דרושים » אבטחת מידע וסייבר » Senior Threat Hunting Researcher (Unit 42)

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
22/06/2026
משרה זו סומנה ע"י המעסיק כלא אקטואלית יותר
מיקום המשרה: תל אביב יפו
סוג משרה: משרה מלאה
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a Security Researcher to join our team at the intersection of security research, AI, and product. This isn't a traditional research role - you'll be deeply embedded in how the platform is built, working side by side with R&D, Product, and AI teams to make sure security expertise is baked into every layer of what we ship. You'll own detection and analytics research across cloud, identity, endpoint, and beyond, while actively shaping how AI capabilities are applied to solve real security problems at scale.





WHAT YOU WILL DO

Research and develop sophisticated detections and behavioral analytics across multiple security landscapes - cloud, identity, endpoint, network, and application - with a focus on coverage that scales across customer environments.
Work closely with R&D, Product, and AI teams as the security authority - reviewing features, shaping designs, and ensuring security logic is sound, practical, and impactful.
Apply an AI-native approach to detection and analytics challenges - leveraging LLMs, ML signals, and AI-assisted workflows to do things that rule-based approaches can't.
Identify gaps in detection coverage and analytical capabilities, and drive those findings directly into the product roadmap.
Analyze real-world attacker techniques and translate them into detection logic, hunting content, and analytical frameworks that ship as part of the platform.
Evaluate detection quality rigorously - measuring fidelity, coverage, and performance against real attacker behavior and production telemetry.
Stay sharp on the evolving threat landscape and rapidly incorporate new techniques, campaigns, and attacker tooling into our detection library.
Contribute to external research output - blog posts, talks, open-source tooling - that reflects our depth and point of view in the security community.
Requirements:
6+ years of hands-on experience in detection engineering, security research or incident response - working with real production data at scale.
Deep knowledge of attacker techniques and behavior across at least 2 from: cloud, identity, endpoint, and network environments, with the ability to translate that directly into high-fidelity detection logic.
An AI-native mindset - you've built or applied AI-powered tooling in a security context (detection pipelines, alert investigation, hunting workflows) and you default to AI-powered approaches before reaching for manual ones.
Experience working within or alongside a product or engineering team - you understand how software gets built, and you know how to make your security expertise actionable for R&D and Product.
Strong coding skills (Python or similar), used for research, data analysis, detection development, and tooling.
A product-oriented approach to research - you think about scale, usability, and customer impact, not just technical correctness.
Self-directed and a strong self-learner - you don't wait to be pointed at problems, and you move fast when you find them.
Strong written and verbal communication skills in English, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8762138
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a SecOps Lead , you will own the core of the security operations function: detection, response, automation, and the processes that connect them. You will guide incident response from first alert through post-mortem, keeping efforts structured and stakeholders informed along the way. You will shape how the team detects, triages, and resolves, and communicate that work clearly to leadership, engineering, and customers.

This is a hands-on role with broad ownership. You should be comfortable writing a detection rule, coordinating a live incident, and walking stakeholders through a post-incident review.

Key Responsibilities

Lead Incident Response: Own the end-to-end incident response lifecycle across infrastructure and enterprise browser platform, driving investigations, coordinating responders, and ensuring timely resolution and post-incident improvements.
Own the IR Framework: Build, maintain, and continuously improve incident response processes, including runbooks, severity definitions, escalation paths, on-call procedures, and communication standards.
Drive Detection Engineering: Design, implement, and continuously improve high-fidelity detections across SIEM, EDR, cloud, and endpoint security platforms, closing visibility gaps and strengthening detection coverage.
Automate Security Operations: Build automation and AI-driven workflows that streamline triage, investigation, enrichment, and response, reducing manual effort and improving operational efficiency.
Threat Hunting & Research: Proactively hunt for threats, leverage threat intelligence, and identify emerging attack techniques relevant to modern enterprise environments.
Own Security Operations: Serve as the technical owner for Security Operations within Product Security, driving strategy, setting best practices, and continuously improving detection and response capabilities.
Partner Across Engineering: Collaborate closely with Engineering, IT, Infrastructure, and Compliance teams to embed security into new services, infrastructure changes, FedRAMP initiatives, and customer-facing security requirements.
Communicate During Incidents: Provide clear, timely communication throughout incident response, keeping technical teams, leadership, and stakeholders aligned on impact, progress, risks, and next steps.
Requirements:
5+ years of hands-on experience in Security Operations, Incident Response, or Detection Engineering.
Proven experience leading end-to-end incident response for high-severity security incidents in cloud or enterprise environments.
Strong understanding of detection engineering, threat hunting, and modern security operations, with hands-on experience using SIEM, EDR, and cloud security platforms.
Experience building and improving incident response processes, including runbooks, severity frameworks, escalation paths, and post-incident reviews.
Hands-on experience automating security operations using SOAR platforms and AI-powered workflows (Torq, Tines, or similar).
Solid understanding of AWS security fundamentals, including IAM, CloudTrail, and containerized environments (EKS is an advantage).
Strong knowledge of modern attack techniques, threat intelligence, detection methodologies, and investigation best practices.
Excellent written and verbal communication skills, with the ability to communicate effectively during incidents and present findings to both technical and non-technical stakeholders.
Experience collaborating across Engineering, Infrastructure, IT, and Compliance teams to improve security posture.
Experience mentoring engineers or leading cross-functional security initiatives is an advantage.
Familiarity with SOC2, FedRAMP, or other regulated compliance frameworks is a plus.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769437
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a Threat Hunting Expert to join our team and shape the future of threat detection. In this role, you'll be at the forefront of identifying and analyzing emerging threats, helping to shape the features of our Threat Detection platform. You'll be crafting detection logic and hunting strategies that enable security teams to identify and respond to advanced threats across their entire environment.


WHAT YOU WILL DO

Work directly with customers to help them solve concrete security pain points and operational use cases using , primarily during POVs and onboarding.
Perform advanced threat hunting across customer datasets to identify meaningful security findings, including compromise evidence, exploitation indications, suspicious activities, and visibility or posture gaps.
Build and evolve internal tools and AI-powered capabilities that support threat hunting, anomaly detection, and exploratory analysis.
Translate immediate customer security needs into ad-hoc security content, including detections, threat hunting notebooks, and investigative workflows.
Participate in customer-facing sessions alongside Sales Engineers and Technical Account Managers to present findings, explain security context, and walk through capabilities and content.
Deliver technical demonstrations, workshops, trainings, and hands-on sessions that show customers how to use for their security workflows.
Research emerging threats, including new CVEs and active campaigns, in collaboration with the CTI team, and translate them into immediate detections and threat hunting content.
Publish public-facing technical content on threat hunting and SecOps, including blog posts, webinars, open-source tools, and research findings.
Requirements:
At least 6 years of hands-on experience in security operations, threat hunting, incident response, or detection engineering, working with real production data.
Strong hands-on experience investigating security events, performing advanced threat hunting, and identifying meaningful findings.
Deep familiarity with common attack techniques, attacker behavior, and modern threat landscapes across endpoint, identity, network, cloud, and application environments.
Comprehensive knowledge of security controls and security architectures across cloud, network, identity, application, and endpoint environments.
Experience working with large-scale security datasets and performing exploratory analysis, anomaly detection, and investigative research.
Ability to write efficient, readable code and scripts for analysis, automation, and internal tooling used by the team.
Comfort working directly with customers in technical discussions, explaining findings, tradeoffs, and investigative approaches clearly and practically.
Experience collaborating with product, engineering, or research teams to influence tooling, workflows, and platform capabilities.
Strong written communication skills, with the ability to produce clear technical documentation and public-facing content when needed.
Excellent English communication skills, both written and verbal.
Curiosity and initiative to research emerging threats, new techniques, and evolving attacker behavior, and apply that research in practice.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8762126
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
21/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
our mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our company values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day. our mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our company values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
Conduct investigations of advanced threat actor activity across cloud, identity, endpoint, and on-premises environments to identify intrusion methods, attacker objectives, and operational patterns.
Identify and track emerging threats, attacker techniques, campaigns, and trends to enable proactive detection, disruption, and defence before customer impact.
Develop detections, mitigations, and security guidance by identifying attack paths, security weaknesses, and opportunities to strengthen defensive coverage.
Build investigative tooling, automations, proof-of-concepts, and research capabilities that improve the scale and effectiveness of security investigations.
Drive product, detection, and engineering improvements by translating investigation findings into actionable changes across our company security platforms and services.
Providing recommendations to improve customers cybersecurity posture going forward and performing threat intelligence knowledge transfer to prepare customers to defend against todays threat landscape
Synthesize complex technical research into clear, actionable intelligence, reports, briefings, and recommendations for technical and executive audiences.
Advance understanding of nation-state, cybercriminal, and emerging threat actors through research, attribution, capability assessments, and adversary tracking.
Share findings, influence strategy, and drive organizational change through knowledge transfer, best practices, and adoption of security improvements.
Requirements:
4+ years of experience in Threat Hunting, Incident Response (DFIR), Threat Intelligence, or Security Research.
Experience investigating sophisticated cyber threats, including APT or nation-state activity.
Experience working with security telemetry, logs, and SIEM platforms.
Familiarity with KQL or equivalent query languages (Splunk, Humio, Kibana, etc.).
Experience with EDR and security monitoring technologies such as our company Defender, Sentinel, CrowdStrike, or similar platforms.
Ability to analyze security data, investigate attacker behavior, and identify indicators of compromise (IOCs), indicators of activity (IOAs), and TTPs.
Understanding of scripting or the ability to read and interpret code and automation workflows.
Strong communication skills in English and ability to work in a global team environment.
Preffered Qualifications
Industry certifications in cybersecurity, DFIR, incident response, or threat hunting (e.g., CISSP, GIAC).
Experience identifying novel attacker techniques and translating findings into scalable detections.
Experience performing malware analysis or reverse engineering.
Experience analyzing large-scale security telemetry and hunting across enterprise environments.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8748025
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Hunt, investigate, and analyze advanced persistent threat (APT) activity across endpoints, servers, cloud, and network infrastructure. partner with our Threat Intelligence team to resolve complex intrusions in customer networks. You'll uncover stealthy adversary behavior, reconstruct attack chains, and build the tools and methods that make our hunting and forensics better. You'll also present original research at top-tier industry conferences and
Key Responsibilities
Hunt and investigate targeted intrusions, long-dwell compromises, and espionage- driven activity across enterprise, cloud, identity, and network environments.
Perform advanced forensics across operating systems, cloud, memory, and network telemetry; correlate signals to determine the scope of compromise.
Build innovative tooling, research systems, and hunting/investigation workflows; identify capability gaps and propose automations to close them.
Produce clear reports, forensic timelines, threat-actor assessments, and actionable detection and remediation guidance.
Support internal security, threat intelligence, detection engineering, and investigation teams with expert forensic findings and technical analysis.
Partner with the Threat Intelligence team to resolve complex intrusions in customer networks.
Represent the organization through conference talks, workshops, and original research.
Requirements:
Extensive hands-on APT hunting, intrusion investigation, and digital forensics.
Deep understanding of APT tradecraft - stealth, persistence, credential abuse, defense evasion, living-off-the-land, custom tooling, supply-chain compromise, and command-and-control.
Broad forensic expertise across operating systems, cloud platforms, network and edge infrastructure, and memory, using industry-standard forensic and hunting tools.
Telemetry analysis across security platforms (EDR, SIEM, network, and identity systems) and the ability to build detection and hunting logic.
Strong development skills in Python (and ideally another language such as Go, C/C++, or PowerShell) to build tooling, automations, and analysis pipelines.
Strong communication for technical and executive audiences, including conference-grade presentations.
Represents the organization publicly, delivering talks, workshops, and research at top-tier cybersecurity and forensics conferences.
Nice to Have
Malware analysis and reverse engineering.
Experience with enterprise EDR/XDR and SIEM platforms.
Container, SaaS, and hybrid-cloud investigation experience.
Threat-intel collaboration; published research or prior conference talks.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785669
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
20/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.
This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.
You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of Aidocs clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
Additional Strengths
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8745764
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
09/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a threat Security Researcher to own the "right" side of the platform - from live cloud workloads and the eBPF telemetry they emit, through adversary behavior in containers and Kubernetes, into the AI systems and agents now embedded in production. You'll hunt down how novel attack techniques actually unfold at runtime - the credential theft, the lateral movement, the abuse of a model or an MCP tool - then turn that research into the detection logic that runs over our vast runtime telemetry and powers real-time threat protection. This role sits at the intersection of threat research, cloud, AI security, and detection engineering.
Conduct deep technical research into modern cloud environments and AI systems and discover novel attack techniques.
Lead product initiatives in the threats domain from inception to production. Collaborate closely with product, backend, and GTM, translating research into product capabilities.
Define and create complex detection logic over our vast telemetry, with a focus on coverage that scales across customer environments.
Identify gaps in detection coverage and evaluate detection quality. ensuring security logic is reliable and impactful.
Stay up to date with the evolving threat landscape (threat intelligence, campaigns) and incorporate into our product
Contribute to PR presence - technical research content, talks, open-source tooling.
Requirements:
5+ years of experience in threat research, including threat hunting, incident response or detection engineering
Military background experience, university degree, or Ex-CNAPP
Curious, detail-oriented mindset with proven ability to self-learn complex topics and new mechanisms.
Hands-on skills with scripting languages (e.g., Python) as well as query languages (e.g., KQL
Ability to work independently and also across teams, in a dynamic, fast-moving, demanding environment
Strong written and verbal communication skills in English, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.
Advantages :
Experience in AI Security Research
An AI-native mindset, you've built or applied AI-powered tooling in a security context
Experience conducting data-driven research and working with large-scale telemetry.
Experience in public-facing work, such as presenting at recognized industry conferences or authoring technical blog posts.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8773788
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a Threat Detection Researcher to join the Threat Research team and spread the power. In this role, you will further develop the Cloud-native Threat Detection domain.
Check out some of our recent research:
Detecting Malicious OAuth Applications
Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild
Discovers Cloud Email Abuse Campaign
Responsibilities
Drive the full lifecycle of security detections - from threat research and data analysis to building and shipping detection logic directly into production.
Design behavioral baselines for complex cloud environments using diverse signals, and develop high-fidelity detections based on those baselines.
Expand our detection engine with novel and high-impact telemetry sources, pushing the boundaries of what can be detected in modern cloud environments.
Conduct deep technical research into complex cloud services to uncover novel attack vectors.
Investigate real-world attacks across cloud environments, identity providers (IDPs), and infrastructure-as-a-service (IaaS) platforms.
Hunt and analyze emerging threats and active campaigns targeting the cloud ecosystem.
Requirements:
Minimum Qualifications
6+ years of hands-on experience in security or threat research, with a proven track record of driving investigations to actionable, real-world impact.
Experience conducting data-driven research and working with large-scale telemetry.
Proficiency in Python, Go, and query languages (e.g., KQL, SQL).
Strong self-motivation and ability to independently drive complex research projects from concept to delivery.
Preferred Qualifications
Familiarity with cloud infrastructure (AWS, GCP, Azure), Kubernetes, and modern cloud-native architectures.
Background in incident response, red teaming, or threat hunting.
Hands-on experience building and shipping security detections as part of a product.
Experience writing technical blogs, publishing security research, or speaking at industry conferences.
Leveraging AI/LLM-driven tools to enhance detection generation and telemetry analysis.
Clear and effective communicator with excellent collaboration skills, comfortable working across teams and disciplines.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798641
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Lead Detection Engineer .This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline.

Youre welcome to work in our offices in Tel Aviv, Israel

Your responsibilities will include:

Detection coverage strategy across endpoint, identity, cloud, and infrastructure - how it's measured, prioritized, and continuously improved.
Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic.
Architecture connecting detections to enrichment, triage, and automated response workflows.
Technical standards for how detections are designed, tested, documented, deployed, and retired.
Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops.
Design and build high-fidelity behavioral detections across SIEM and EDR platforms.
Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.
Validate detections through threat simulations and continuous detection testing.
Partner with SOC analysts to close the feedback loop between detections and real investigations.
Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership.
Make architectural decisions that scale as the team and organization grow.
Requirements:
We expect you to have:

Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role - with demonstrated depth, not just breadth.
Experience owning or leading detection engineering work as a senior technical contributor
Strong understanding of attacker tradecraft and adversary behavior.
Hands-on experience with at least one enterprise SIEM and EDR platform - Splunk, Microsoft Sentinel, CrowdStrike, or equivalent.
Cloud security depth across Azure, AWS, or GCP.
Strong query development skills in SPL, KQL, Sigma, or similar.
Strong scripting skills (python, powershell etc)
Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows.
Experience using MITRE ATT&CK to design, validate, and measure detection coverage  
Ability to make and defend technical decisions and establish standards others adopt.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8761440
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
Join a team redefining cloud security operations across Cloud Detection & Response (CDR) and Cloud Security Posture Management (CSPM). Our team operates at the intersection of security, engineering, and large-scale cloud operations. We build products that help organizations detect threats faster, respond with confidence, continuously reduce risk, and secure modern cloud environments at scale. This is an opportunity to help shape the future of autonomous cloud defense by building technology that turns security signals into meaningful action.
Key Responsibilities
Help build the next generation of the Autonomous Cloud SOC by transforming detections, posture findings, and emerging threats into intelligent investigation and response workflows.
Design and build automated playbooks that investigate security signals, gather evidence, assess blast radius, validate risk, and guide or execute response actions.
Work across cloud control planes, identity systems, Kubernetes environments, network telemetry, and posture data to turn signals into high-confidence outcomes.
Leverage existing detections, continuously improve investigation logic, and ensure response workflows remain effective as cloud environments and attacker techniques evolve.
Requirements:
4+ years in security engineering, cloud operations, incident response, threat hunting, DevSecOps, or related security disciplines.
2+ years of hands-on experience securing or operating environments within Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Infrastructure (GCI/GCP).
Strong experience with Kubernetes, containers, and modern cloud-native architectures.
Deep understanding of cloud networking concepts, including VPC Flow Logs, Transit Gateways, service meshes, and traffic patterns (East-West vs. North-South).
Strong comprehension of identity systems (IAM) and how policies interact with network controls to establish secure boundaries.
Experience with CI/CD pipelines and modern software delivery practices.
Proven experience with incident triage, investigations, containment, remediation, or formal operational response processes.
Experience with posture management, governance controls, or applying security best practices such as CIS Benchmarks and recognized cloud architecture frameworks.
Strong scripting or programming proficiency in languages such as Python, Go, or Bash.
Excellent communication skills, demonstrating the ability to clearly explain complex findings and facilitate alignment across cross-functional teams.
Preferred Qualifications
Experience working with large-scale data pipelines and analytics platforms such as BigQuery or Dataflow.
Familiarity with threat frameworks such as MITRE ATT&CK.
Recognized expertise or advanced certifications in cloud security, detection and response, or posture management across Amazon Web Services, Microsoft Azure, or Google Cloud.
Experience operating highly available, large-scale cloud environments.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8781550
סגור
שירות זה פתוח ללקוחות VIP בלבד