דרושים » אבטחת מידע וסייבר » WAF Security Specialist

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
3 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
our company's WAF Copilot takes a freshly disclosed CVE and produces a validated, provider-specific WAF rule - researching the vulnerability, deriving the attack surface, composing the rule, then attacking its own output with an independent bypass judge and a false-positive prober before a human is offered a deploy.
As WAF Security Specialist you are the ground truth the Copilot is measured against - the person who can look at a generated rule and say this blocks the PoC but not the four obvious variants, this will trip on legitimate multipart uploads, this is 340 WCUs of nothing because the managed ruleset already catches it, this can't be anchored tightly enough to live in a global Web ACL.
You'll be shipping rules for real customers - and you'll do it through our AI harness, and help optimize it.
In practice that means driving the harness on live work: feeding it a vulnerability, judging what comes back, tightening the match, and validating it against real exploit traffic until it's something you'd put your name on.
Sometimes you'll write the expression yourself - the CVE with no public PoC, the emerging threat you have to reason out of a patch diff, the customer who needs coverage this afternoon. Most of the time you'll be applying expert judgment at every step of a generated rule's life, which is a different and harder skill than authoring from a blank page.
Because you'll be the harness's heaviest user, you'll also be the reason it gets better. You'll see exactly where it breaks down - the research step that missed the real sink, the composer that over-broadened, the judge that passed a rule it shouldn't have - and turn that into validations, analyses, and evals that go back into the agent. You'll work side by side with the Copilot & AI team so the agent stops making the mistake, instead of you catching it again next month. That feedback loop is the core of this role.
All of it rests on knowing where WAFs actually break: normalization and encoding evasion, parameter pollution, body-inspection size limits, oversize-content handling, rule precedence, and the gap between "the rule matched in staging" and "the rule holds against a motivated attacker." An AI can propose a rule. Knowing whether to trust it is the job.
What You'll Do
Create - Produce production WAF rules across providers for high-impact CVEs and customer findings - driving the Copilot harness on most of them, writing the expression yourself on the hard ones (no public PoC, exploitable path reasoned out of a patch diff, urgent customer coverage). Your rules ship, and they set the bar generated rules are measured against.
**Optimize -**Tighten generated rules for real production constraints: WCU and rule-capacity budgets, latency, provider expression limits, and the anchoring required for a rule that fires against all traffic behind a shared Web ACL - not just the vulnerable app.
Validate - Own the adversarial pass. Build exploit variants the PoC doesn't cover, hunt bypasses in our own rules, and run the false-positive side seriously - verifying against how the legitimate client actually behaves on the wire, not against an assumption.
Requirements:
Deep, hands-on WAF expertise across multiple major providers - you've written, tuned, and operated real rules in production on several of: AWS WAFv2, Cloudflare, F5, Imperva, Akamai, Azure, GCP, Fortinet, ModSecurity/CRS. Not "managed a WAF vendor relationship" - written the rules.
You know the caveats cold. Body-inspection limits and oversize handling, text transformations and normalization order, encoding and unicode evasion, parameter pollution, chunked and multipart edge cases, rule precedence and evaluation order, WCU/capacity economics, and how each provider's expression language quietly differs from the others.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8847733
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
29/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Senior Vulnerability Researcher.
You'll have the room to follow the research where it leads, and the backing of an ecosystem created to set you up for success by providing every tool and access that could help.
Some threads will feed directly into how understands what's genuinely exploitable, grounding the platform in real attacker reality rather than theoretical risk. Others will be pure discovery, pursued because the problem is hard and the finding truly matters, and published to move the field forward.
Either way, your work establishes authority in the field. Through original research, disclosures, and technical thought leadership, you'll build a body of work that earns the respect of the security community and sharpens how the industry thinks about what's truly secure.
What you will Do:
Hunt for what established security paradigms miss: flawed assumptions, gaps between specified and actual behavior, and novel vulnerability classes and exploitation techniques that don't yet have names.
Reverse-engineer and deeply understand systems, protocols, and architectures at the implementation level - developing a precise understanding of how they actually work, rather than what their designers intended.
Develop hypotheses and convert them into working proof-of-concept exploits that demonstrate real-world risk before attackers do.
Own research threads end-to-end, from an early exploration, developing and following hunches all the way through to a proof of concept, responsible disclosure or publication, following the evidence wherever it leads without waiting for a defined playbook.
Ground understanding of exploitability in attacker reality - when research surfaces findings relevant to how the platform models identity attack surface across human and non-human identities, bring that signal in.
Promote standing in the security community through original research, CVEs, and technical thought leadership that advances the field and earns trust on its merits.
Requirements:
6+ years of hands-on vulnerability research, reverse engineering, or offensive security, with a proven track record of finding non-trivial flaws and the depth in systems, protocols, and architectures to understand precisely why they exist.
A first-principles approach to how things actually work, not how they're documented to work: you pull the thread until you hit ground truth, and you're not satisfied until you do.
The instinct and ability to see what others overlook - the unquestioned assumptions in established systems, the edges no one has tested, the failure modes that live in the gap between spec and implementation.
End-to-end ownership of research: you drive hypotheses to conclusions through dead ends, changes of directions and reach hard proofs
Strong hands-on expertise, converting theories and research into a working chain and proof of concept.
Result driven depth: you go as far as a problem deserves, because the result is worth it, and you know when it is.
A track record of original significant discoveries - published CVEs, novel vulnerability classes or exploitation techniques, research that named a problem the field didn't have words for yet.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8837070
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
29/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Senior Product Security Researcher.
As a Security Researcher, you'll own and evolve the core of the Oak platform: the frameworks and logics that turn fragmented, cross-surface identity data into precise, high-signal insight. You'll work directly with real-world data to find emerging attack patterns, reason about privilege and exposure, and convert what you learn into intelligence that tells customers what's actually risky - and what to do about it.
Identity is also the fastest-moving attack surface in the enterprise right now. The explosion of non-human identities and autonomous AI agents is rewriting what "who has access to what" even means, and you'll be at the front of it - defining how discovers, scores, governs and secures these identities before the rest of the market has a vocabulary for the risk.
You'll also shape voice in the field. Through original research, published findings, and technical thought leadership, you'll influence how practitioners and analysts understand identity risk as the perimeter dissolves.
What you will Do:
Drive research end-to-end - from hypothesis and exploration all the way through to the intelligence and logic that ship into the platform and makes impact on our customers.
Translate deep expertise in identity and security into the analytical engine that drives how reasons about risk, governance, and access decisions across organizations.
Create and own knowledge - the content, logic and intelligence behind every insight made, while setting and maintaining the quality, accuracy depth and coverage of the platform.
Pioneer approach at the cutting edge of a category being reinvented - as the identity foundations are rebuilt for a new world
Shape the field's understanding of identity through original research and technical thought leadership, while raising the research bar across the team and delivering top-tier value to our customers.
Requirements:
5+ years of hands-on security research experience, with a track record that demonstrates depth across identity, access control, or adjacent threat domains.
Low ego, high impact - you share findings freely, measure success by the team's impact and you are value-driven, Willing to roll up your sleeves for the foundational work creating knowledge and insights in order to provide real value to real customers.
Innovative and forward thinking - Continuous desire to learn, explore and create.
The instinct to find what others miss: you approach identity attack surfaces, NHI exposure, and AI agent behavior with genuine curiosity and a willingness to go where the research leads.
A collaborative default - happy to share and work alongside product, engineering, and go-to-market teams in order to translate raw research into intelligence that sharpens Oak's platform and customers' understanding of their identity risk.
Nice to have:
A history of original, published work - conference presentations (Black Hat, DEFCON, or equivalent), blog series, or white papers that has moved the needle and made impact.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8837082
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As our VP Security & Research, you'll report directly to the CEO and own malvertising detection vision, combining deep security research with AI and agentic innovation. You'll lead our security research team, uncover new attack techniques before they reach users, and turn that insight into detection that works in real time at massive scale. You'll build a research agenda that puts GeoEdge on the stage at the world's top security conferences, and partner with Product, R&D, data Science, Customer Support, and other key functions inside and outside the company to bring it to market. You'll be the security and research voice of GeoEdge for customers, partners, and the wider security community. What You'll Do
* Set the strategy and roadmap for malvertising detection and security research
* Lead, mentor, and grow the security research team
* Drive AI and agentic innovation in detection, working with R&D and data Science to turn research into production-grade capabilities
* Uncover and track emerging malvertising threats, evasion techniques, and attacker campaigns across the ad ecosystem
* Own detection quality: push for uncompromising precision, coverage, and speed
* Drive original research and publications, and represent GeoEdge at leading security conferences
* Partner with Product, R&D, data Science, Customer Support, and other key functions in the organization and outside of it
* Report to the CEO and management on research impact, threat landscape, and priorities
Requirements:
What You Bring
* 8+ years in security, including 3+ in leadership
* A proven research track record: publications, CVEs, conference talks, or technical papers
* Hands-on expertise in AI and agentic systems, with experience applying LLMs, Machine Learning, and AI agents to real security problems
* Deep understanding of how attackers evade detection, including cloaking, obfuscation, and adversarial use of AI
* Strong background in web security and web technologies ( JavaScript, browsers, HTTP/HTTPS)
* Experience in threat research, malware analysis, or detection engineering
* Ability to translate complex research into business impact for executives and customers
* Excellent English; BSc in Computer Science or equivalent experience Advantages
* Experience building or shipping AI-powered or agentic security products
* Experience in AdTech, digital advertising, or malvertising research
* Background in a cybersecurity product company
* Experience building or leading a security research team
* Alumni of technological or military intelligence units
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8849511
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
6 ימים
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a security programmer to help us build the next generation AI container network security system.
This role sits at the intersection of systems programming, network security, and cloud-native infrastructure.
What You'll Do
Help design and implement traffic inspection and prevention components that run in-line within Kubernetes clusters (as a DaemonSet, sidecar, or CNI-integrated component)
Build or contribute to protocol parsers and signature/rule-matching engines
Contribute to an AI-assisted signature generation pipeline
Work with the Linux networking stack to intercept and act on traffic with acceptable latency overhead
Help ensure the data path is efficient enough to run under the resource budgets typical of Kubernetes workloads
Collaborate with detection research and cloud security teams to translate threat intelligence into enforceable rules and behaviors.
Requirements:
Professional experience in Rust or C/C++ (comfort with both, or willingness to pick up the second, is a plus - not a hard requirement)
Security background - experience with developing security products - such as IPS, firewall, researcher, API security, etc
General familiarity with Kubernetes and at least one public cloud (AWS, Azure, or GCP) - production experience is preferred, but strong infrastructure/networking experience elsewhere is also welcome
Comfort working on systems/infrastructure-level software rather than purely application-level code
Hands on AI SDLC experience
Curious
Tech savvy
Good communication skills
Independent
Advantage
Experience with DPI engines, protocol parsers, or signature-matching systems (e.g., Snort/Suricata-style rules)
Exposure to ML/AI approaches for anomaly detection, classification, or rule generation
Linux kernel/networking internals: netfilter/nftables, eBPF/XDP, TCP/IP, TLS
Kubernetes networking specifics: CNI, NetworkPolicy, service mesh data planes (Envoy/Istio)
Container runtime/isolation experience: containerd/CRI-O, namespaces/cgroups
Low-latency/high-throughput systems experience (zero-copy design, lock-free structures)
Familiarity with attacker techniques and IPS/IDS evasion
Comfort with ambiguous, greenfield technical work.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8841826
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time and Hybrid work
We are looking for a Senior Fraud Analyst to serve as the technical cornerstone of our Fraud Prevention team.
In this role, you won't be managing a team; youll be managing the technical evolution of our fraud defenses. Reporting directly to the Fraud Prevention Director, you will act as a high-level individual contributor, bridging the gap between data science, engineering, and risk strategy. You will be responsible for pioneering the use of AI and advanced analytics to protect our community and ensure our platform remains the safest place for independent businesses to grow.
Here are a few of the things you'll do:
Technical Strategy & Architecture: Partner with the Fraud Prevention Director to define the long-term technical roadmap, moving toward an AI-first, autonomous fraud detection ecosystem.
AI & LLM Integration: Design and implement Generative AI agents and LLM-powered workflows to automate complex forensic investigations, reducing the time-to-detect for emerging fraud vectors.
Advanced Detection Modeling: Develop and prototype sophisticated ML models and graph-based heuristics to identify collusion, synthetic identities, and fraud rings.
Cross-Functional Technical Lead: Serve as the primary technical consultant to Product and Engineering, ensuring that new payment features (like RTP or international expansion) are built with scalable, AI-driven safeguards from day one.
Expert Forensics: Act as an escalation point on high-stakes, large-scale fraud attacks, utilizing advanced Python and network analytics to deconstruct and mitigate threats.
Data Excellence: Set the standard for the fraud teams technical stack. You will optimize our SQL/Python environments and ensure our data infrastructure is capable of supporting real-time AI inference.
Requirements:
5+ years of experience in fintech or payments fraud analytics. You are a seasoned IC who has scaled fraud programs in complex, high-volume environments.
AI/ML Expertise: Proven experience leveraging Generative AI, LLMs (e.g., RAG, agentic workflows), and Machine Learning to solve real-world risk problems. You don't just use these tools; you know how to build with them.
Technical Powerhouse: Mastery of Python (for data science and automation) and SQL (performance tuning, CTEs, window functions). You are comfortable working alongside engineers and data scientists.
Network Analysis: Deep experience with graph databases (Neo4j, TigerGraph) and link-analysis techniques to identify organized criminal networks.
Demonstrated ability to translate complex quantitative findings into executive‑level insights and influence roadmaps across product, engineering, finance, and support.
Strategic Influence: While this is not a management role, you have a track record of influencing technical roadmaps and advising senior leadership on risk-reward trade-offs.
Advanced data‑visualization skills (Looker, Tableau, Omni, Superset, or equivalent) with a portfolio of self‑service dashboards adopted by the company‑wide.
Domain Depth: Expert knowledge of the payments lifecycle, including CNP, ACH, and RTP risk, as well as the specific fraud challenges of the SaaS and marketplace sectors.
Regulatory Fluency: A solid understanding of PCI DSS, Nacha rules, and the emerging regulatory landscape surrounding AI in financial services
Prior experience scaling fraud programs in a marketplace, SaaS, or creator‑economy context - Advantage.
Education: Bachelors or Masters degree in a quantitative field (e.g., CS, Statistics, Mathematics, Economics) or equivalent technical experience- Advantage..
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8840712
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
3 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a Pentest Product Associate to join our Product team and help expand the power of our company. In this pivotal role, you will be the primary operator of our cutting-edge AI-driven Dynamic Application Security Testing (DAST) agent while simultaneously innovating detection mechanisms for cloud-native technologies. You will bridge the gap between automated AI testing and cloud infrastructure, defining the "rules of engagement" for our agents to ensure they effectively simulate sophisticated attacks and accurately classify the modern attack surface.
Responsibilities
Develop advanced detection algorithms to classify cloud technologies while fine-tuning the attack policies that define how our agents identify and exploit vulnerabilities.
Analyze cloud services, APIs, and log payloads to review complex attack paths, reducing false positives and ensuring compliance with industry standards.
Stay at the forefront of novel attack vectors and emerging cloud/API threats, translating new techniques into executable behaviors for the company DAST engine.
Collaborate directly with Research, Backend, and R&D teams to turn operational insights into feature requests, positioning our company as the market leader in vulnerability management.
Requirements:
2 years of hands-on experience in AppSec or penetration testing, including proficiency with enterprise tools like Burp Suite, OWASP ZAP, or Acunetix.
Hands-on experience with Linux, Windows, Docker, Kubernetes, web protocols (HTTP/S, REST, GraphQL), and authentication mechanisms (OAuth, SAML).
Proficiency in scripting languages such as Python, Bash, or Go to automate security tasks and interact with codebases.
Solid knowledge of networking concepts, the OSI model, and cloud infrastructure (AWS, Azure, or GCP).
Preferred Qualifications
Knowledge of AI/ML and how LLMs or reinforcement learning agents operate within a cybersecurity context.
SaaS and cloud experience, with familiarity in AWS, Azure, or GCP environments and modern cloud-native architectures.
A red teaming background, with experience in simulated adversarial attacks and bypassing standard WAF or security controls.
An analytical mindset with the ability to diagnose complex logs and scans to distinguish between tool failures, configuration issues, and valid security findings.
Self-motivated with the ability to work collaboratively and communicate high-stakes security concepts effectively across teams.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8847769
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Cloud - and lead a small, growing team of analysts and engineers.

This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy.

What youll do
Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.

Architect and operate detection coverage across our cloud and bare-metal environments

Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks.

Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure

Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents.

Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.

Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.

Build and maintain Security Incident Response program: people, processes, tools.

Build tools, runbooks, and on-call processes that scale as the company grows.
Requirements:
6+ years in security operations, detection engineering, or incident response - with at least 1-2 years leading or mentoring a team.

Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).

Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.

Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).

Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.

Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.

Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase. Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818174
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Lead Detection Engineer.This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline.

Youre welcome to work in our offices in Tel Aviv, Israel

Your responsibilities will include:

Detection coverage strategy across endpoint, identity, cloud, and infrastructure - how it's measured, prioritized, and continuously improved.
Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic.
Architecture connecting detections to enrichment, triage, and automated response workflows.
Technical standards for how detections are designed, tested, documented, deployed, and retired.
Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops.
Design and build high-fidelity behavioral detections across SIEM and EDR platforms.
Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.
Validate detections through threat simulations and continuous detection testing.
Partner with SOC analysts to close the feedback loop between detections and real investigations.
Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership.
Make architectural decisions that scale as the team and organization grow.
Requirements:
Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role - with demonstrated depth, not just breadth.
Experience owning or leading detection engineering work as a senior technical contributor
Strong understanding of attacker tradecraft and adversary behavior.
Hands-on experience with at least one enterprise SIEM and EDR platform - Splunk, Microsoft Sentinel, CrowdStrike, or equivalent.
Cloud security depth across Azure, AWS, or GCP.
Strong query development skills in SPL, KQL, Sigma, or similar.
Strong scripting skills (python, powershell etc)
Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows.
Experience using MITRE ATT&CK to design, validate, and measure detection coverage  
Ability to make and defend technical decisions and establish standards others adopt.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818112
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
6 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Malware Group Manager to lead our endpoint protection and file security teams.
Someone with a passion for stopping malware where it lands, whether it comes through an email, or from the web, and for building the protections that keep our customers safe. Someone who wants to shape research and detection strategy across multiple teams, understand how attackers operate, and stay ahead of fast-moving threats, including zero-day attacks.
Our teams work across a rich stack: endpoint protection engines, file analysis and sandboxing, reverse engineering, and big data pipelines that turn raw telemetry into actionable threat intelligence and protections.
In this position you will lead several teams, set the technical and research, and make sure we deliver detection that works at scale.
Key Responsibilities
Lead and grow multiple teams and across endpoint protection and file security, and own the group's roadmap
Drive the group's AI transformation - bring GenAI and machine learning into how we research threats, build detection, and speed up our work
Set research and detection strategy, and align it with product and business goals
Drive endpoint and file protection capabilities that stop known and zero-day threats
Build a strong engineering and research culture and develop the next generation of leaders on your teams, and tooling to support them.
Requirements:
Desired Background
A seasoned group manager with 3+ years of experience in Cyber Security, including leading teams and/or team leaders.
A strong background in malware research, endpoint protection, or file security
Experienced change leader with demonstrated AI transformation leadership
Proven ability to set technical direction and deliver across multiple teams
A problem solver, capable of finding creative solutions and getting things done
Fluent in English
It would be great if you also have:
Hands-on background in reverse engineering, detection research, or threat intelligence
Experience applying AI or machine learning to security problems
Published material, Public speaking or conference presentations.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8841802
סגור
שירות זה פתוח ללקוחות VIP בלבד