דרושים » אבטחת מידע וסייבר » Sr MSIAM SOC Engineer (Unit 42)

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 5 שעות
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Sr MSIAM SOC Engineer (Unit 42)
Job Summary
As a Senior SOC Engineer within Unit 42, you will drive the creation, validation, and optimization of custom detection rules and automated playbooks across our global customer base. Acting as a trusted advisor, you will collaborate closely with clients to maximize their security posture using Cortex XSIAM and Unit 42 expertise. This highly analytical role leverages your deep understanding of detection lifecycles, proactive automation, and threat intelligence to secure enterprise environments. You will architect end-to-end security lifecycles that seamlessly connect data ingestion with high-fidelity detection engineering.
Key Responsibilities:
Own the full lifecycle of custom detections and response automations, deploying them as high-fidelity Cortex XSIAM correlation rules and playbooks through a rigorous engineering process of development, testing, staging, and soft implementation.
Drive the continuous refinement of correlation rules to ensure strict standards for performance, accuracy, and operational relevance.
Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic.
Champion proactive automation by engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand.
Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.
Requirements:
Required Qualifications:
5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms in complex enterprise environments.
Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning.
Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback.
Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions.
Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests.
Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms.
Software development experience with a strong proficiency in Python for security automation and scripting.
Preferred Qualifications:
Previous hands-on experience utilizing and optimizing Cortex XSIAM.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830540
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 6 שעות
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a Senior SOC Engineer within Unit 42 at Palo Alto Networks, you will drive the creation, validation, and optimization of custom detection rules and automated playbooks across our global customer base. Acting as a trusted advisor, you will collaborate closely with clients to maximize their security posture using Cortex XSIAM and Unit 42 expertise. This highly analytical role leverages your deep understanding of detection lifecycles, proactive automation, and threat intelligence to secure enterprise environments. You will architect end-to-end security lifecycles that seamlessly connect data ingestion with high-fidelity detection engineering.
Key Responsibilities
Own the full lifecycle of custom detections and response automations, deploying them as high-fidelity Cortex XSIAM correlation rules and playbooks through a rigorous engineering process of development, testing, staging, and soft implementation.
Drive the continuous refinement of correlation rules to ensure strict standards for performance, accuracy, and operational relevance.
Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic.
Champion proactive automation by engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand.
Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.
Requirements:
5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms in complex enterprise environments.
Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning.
Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback.
Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions.
Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests.
Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms.
Software development experience with a strong proficiency in Python for security automation and scripting.
Preferred Qualifications
Previous hands-on experience utilizing and optimizing Cortex XSIAM.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830331
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 6 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Principal / Sr. Principal Security Research - Advanced Cyber Research (Cortex)
We are seeking a visionary and highly technical Principal / Sr. Principal Security Researcher to join our security research team. In this role, you will be at the forefront of innovating automated defense systems to rapidly protect platform customers against advanced cyber threats at an unprecedented scale. This position offers a unique opportunity to blend deep traditional cybersecurity expertise - including OS internals, reverse engineering, and advanced detection engineering with cutting-edge AI technologies like LLMs, SLMs, and agentic workflows.
You will spearhead the creation of innovative prevention solutions, leveraging massive streams of agent telemetry to design AI-driven logic that neutralizes threats before they execute. As a key technical leader, you will partner closely with top-tier data scientists and product engineers to translate cutting-edge security research into production-grade capabilities, ensuring we stay ahead of the evolving threat landscape.
Key Responsibilities:
Develop Automated Defense Systems:Create, engineer, and deploy automated solutions for the prevention and detection of advanced cyber threats, analyzing complex data to rapidly protect platform customers at scale.
Innovate with AI:Partner closely with data scientists to leverage LLMs, SLMs & deeplearning techniques to fuel these advanced prevention solutions and automated defense capabilities.
Research, develop, and continuously improve the Agentix solution. Drive the development of next-generation security content by designing and implementing specialized AI agents to automate security operations and workflows.
Drive Security Innovations:Spearhead new research initiatives from the ground up. Act as the primary driver across key stakeholders, leading top-tier data scientists and engineers to ensure the successful delivery of enterprise-grade security capabilities.
Requirements:
Required Qualifications:
5+ years of hands-on experience in the cybersecurity research field.
Threat Research & OS Internals:Proven track record of applying deep cyber and analytical expertise to build robust security logic using endpoint telemetry. Supported by a profound understanding of Windows and Linux OS/kernel internals to engineer advanced defenses.
Reverse engineering experience:Demonstrated expertise in reverse engineering (e.g., IDA Pro, Ghidra) across multiple platforms to dissect malware and identify sophisticated attack vectors.
Programming & Native Code Comprehension:Strong proficiency in Python for data analysis and rapid prototyping, combined with the ability to comprehend native code (C, C++, or Rust) to effectively read and interpret agent code, low-level system interactions, and memory operations.
End-to-End Research Ownership:A scientific, data-driven approach to solving complex security challenges, with a proven track record of owning research initiatives from initial ideation through to the deployment of production-grade capabilities.
Communication & Mentorship:Excellent communication skills, with the ability to clearly articulate complex threat research to diverse audiences, mentor junior team members, and champion security initiatives across the organization.
Preferred Qualifications:
AI Agents & Frameworks:Hands-on experience developing and working with AI Agents and agentic workflows. Technical understanding of the architectural distinctions between an agent, a skill, and Model Context Protocol (MCP). Proven experience utilizing common agentic frameworks.
Data Scale & Telemetry Analysis:Proficiency in query languages (e.g., SQL) and big data platforms (e.g., GCP) to parse, manipulate, and query large-scale agent telemetry, extracting actionable security insights and uncovering threat patterns from massive datasets.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830285
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 2 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time
Principal Security Researcher (Cortex - AgentiX)
Job Summary:
As a Principal Security Researcher , you will act as an architect for the Autonomous SOC, focusing directly on Cortex AgentiX. You will design and build intelligent, automated investigation and remediation agents that empower thousands of customers to secure their environments at scale.
We are looking for a practitioner who combines deep hands-on expertise investigating threats and protecting organizations with a pragmatic approach to solving complex security challenges.
Key Responsibilities:
Develop in-product specialized agents to accelerate detection, respond to real-time threats, prioritize, and mitigate risks.
Establish guardrails, continuous evaluation metrics, and deterministic controls for agentic AI, ensuring complex multi-step plans execute reliably.
Drive the complete product development lifecycle, encompassing definition, design, implementation, and testing phases.
Partner cross-functionally with product management, engineering, and research teams.
Requirements:
Required Qualifications:
10+ years of hands-on experience securing enterprise organizations.
Proven track record in DFIR and threat hunting, including containing and remediating complex security incidents using dozens of tools.
Practical experience utilizing industry standard frameworks, such as MITRE ATT&CK, for threat modeling.
Coding proficiency, preferably Python.
Advanced expertise leveraging AI capabilities for cybersecurity.
Exceptional analytical and problem-solving skills with a demonstrated ability to resolve complex challenges.
Excellent written and verbal communication skills to effectively collaborate with cross-functional teams.
Preferred Qualifications:
Experience with Agentic AI SOC and Security Orchestration, Automation, and Response (SOAR) platforms, preferably Cortex XSOAR/XSIAM.
Relevant security certifications, such as CISSP.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830966
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 6 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Senior/ Principal Security Researcher - Cloud & Kubernetes (Cortex)
Job Summary:
If you are an innovator at heart and passionate about redefining how organizations secure modern environments end-to-end, we're looking for you. This is an opportunity to join an exceptional group of researchers working on a startup-level product within the largest security company, helping revolutionize how organizations protect their Kubernetes and hybrid cloud environments.
Key Responsibilities:
Contribute to a team of talented security researchers focused on defending organizations as they transition from on-premises data centers to modern cloud and Kubernetes infrastructure.
Drive the execution of research initiatives to uncover novel techniques for detecting and responding to sophisticated attacks targeting hybrid and cloud-native environments.
Define and prioritize detection use cases, relevant datasets, and innovative analytic approaches combining runtime visibility and posture management across diverse platforms.
Stay up to date with the latest attacker methodologies, APT campaigns, and TTPs to ensure our detection capabilities stay ahead of evolving threats in both legacy and cloud contexts.
Simulate real-world attacks and perform deep behavioral analysis to inform and validate detection content.
Collaborate across engineering, product management, and go-to-market teams to deliver impactful security solutions.
Share insights with the security community through blogs, conference talks, and publications.
Requirements:
Required Qualifications:
5+ years in security research with a proven track record of driving impactful projects.
Deep expertise in cloud-native security, with strong focus on Kubernetes, containers or major cloud providers (AWS, Azure, GCP, OCI) or Linux internal.
Experience developing or working with detection and response products, such as XDR, EDR, or cloud workload protection platforms.
Excellent communication skills, with the ability to articulate complex research findings and drive alignment across diverse teams.
Proficient in hands-on coding and scripting (e.g., Python).
Preferred Qualifications:
Experience working with large-scale data pipelines and analytics (e.g., GCP BigQuery, Dataflow).
Familiarity with Kubernetes threat modeling frameworks (e.g., MITRE ATT&CK for Containers).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830304
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a skilled Security Automation Engineer to join our SOC Automation team and play a key role in building and scaling automation across Security Operations. This is a hands-on role - you will design, develop, and integrate automation solutions across SIEM, EDR, and other security platforms, contributing to our SOAR capabilities from the ground up.

You will work in a technologically rich environment, integrating with a wide range of security and infrastructure systems across the network - a unique opportunity to build automation at scale in a greenfield setting, with real influence over the architecture and tooling decisions.

We are especially interested in candidates who are curious about leveraging AI and intelligent agents to help evolve next-generation automation and response workflows - and who want to be a driving voice in how we apply those technologies.

Your responsibilities will include:

Automation development

Design and develop automation workflows for incident response and SOC operations
Identify and eliminate manual processes through scalable automation
Build reusable components and maintainable automation patterns
Engineering & integration

Develop integrations using REST APIs, webhooks, and event-driven architectures
Write high-quality, maintainable Python for automation and orchestration
Implement data parsing, enrichment, and transformation across multiple systems
SOAR & platform buildout

Lead or actively contribute to the evaluation, selection, and implementation of SOAR/automation platforms
Design the automation architecture and integration strategy for the team
Build automation capabilities in a greenfield environment - your decisions will shape the foundation
SOC collaboration

Work closely with SOC analysts and incident responders to translate operational needs into automation solutions
Improve end-to-end detection and response workflows through close partnership with the team
AI & innovation

Actively build and evaluate AI/LLM and agent-based workflows applied to security automation
Prototype AI-assisted enrichment, triage, and response solutions and drive them toward production
Requirements:
Minimum 3 years of hands-on experience with SOAR platforms (e.g., Torq, Cortex XSOAR, Splunk SOAR, or similar)
Strong hands-on experience with Python (or a comparable language)
Experience designing or implementing automation frameworks or workflows
Experience building integrations using REST APIs and web services
Experience working with security tools such as SIEM, EDR/XDR, or ticketing systems
Experience with at least one cloud platform (Azure, AWS, or GCP)
Solid understanding of incident response processes and SOC alert-handling workflows
Experience with at least one SIEM platform (Splunk,Sentinel,Qradar,Crowdstrike)
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817744
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 1 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Security Researcher to join our research group as part of a growing team developing Autopilot, an innovative product for autonomous investigation and response.
As a core member of the team, you'll go beyond research: youll research, design, and develop investigation modules that allow Autopilot to autonomously detect, investigate, and respond to advanced threats at a massive scale.
Youll analyze everything from new malware behaviors to attacker techniques and process activity in enterprise-scale networks, using data collected from across millions of endpoints. Your work will span identifying attack patterns and uncovering statistical anomalies, as well as validating that the system responds effectively to real-world attacks and APT campaigns using production data.
Key Responsibilities:
Research and implement new autonomous methods for investigating and responding to targeted attackers, using large-scale, diverse security datasets
Develop and design the graph-based algorithms that power autonomous investigation and decision-making capabilities
Design automated incident response by developing reusable logic that transforms raw security data and alerts into clear, actionable insights.
Leverage graph algorithms, AI techniques, and statistical methods to mimic and scale human security analyst workflows
Conduct deep, hands-on investigations into modern malware, APTs, and complex attack flows to inform detection and response logic
Stay up to date with attacker methodologies, tools, and techniques (TTPs), ensuring our product remains effective against evolving threats
Contribute to a collaborative, fast-paced research team, helping shape our research strategy, improve processes, and continuously enhance the product
Requirements:
Required Qualifications:
5+ years of experience in security or threat research, in which you conducted deep research with actionable insights and real-world impact.
Proven experience as part of an R&D/development team, along with strong proficiency in Python programming
Intimate knowledge and understanding of attack methods and techniques over endpoints and enterprise networks
Comfortable working with large-scale datasets to extract meaningful insights through advanced analysis
Strong sense of ownership and ability to independently drive projects from concept to execution
Critical thinker who thrives both independently and in collaborative team environments
Excellent verbal and written communication skills
A cybersecurity professional driven to solve the next generation of security challenges.
Preferred Qualifications:
In-depth knowledge of the inner workings of operating systems (especially Windows)
Experience working with graph DB and algorithms
Experience in statistics, advanced data studies, or machine learning.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8831013
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Threat Researcher to join its Threat Intelligence Analysis (TIA) team. The team is responsible of discovering, analyzing and tracking advanced threat actors and campaigns, with a strong focus on high-end cybercrime and state-sponsored activities. You will join a team of motivated, independent & highly technical individuals and contribute the effort to protect our company customers and empower the company brand.
Key Responsibilities
Identify, understand and monitor advanced campaigns using publicly available sources as well as internal telemetry.
Analyze malware and other hacking tools utilized by threat actors in active campaigns and intrusions.
Create technical research content for public and private intelligence reports.
Help build protections and detections based on deep understanding of advanced threat actors Tactics Techniques and Procedures (TTPs).
Collaborate with other security teams to assist threat intelligence and research tasks.
Requirements:
Your Knowledge & Skills
5+ years of experience as a threat researcher, incident responder, malware analyst, detection engineer or other relevant roles.
Practical experience in tracking state-sponsored or advanced financially motivated actors - including malware, infrastructure and TTPs.
Profound knowledge and understanding of malware and common attacking techniques.
Hands-on experience in automating and optimizing hunting and enrichment processes using code (preferably Python).
Familiarity with query languages and data exploration tools.
Ability to translate technical findings into actionable detection and prevention signatures.
Experience in writing technical blog posts and technical analysis reports.
Experience in public speaking and presentation of research in cyber security conferences .
Fluent English.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785668
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
25/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
our company's attack surface spans several distinct businesses: the engine and editor developers build on, a wide portfolio of cloud products and services, a large monetization business, and a growing set of AI-assisted creation tools. Code built with our company runs everywhere from a developer's workstation to billions of end-user devices, so targets range from native binaries to distributed cloud systems to AI pipelines, and findings here matter.
This role brings an attacker's mindset to that landscape: penetration testing and red team engagements built on complex attack chains. You would combine manual techniques with automation and tooling you develop as part of your craft, extending your reach across the company ecosystem.
What you'll be doing
Plan and execute objective-based penetration tests and red team engagements across our company's products, cloud services, and infrastructure
Find and validate exploitable vulnerabilities, chain them into realistic attack paths, and demonstrate impact with reproducible proofs of concept
Develop the automation and tooling that extend the team's offensive reach across the company ecosystem
Run joint exercises with the SOC and detection engineering teams to validate telemetry and improve detections
Deliver clear findings to engineering teams and surface recurring risk patterns to security leadership.
Requirements:
5+ years of hands-on experience in offensive security, penetration testing, or red teaming
Proven ability to find, exploit, and chain vulnerabilities across applications
Deep understanding of how modern web applications and APIs break
Hands-on experience assessing cloud environments (AWS or GCP)
Strong ability to develop and validate offensive tooling
You might also have
Adversary emulation experience: designing engagements around real threat actor TTPs
Security research in real-time 3D, game engines or SDKs, or mobile runtimes
Experience attacking CI/CD and build systems.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796320
סגור
שירות זה פתוח ללקוחות VIP בלבד