועוד.</p> <p>"ישראל היא המרכז השני בגודלו של Tenable בעולם, והמקום שמשפיע יותר מכל על אסטרטגיית המוצר של החברה ועל עיצוב עתידה הטכנולוגי. זאת, הודות לריבוי הטאלנטים בישראל, ה-mindset הסטארט-אפיסטי שלהם, הרקע הביטחוני, האקוסיסטם בתחום הסייבר, ועכשיו גם האקוסיסטם המתפתח בעולם ה-AI. כל אלה הופכים את ישראל לביתה השני של טנאבל", אמר קורסונסקי. "גם שלוש השנים האחרונות לא שינו את הכיוון שלנו בטנאבל, כאשר עובדינו במרכז הישראלי המשיכו לדלוור ולהוכיח את חוסנו ויכולותיו של ההיי-טק הישראלי בתקופות משבר, ובמקביל המשכנו לגדול אורגנית וגם לא אורגנית. אנו …
9 ביולי 2026
<p>כ-50 חוקרות סייבר בישראל הגיעו למפגש Security <strong>ResearchHers</strong> ראשון מסוגו בישראל, שההובילה חברת הסייבר <strong>טנאבל</strong> (Tenable). בין המשתפות: נציגות <strong>ממיקרוסופט, פאלו אלטו, טנאבל, </strong><strong>Zenity</strong><strong>, </strong><strong>Dream</strong><strong>, </strong><strong>XM</strong><strong>, </strong><strong> Cyber</strong><strong> ועוד</strong>. מטרת המפגש ליצור קהילת נשים חוקרות סייבר שעובדות יחד, ולשלוח קריאה לעודד יותר נשים להיכנס לתחום שבו במחלקות הפיתוח הנשים הן מיעוט, וביחידות המחקר האחוז שלהן נמוך עוד יותר.</p> <p><strong>שלי קליין</strong>, ראשת צוות מחקר אבטחה, <strong>וליאת חיון</strong>, סמנכ"לית ניהול מוצר בטנאבל, אירחו את האירוע שנדונו בו נושאים מקצועיים, בהם נראות מקצועית – כיצד להציג את המחקר שלך על במות בכנסי סייבר? השפעה אישית על מוצר החברה ומפת הדרכים שלו: כיצד להבטיח שממצאי המחקר</p> <p><img alt="מימין: ורוניקה סנדרוביץ, חוקרת אבטחה בפאלו אלטו; ספיר שניידר, חוקרת סייבר בכירה במיקרוסופט; ליאור פתיחה - חוקרת אבטחהב-XM Cyber; ליאת חיון, סמנכ"לית ניהול מוצר ב-טנאבל; שלי קליין, ראש צוות מחקר אבטחה בטנאבל; דניאלה שלו, חוקרת אבטחה בחברת דרים." class="attachment-post-thumbnail size-post-thumbnail wp-post-image" height="416" src="https://www.pc.co.il/wp-content/uploads/2026/06/חוקרות-סייבר.jpg" title="מימין: ורוניקה סנדרוביץ, חוקרת אבטחה בפאלו אלטו; ספיר שניידר, חוקרת סייבר בכירה במיקרוסופט; ליאור פתיחה – חוקרת אבטחהב-XM Cyber; ליאת חיון, סמנכ"לית ניהול מוצר ב-טנאבל; שלי קליין, ראש צוות מחקר אבטחה …
8 ביוני 2026
hiring signal · from our data
From our job data · always current
17 open roles in Israel · +61 worldwide
Live openings we track — Israel first, plus worldwide when we have them.
Top roles