For instance the attack path isnt immediately clear and there needs to be a period of developing proof of concept exploits that are then tested in a variety of environments, there needs to be persistence techniques developed, there needs to be a C2 system, there needs to be a methods to avoid detection. Stuxnet was probably a collection of many 0days that were used in conjunction. Each 0day probably takes months of "dev time" at minimum to develop.
I’ve seen firsthand that security engineers tend to be paid less than mainstream dev roles, but pocket money for the best talent in the world seems unlikely. The IDF needs them more than they need the IDF. Even with religious beliefs in play, wouldn’t market forces still have an effect?
Well, this of course only applies to the conscripts who are serving their mandatory (almost) 3 years in the IDF. It's not like you can leave and if you're planning to build your career in this field it obviously preferable than serving in combat or logistics units.
I would assume they are more like interns/apprentices though (how useful can most 18-20 year olds be anyway?) and most real work is done by people who are actually being paid a salary.
Basically a signal intelligence/hacking unit just like any other military outfit in their forces.
It is mostly 18 to 21 year olds. And I would think it looks really good in your CV if you want to work on the sector later.
I wonder which unit is the elite one.