דרושים » אבטחת מידע וסייבר » Security Detection Engineer

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Herzliya
Job Type: Full Time
We are seeking a talented, tech savvy Detection Engineer to join our Cyber Security team and elevate detection and response capabilities across cutting-edge systems.

Responsibilities

Lead initiatives to enhance our capabilities for effectively detecting and responding to security incidents.
Design, develop, refine detection rules, alerts, and dashboards across security platforms to identify malicious or suspicious behavior.
Deploy, manage, and maintain the infrastructure components of various detection platformsincluding indexers, search heads, forwarders, and clustersto ensure high availability, optimal performance, and scalability
Parse and analyze logs from endpoints, servers, network devices, cloud services, EDR/XDR, and more.
Automate detection pipelines and content deployment using Detection-as-Code methodologies and CI/CD frameworks.
Tune and optimize detection logic to minimize false positives and enhance alert fidelity.
Collaborate with different teams to continuously improve detection coverage.
Integrate with SOAR tools and workflows, developing playbooks that enhance speed and consistency of incident response.
Perform proactive threat hunting, alert triage, and incident investigations, leveraging threat intelligence and different cybersecurity frameworks.
Requirements:
Minimum 4 years in detection engineering, or equivalent roles.
SIEM proficiency: Hands-on experience with Splunk or Azure Sentinel is mandatory; working with both is highly desirable.
Familiarity with Detection as Code frameworks and CI/CD best practices.
Hybrid environment: Experience operating across Linux/Windows on-premises and cloud infrastructure.
Security fundamentals: Strong grasp of networking, operating systems, EDR/XDR, IDS/IPS, proxies, firewalls, and endpoint behaviour.
Analytical mindset: Able to distinguish between false positives and true alerts and continuously refine detections.
Collaboration & communication: Work effectively across teams to implement robust detection strategies.
Self‑driven: DIY approachadept at researching, building, and deploying solutions end‑to‑end.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8368233
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
1 ימים
דרושים בריקרוטיקס בע"מ
Location: More than one
Job Type: Full Time and Hybrid work
* Penetration Tester / Red teamer at a Leading Cyber Firm*
Our company specializes in cybersecurity consulting and we are currently expanding our team, and looking for a talented *PT* to join our top star Red team.
We offer a dynamic and challenging role in a company that greatly values human capital and work with cutting-edge security technologies and top-tier clients.

*Youll be responsible for: *
Conducting penetration testing and security surveys in the organization's infrastructure systems.
Hands-on experience in penetration testing cloud, web, and mobile applications.

What you should have:

Ability to work in a dynamic, fast-moving, and growing environment
Ability to plan and project / tasks delivery
Ability to work in team
Ability to write and review PT reports in Hebrew and English
Deep understanding of security principles, theories, and attacks.
Requirements:
*Job Requirements:*
2+ years of hands-on experience in penetration testing of applications, infrastructure, and networks, including deep understanding of Linux and Windows environments.
Strong expertise in Active Directory penetration testing, including enumeration, privilege escalation, lateral movement, and use of tools such as BloodHound, Mimikatz, and Impacket.
Proficiency in scripting ( Python, PowerShell, Bash) for automation and custom offensive tooling.
Practical experience with EDR evasion and advanced offensive security techniques, with familiarity in both open-source and commercial PT tools.

Nice to have:
Experience with system network management / programming / information security products - an advantage.
Offensive Security Certifications such as OSCP, AWAE, OSCE. - an advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8395025
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Herzliya
Job Type: Full Time
We are looking for a talented, tech-savvy individual to join our Cyber Security team and help us tackle the toughest security challenges in cutting-edge ecosystem.

In this role, you will be a subject matter expert and play a major part in our efforts to build and maintain security infrastructure, design secure architectures, enforce security best practices, and automate security processes.

The Cyber Security team is composed of strong and experienced security engineers, responsible for defining the security strategy and managing all of infrastructure.

Responsibilities:

Define, implement, and maintain security policies, standards, and methodologies; ensure they evolve with new threats and technologies.
Design, deploy, and operate detection, prevention, and response technologies across a scaled, diverse, and complex environment (hybrid infrastructure: public cloud + on-premises).
Build and operate secure infrastructure: hands-on ownership of security configurations and system hardening.
Conduct security assessments, secure-design reviews and architecture assurance reviews to identify and mitigate possible security risks.
Automate security processes: configuration deployments, infrastructure management, detection, response, compliance checks, patching, configuration drift, etc.
Design, develop, and implement secure software development and deployment pipelines, incorporating best practices, automation, and CI/CD methodologies.
Stay ahead of emerging cyber threats and technologies: research, evaluate, pilot, and integrate where relevant.
Participate in creating incident response playbooks, coordinate incidents investigations, root cause analysis, and lessons learned.
Requirements:
6+ years of experience in security engineering, or equivalent.
Strong hands-on experience with security tools, services, deployment automation, and configuration management.
Demonstrated expertise in cloud security, including low-level design of secure cloud architectures (e.g., VPCs, network segmentation, endpoints, encryption).
Solid understanding of operating systems (Linux, Windows, macOS) and networking fundamentals (TCP/IP, DNS, VLANs, routing, etc.).
Well-versed in identity & access management: Conditional Access, Zero Trust, RBAC, identity lifecycle, access reviews, compliance, and governance.
Hands-on experience with infrastructure as code.
Experience securing microservices, containerized environments and serverless.
Strong knowledge of modern Secure Software Development Lifecycle (SSDLC) practices: threat modeling, secure design, code reviews, API security, SAST/DAST/SCA.
Programming/scripting skills to build automation, tools, and playbooks.
Self-motivated and autodidactic, with the ability to deliver solutions end-to-end as part of a do it yourself approach.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8368231
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Herzliya
Job Type: Full Time
Our Security team is looking for a hands-on Cloud Security Specialist with a strong focus on Identity & Access Management (IAM) to help drive our security posture across cloud environments. In this role, youll be the go-to expert for IAM governance and cloud identity controls across AWS and GCP- enabling secure access at scale, while working closely with security, DevOps, and engineering teams to solve complex security problems.
The ideal candidate is highly motivated, demonstrates a can do' attitude and needs to have a combination of technical and communication skills, as well as the ability to handle a mix of multiple tasks including projects and technical work.
What you'll do:
Build and maintain secure role, permissions, and account structures aligned with least privilege and zero trust principles.
Manage and govern human and non-human (machine) access to sensitive SaaS applications (e.g., Okta, Git, etc.).
Monitor and improve cloud identity hygiene: users, roles, service accounts, federated access, and third-party integrations.
Automate detection and remediation of IAM misconfigurations and over-privileged identities.
Collaborate with DevOps and engineering to embed IAM best practices into infrastructure pipelines and app deployments.
Support incident response and investigations related to IAM abuse, access misuse, or privilege escalations.
Contribute to detection rules, playbooks, and cloud-specific DFIR processes.
Provide guidance during access reviews, role audits, and trust relationship validation.
Lead the design and enforcement of IAM controls across AWS and GCP.
Requirements:
4+ years of experience in security, with at least 23 years focused on cloud IAM, especially in AWS (IAM roles, policies, STS, Organizations, Identity Center, SCPs).
Experience managing IAM in GCP (service accounts, workload identity federation, custom roles).
Solid knowledge of IAM principles: least privilege, zero trust, RBAC/ABAC, identity lifecycle, and access governance.
Familiarity with DFIR in cloud environments: log analysis, alert triage, evidence collection, and investigations.
Hands-on experience with infrastructure-as-code (e.g., Terraform, CloudFormation).
Proficient in scripting (e.g., Python, Bash) for automation and IAM enforcement.
Proven experience collaborating with engineers, SREs, and IT to solve complex identity and access issues.
Excellent English communication skills verbal and written.
Self-starter with strong problem-solving skills and attention to detail.
Bonus Points:
Familiarity with Wiz or similar CSPM/CIEM platforms.
Certified AWS Security Specialty.
Experience in handling or supporting IAM-related incidents (escalations, investigations, remediation).
Experience with cloud-native detection tools (AWS GuardDuty, CloudTrail, GCP SCC, etc.).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8369794
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
21/10/2025
חברה חסויה
Location: Herzliya
Job Type: Full Time and English Speakers
We are seeking an experienced MDR Team Lead who will oversee a team of MDR Security Analysts.
This oversight includes training and developing the knowledge and skills needed to execute the MDR mission, ensuring adherence to all operating policies and procedures, ensuring the delivery of the MDR service within all SLAs, and serving as a point of technical and operational escalation for MDR analysts.
Data is the #1 target of attackers, and Varonis' Managed Data Detection and Response (MDDR) customers entrust our team with the security of their data. MDR Team Leads are the lynchpin of MDR operations, ensuring the team is working 24x7 to monitor, triage, investigate, and escalate incidents where data is at risk and to ensure we meet operational SLAs.

Responsibilities:
Technical and operational escalation point for investigations, incidents, and other elements of the MDR service.
Assist in the development, documentation, analysis, testing, and modification of Varonis threat detection systems, playbooks, runbooks, and MDR team operations.
Continuously train the team so they are equipped with the required skills and knowledge to effectively execute the MDR service.
Validate findings and coordinate investigative efforts with customers and internal teams.
Ensure all investigative findings are documented and communicated appropriately by the team, including tracking in CRM.
Maintain up-to-date knowledge of all aspects of Varonis MDR service.
Oversee and execute programs, projects, operational tasks, and responsibilities related to the MDR service.
Conduct regular performance reviews and quarterly SWOT analyses to drive team growth and development.
Requirements:
Proven success in leading and managing within a team-oriented environment.
4+ years of experience working in cybersecurity operations in a global cybersecurity company
2+ years of experience leading a team.
Degree or certification(s) in cybersecurity and/or proven ability to execute across cybersecurity operations disciplines, including monitoring, detection, investigation, and incident response.
Proven ability to deliver security operations service while meeting SLA and other operational requirements.
Knowledge of common security technologies and tools including network-based (firewall and IDS), host-based (EDR and AV), data-based (DLP and DSPM), and identity-based (PAM and IAM).
Proven ability to creatively problem-solve when handling complex issues.
Strong analytical and critical thinking skills.
Excellent communication skills in English (written and oral) and interpersonal skills (direct reports, colleagues, and customers).
Attention to detail and the capability to deliver outcomes autonomously.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8379510
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
29/09/2025
חברה חסויה
Location: Herzliya
Job Type: Full Time
CodeValue is looking for a skilled and experienced Security Architect to join our team and take a leading role in designing, implementing, and governing the security posture of our cloud and enterprise environments. This individual will work closely with cross-functional teams to ensure security is embedded across systems, applications, and workflows, aligning with industry best practices and compliance requirements.
Requirements:
Mandatory Qualifications
* At least 3 years of experience as a Security Engineer/DevSecOps
* Understanding of the Shared Responsibility Model
* In-depth knowledge of securing at least one cloud platform: AWS / Azure / GCP
* Understanding of Landing Zone and Well-Architected Best Practices
* Expertise in IAM (Identity and Access Management) network security (VPC, SG, FW).
* Experience in writing cloud policies (e.g., SCP Monitoring and logging (CloudTrail, GuardDuty, Security Hub).
* Strong understanding of general information security: security principles, encryption, risk management, incident response
* Scripting languages: Python / Bash / PowerShell
* Experience in configuring WAF Infrastructure as Code (IaC): Terraform / CloudFormation Preferred Qualifications:
* Experience in Kubernetes and container security Data security (encryption, KMS ), securing cloud services (e.g., EC2, Lambda, Containers
* Relevant certifications: AWS Certified Security – Specialty, Azure Security Engineer, CCSP (strong advantage).
* Familiarity with DevSecOps and code security tools (SAST/DAST)
* Experience with CSPM tools (e.g., Wiz, Orca Security, Prisma Cloud).
* Familiarity with SIEM tools (Splunk, Sentinel) and investigation capabilities.
* Experience securing Microsoft 365 services and Google Workspace
* Understanding of regulations and standards (GDPR, ISO 27001). Personal Skills Hands-on approach. Strong interpersonal communication skills and teamwork capabilities. High-level English proficiency.

This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8235613
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/10/2025
חברה חסויה
Location: Herzliya
Job Type: More than one
We are looking for a Cloud Security Researcher.
Responsibilities:
Research for new security issues/vulnerabilities in Cloud Environments & SaaS Applications
Write proof-of-concept, threat detections, and analytical algorithms
Analyze logs and behavior of user activities on Cloud Environments & SaaS Applications
Hunt threat actors & insider threats
Collaboration with R&D groups within the company to implement your latest research
Evaluate and recommend steps to harden customer's Cloud Environments & SaaS Applications
Optimizing existing algorithms to reduce false positives and increase the value of our products
Writing cyber security oriented blogs and publications
Follow and Evaluate new security threats, attack vectors, and technologies
Requirements:
Cybersecurity professional with a minimum of 5 years experience as on-prem/cloud security researcher
Knowledge and experience researching IaaS platforms like AWS, Azure or GCP (advantage)
Experience with identifying and analyzing trends or patterns related to security incidents and abnormal behaviors
In-depth understanding of an organizations security, risks, and potential attack vectors in all the organizations perimeters
Understanding security issues, attack vectors, and related security trends
Strong knowledge of SQL language
2 years of Hands-on experience in programming and scripting (/Python)
Passion for conducting Value-to-customers-driven research
Must possess strong verbal & written communication skills in English
Problem-solving skills in an effective and creative way while maintaining a prominent level of flexibility
Experience with data analysis of large data sets
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8383984
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
7 ימים
חברה חסויה
Location: Herzliya
Job Type: Full Time and Hybrid work
We are in search of a skilled and motivated Security Researcher to join our team.
As a Security Researcher, your primary focus will be on creating and researching anomaly and behavioral based threat models, dissecting attack techniques, and leading proactive threat-hunting endeavors across a spectrum of domains, including cloud infrastructures (with a specialized emphasis on Office 365 and Azure), network security, proxies, firewalls, DNS, Active Directory, Azure Active Directory, and SharePoint, and product security.
Your role will require a profound comprehension of security concepts and a forward-thinking approach to identifying and writing detections for potential risks.
Requirements:
Technical proficiencies:
Profound knowledge with 365 apps, Active Directory, Kerberos, AAD, Firewalls, Proxies, SharePoint, DNS.
Strong understanding of an attack life-cycle, and up-to date attack techniques and vectors.
Strong background in Python (working with dataframes - pyspark /Pandas is an advantage) and PowerShell.
Query language background (for example, Kusto Query Language/SQL).
Experience as an Incident Responder, Threat Hunter, Red Teaming, Security Research.
Experience in investigating complex customer incidents (and be ready to talk about it).
Previously published reports or conference talks is an advantage.
Skills:
Strong communications skills
Can do approach
Great team player
Being able to collab with different teams and multitask
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8385468
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
7 ימים
Location: Herzliya
Job Type: Full Time and Hybrid work
we are seeking an experienced and innovative Senior Product Manager to spearhead the development of cutting-edge security solutions. This role offers a unique opportunity to shape the future of data protection and cybersecurity in the AI Area.
Role Overview :
You will own the product lifecycle for one of the most strategic areas in our portfolio. This role sits at the intersection of data security, threat intelligence, and AI, shaping how organizations defend against advanced email threats such as phishing, BEC, credential harvesting, and malware.
Whether you come from a product management background or have hands-on experience as a security analyst, SOC expert, or security researcher, your insights will help us build differentiated solutions that protect our customers most sensitive communications.
Responsibilities :
Define and execute the product vision, strategy, and roadmap for Email Security.
Collaborate with engineering, data science, threat research, and marketing to deliver innovative security products.
Analyze customer pain points, threat intelligence, and market trends to identify opportunities for innovation.
Drive end-to-end product development, ensuring timely delivery and high-quality results.
Partner with customers, analysts, and internal stakeholders to validate solutions and uncover unmet needs.
Clearly communicate product vision, progress, and results to executives, clients, and internal teams.
Requirements:
4+ years of experience in product management, security analysis, or security research.
Proven ability to lead cross-functional initiatives and influence without authority.
Strong communication and collaboration skills across technical and non-technical teams.
Passion for solving complex security challenges and delivering impactful, user-centric solutions.
Advantage: Deep expertise in email security, including phishing, BEC, credential harvesting, malware distribution, and spam protection.
Advantage: Experience with AI-driven security, Microsoft 365, and/or integration of third-party security platforms.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8385459
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Herzliya
Job Type: Full Time
We are looking for an embedded security researcher to join us in researching and developing cutting-edge cyber security projects.
Responsibilities
As an Embedded security researcher, you will be dealing with:
Embedded systems Reverse engineering.
Real-time Embedded End-to-End Low Level software developments on various unique embedded platforms and environments.
Requirements:
Deep understanding of embedded systems internals and operating systems.
5+ years of experience in real-time embedded systems development, writing code in C/C++ and Assembly.
Experience with embedded systems communication protocols, peripherals and debugging.
Experience in reverse-engineering using dis-assemblers (IDA Pro or GHIDRA).
Good knowledge of network communication protocols and topologies.
Experience in Python scripting.
Highly motivated and very creative individual.
Experience in vulnerability research - advantage.
Graduate of an elite technological unit in the IDF - advantage.
Bachelor's degree in computer science or engineering - advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8369428
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/10/2025
Location: Herzliya
Job Type: Full Time and Hybrid work
We are looking for a Cloud Security Research Team Leader.
We work in a flexible, hybrid model, so you can choose the home-office balance that works best for you.
Responsibilities:
Team Leadership
Lead and mentor a team of top notch cloud security researchers.
Foster a culture of innovation, collaboration, and excellence within the team.
Provide technical guidance and support to team members.
Requirements:
Cybersecurity professional with 5+ years experience as on-prem/cloud security researcher
Proven experience in leading technical teams and driving research projects with 2+ years management experience.
Knowledge and experience researching IaaS platforms like AWS, Azure or GCP (advantage)
Knowledge and experience researching SaaS and IDP platforms (advantage)
Experience with identifying and analyzing trends or patterns related to security incidents and abnormal behaviors
In-depth understanding of an organizations security, risks, and potential attack vectors in all the organizations perimeters
Understanding security issues, attack vectors, and related security trends
Strong knowledge of SQL language
3+ years of Hands-on experience in programming and scripting (C++/Python)
Passion for conducting Value-to-customers-driven research
Must possess strong verbal & written communication skills in English
Problem-solving skills in an effective and creative way while maintaining a prominent level of flexibility
Experience with data analysis of large data sets
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8383978
סגור
שירות זה פתוח ללקוחות VIP בלבד