דרושים » אבטחת מידע וסייבר » MDR Security Analyst (Threat Hunting)

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 2 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time
Act as a Customer Security Advisor, conducting threat-hunting activities and performing security assessments on customer networks. Effectively communicate findings, recommendations for remediation, and mitigation strategies to customers
Serve as an escalation point for the SOC analysts, assisting in the investigation, analysis, and response to security incidents
Develop cyber kill-chain indicators of an attack and hunting heuristics to enhance the ongoing threat-hunting process
Enhance the product accuracy and its capacity to detect emerging threats within the dynamic security landscape
Requirements:
Proven hands-on experience in the cybersecurity industry
Excellent customer service skills
Strong knowledge of networking architecture and protocols, including TCP/IP, DNS, SSL, SMB, HTTP, IP Routing, etc.
Comprehensive understanding of the cybersecurity landscape, common threats, and attack scenarios, such as malware infections, command and control (C&C) communication, drive-by attacks, phishing, and network scans
Practical experience with security technologies, including firewalls (FW), intrusion prevention systems/intrusion detection systems (IPS/IDS), antivirus (AV), security information and event management (SIEM) systems, endpoint protection, and network forensics tools
Analytical mindset, capable of formulating hypotheses and validating them through in-depth analysis and technical evidence
Fluent in English with exceptional communication skills
Proficiency in at least one scripting language such as Python or Ruby
Advantageous: Experience with Extended Detection and Response (XDR) solutions
Advantageous: Previous experience working in Managed Security Service Provider (MSSP) or Managed Detection and Response (MDR) providers as a Threat Hunter or Security Analyst
Ability to work effectively as a team player, demonstrating responsibility and strong organizational skills
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8822063
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
5 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a CyOps Analyst, you will be investigating security alerts from the Cynet platform in order to detect threats and conduct live incident response engagements, investigating and analyzing programs and software using analysis programs to identify threats and classify malware based on previous threats and commonalities, investigating and issuing threat intelligence and malware analysis report. The SOC works closely with the Research team to perform tests and uncover new attack vectors to enhance, develop, and configure threat hunting tools. Additional responsibilities include:
* Identifying unknown threats for our global clients through advanced threat hunting services to complement the standard Security Operations Center services.
* Performing analysis and forensics on security threats, malware and attacks in the wild, using industry standard platforms and tools.

About Us:
Cynet is a leader in threat detection and response, designed to simplify security for organizations of all sizes. Our mission is to empower lean security teams and their partners with an AI-powered, unified platform that autonomously detects, protects, and responds to threats - backed by 24×7 security experts. With a Partner First mindset , we focus on helping customers and partners stay protected, operate confidently, and achieve their goals. Our vision is to give every organization true cybersecurity peace of mind, providing fast, accurate protection without the noise or complexity.
Requirements:
* Ability to work through shifts at a 24/7 SOC service, including weekends and public holidays - a Must
* Strong understanding of network architecture and protocols (e.g. HTTP, DNS)
* Hands-on approach to problem solving
* Ability to understand and learn complex technological systems and identify critical areas
* Exceptional analytical skills, creative out of the box thinking, analytical mindset with research orientation
* Strong presentation and training skills
* Experience in operating security tools (e.g. FW, IDS, SIEM, Endpoint protection)
* Fluent English (written and spoken) - a Must
* Experience in exposing and exploiting vulnerabilities – an advantage
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8456907
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
Are you an innovative security researcher with a deep understanding of Linux systems and a passion for protecting modern environments? Do you want to lead the charge in securing enterprise networks against the latest threats?
We're looking for a skilled professional to join our team, focusing on the critical and rapidly evolving fields of Linux Security. You'll be a foundational member of a new and growing team dedicated to the blue ocean of detection, developing multiple new capabilities within the largest cybersecurity enterprise in the world.
This is a unique opportunity to apply your expertise and influence the future of threat prevention-helping us build cutting-edge security solutions from the ground up.
Key Responsibilitie
Play a pivotal role in shaping the future of our security solutions.
Enhance product effectiveness by designing advanced protection components and developing sophisticated detection rules.
Research Linux OS internals, virtualized environments, and malware behaviors to inform and strengthen our attack prevention mechanisms.
Apply advanced AI and big data approaches to investigate and analyze large-scale datasets across our client base.
Lead research on novel protection concepts and bring them to production-grade quality, serving as a subject matter expert.
Stay up to date with the latest attacker methodologies, APT campaigns, and TTPs targeting Linux systems.
Conduct static and dynamic reverse engineering of Linux malware to uncover new techniques and develop mitigation strategies.
Collaborate closely with engineering, product management, and other research teams to translate research findings into production features.
Requirements:
5+ years of experience in cybersecurity research, with a proven track record of impactful projects.
Good knowledge of Linux OS internals, including both user and kernel space.
Solid knowledge of the cyber threat landscape, modern malware techniques, and APTs.
Hands-on experience in real-world threat hunting, incident response, or detection engineering.
Proficiency in programming languages such as Python, C, and/or C++, with a strong understanding of system-level programming and APIs.
Excellent problem-solving skills and a passion for cybersecurity innovation.
Ability to work independently, take initiative, and collaborate effectively in a team environment.
Preferred Qualifications
Background in EDR/XDR products or security solution development.
Experience in reverse engineering, including familiarity with debugging and disassembly tools such as GDB, IDA Pro, or Ghidra.
Experience in advanced data analysis, statistics, or machine learning for security applications.
Experience with Linux kernel development or vulnerability research.
Familiarity with virtualization platforms (e.g., ESXi/vCenter).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8781072
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Hunt, investigate, and analyze advanced persistent threat (APT) activity across endpoints, servers, cloud, and network infrastructure. partner with our Threat Intelligence team to resolve complex intrusions in customer networks. You'll uncover stealthy adversary behavior, reconstruct attack chains, and build the tools and methods that make our hunting and forensics better. You'll also present original research at top-tier industry conferences and
Key Responsibilities
Hunt and investigate targeted intrusions, long-dwell compromises, and espionage- driven activity across enterprise, cloud, identity, and network environments.
Perform advanced forensics across operating systems, cloud, memory, and network telemetry; correlate signals to determine the scope of compromise.
Build innovative tooling, research systems, and hunting/investigation workflows; identify capability gaps and propose automations to close them.
Produce clear reports, forensic timelines, threat-actor assessments, and actionable detection and remediation guidance.
Support internal security, threat intelligence, detection engineering, and investigation teams with expert forensic findings and technical analysis.
Partner with the Threat Intelligence team to resolve complex intrusions in customer networks.
Represent the organization through conference talks, workshops, and original research.
Requirements:
Extensive hands-on APT hunting, intrusion investigation, and digital forensics.
Deep understanding of APT tradecraft - stealth, persistence, credential abuse, defense evasion, living-off-the-land, custom tooling, supply-chain compromise, and command-and-control.
Broad forensic expertise across operating systems, cloud platforms, network and edge infrastructure, and memory, using industry-standard forensic and hunting tools.
Telemetry analysis across security platforms (EDR, SIEM, network, and identity systems) and the ability to build detection and hunting logic.
Strong development skills in Python (and ideally another language such as Go, C/C++, or PowerShell) to build tooling, automations, and analysis pipelines.
Strong communication for technical and executive audiences, including conference-grade presentations.
Represents the organization publicly, delivering talks, workshops, and research at top-tier cybersecurity and forensics conferences.
Nice to Have
Malware analysis and reverse engineering.
Experience with enterprise EDR/XDR and SIEM platforms.
Container, SaaS, and hybrid-cloud investigation experience.
Threat-intel collaboration; published research or prior conference talks.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785669
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Interested in Cyber Security and looking to work on real-world threats?
Join our company's Network Security Research team, where you'll help develop protections that keep organizations around the world safe from emerging attacks. Our team researches new threats, analyzes network vulnerabilities, develops detection and prevention technologies, and delivers frequent security updates to customers worldwide.
This role combines hands-on security research, threat analysis, and product content development, offering the opportunity to work on a wide variety of technologies, attack techniques, and emerging trends-including the growing use of AI in Cyber Security.
Key Responsibilities
Research, develop, and release network protections and security updates for our company's Network Security products.
Reproduce and analyze malicious attacks and campaigns to better understand threats and design effective mitigations.
Investigate network protocols and identify new detection opportunities.
Hunt for emerging threats using our company's cloud-scale data and develop new analysis techniques.
Explore how Generative AI and LLMs can improve threat research, detection, and security analysis.
Share research findings through technical blog posts and other internal and external publications.
Collaborate closely with researchers and developers to bring new protections from research into production.
Requirements:
B.Sc. / B.A. in Computer Science or another technical discipline.
2+ years of experience in Network Security Research, Threat Research, or a similar Cyber Security role.
Great understanding of networking concepts and common protocols (TCP, UDP, HTTP, DNS, SMB, FTP, etc.).
Understanding of the OSI model.
Experience with Generative AI, Large Language Models (LLMs), or AI-assisted security analysis tools, and an interest in applying AI to Cyber Security research.
Strong technical and analytical skills.
Self-motivated, curious, and eager to learn.
Ability to work in a dynamic, collaborative environment.
Fluent written and spoken English.
Nice to Have
Previous experience in Cyber Security.
Familiarity with common network attacks and vulnerabilities, including DDoS, brute force, spoofing, injection attacks, and insecure deserialization.
Understanding of malware behavior, C&C communication, phishing, drive-by attacks, and network scanning techniques.
Hands-on experience with IPS/IDS technologies, signature development, threat detection, or network traffic analysis.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785708
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
e are currently seeking a dynamic Incident Response Analyst to contribute to the success of our rapidly growing business.



As an Incident Response Analyst, you will:

Investigate and respond to workspace security incidents across email, browser security and perimeter security domains.
Handle investigation requests submitted by customers
Perform targeted phishing analysis and investigation of new attack campaigns
Conduct threat hunting based on attack patterns, behaviors, and indicators
Build and improve detections based on new attack types, tactics, companies and trends
Collaborate with development and research teams to provide incident-driven insights, and develop new detection engines for identifying previously unknown attacks
Write professional blog posts based on incident investigations and attack trends, contributing to the companys research-driven content and public visibility
Work in rotating shifts as part of a 24/7 operation (including nights, weekends, and holidays)
Requirements:
At least 3 years of experience in an Incident Response or Security Operation roles
Strong understanding of attack vectors, including Phishing, BEC, Email spoofing and impersonation techniques, Malware, ATO and more
Knowledge of email protocols and security concepts: SMTP, SPF/DKIM/DMARC, headers, authentication methods
Strong querying skills using SQL, SPL, KQL or AQL
Good knowledge with Static & Dynamic techniques
Familiarity with and understanding of code and scripting languages such as Python, JavaScript, Visual Basic, or similar - with the ability to read, interpret, and analyze potentially malicious scripts
Excellent written and verbal communication in English
Team player with a proactive, ownership-driven approach
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8797736
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
5 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a hands-on role that balances deep technical work along with building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by.

Youre welcome to work in our offices in Tel Aviv, Israel.

Your responsibilities will include:

Build and lead global DFIR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders.
Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases.
Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction.
Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements.
Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR.
Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA).
Raise the teams technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness.
Requirements:
7+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise).
Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2).
Technical Expertise

Deep knowledge of Windows and Linux internals, with proven disk and memory forensics capability.
Strong cloud-native platform security: containers and Kubernetes, CI/CD, secrets management, cloud control planes, and IAM attack paths.
Fluency in attacker TTPs (MITRE ATT&CK, including the Cloud and Containers matrices), and hands-on experience with EDR, SIEM, and forensic tooling (e.g., Velociraptor, Volatility, X-Ways/EnCase).
Strong scripting and data-analysis skills (Python, PowerShell, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818167
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a Threat Engineer to assess and develop our state-of-the-art detection solution. In this role, you will own the security coverage of our detection platform and guide development to strengthen our customers' resilience to emerging unknown threats. Your expertise in cyber security will drive our true AI-driven detection platform.
The Responsibilities:
Work closely with developers and data scientists to produce AI detection models.
Design and shape AI-driven security agents by encoding expert attacker and defender reasoning into agentic flows, prompts, decision logic, and investigative strategies.
Act as a domain expert partner for product and engineering teams, ensuring AI-driven security decisions remain grounded in real attacker tradecraft and operational reality.
Apply your cyber expertise to investigate emerging threats and define technical requirements to mitigate them.
Architect and build scalable solutions for evaluating the platform security metrics.
Requirements:
5+ years of experience in cybersecurity research, offensive security, penetration testing, red teaming, threat analysis, or related security engineering roles.
Background in malware analysis, network research and OS internals.
Proven experience with reverse engineering of x86/x64/ARM binaries.
Experienced with analysis tools, such as: IDA, WinDBG, SysInternals etc.
Curiosity and understanding of modern AI techniques - or a strong motivation to partner with AI experts to integrate domain knowledge into intelligent systems.
Strong ownership and leadership skills, with a track record of driving initiatives forward.
Understanding the threat landscape, attacker's mindset and techniques.
Solid coding skills with the ability to dive into internals and develop proof-of-concepts.
Excellent communication, teamwork, and problem-solving skills
Kernel development experience - advantage
Advanced C++ - advantage
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785199
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
09/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a threat Security Researcher to own the "right" side of the platform - from live cloud workloads and the eBPF telemetry they emit, through adversary behavior in containers and Kubernetes, into the AI systems and agents now embedded in production. You'll hunt down how novel attack techniques actually unfold at runtime - the credential theft, the lateral movement, the abuse of a model or an MCP tool - then turn that research into the detection logic that runs over our vast runtime telemetry and powers real-time threat protection. This role sits at the intersection of threat research, cloud, AI security, and detection engineering.
Conduct deep technical research into modern cloud environments and AI systems and discover novel attack techniques.
Lead product initiatives in the threats domain from inception to production. Collaborate closely with product, backend, and GTM, translating research into product capabilities.
Define and create complex detection logic over our vast telemetry, with a focus on coverage that scales across customer environments.
Identify gaps in detection coverage and evaluate detection quality. ensuring security logic is reliable and impactful.
Stay up to date with the evolving threat landscape (threat intelligence, campaigns) and incorporate into our product
Contribute to PR presence - technical research content, talks, open-source tooling.
Requirements:
5+ years of experience in threat research, including threat hunting, incident response or detection engineering
Military background experience, university degree, or Ex-CNAPP
Curious, detail-oriented mindset with proven ability to self-learn complex topics and new mechanisms.
Hands-on skills with scripting languages (e.g., Python) as well as query languages (e.g., KQL
Ability to work independently and also across teams, in a dynamic, fast-moving, demanding environment
Strong written and verbal communication skills in English, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.
Advantages :
Experience in AI Security Research
An AI-native mindset, you've built or applied AI-powered tooling in a security context
Experience conducting data-driven research and working with large-scale telemetry.
Experience in public-facing work, such as presenting at recognized industry conferences or authoring technical blog posts.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8773788
סגור
שירות זה פתוח ללקוחות VIP בלבד