TL;DR
Principal Cloud Security Researcher: Driving groundbreaking research and setting the technical direction for cloud threat research across AWS, Azure, and GCP with an accent on identifying emerging attack surfaces and novel techniques. Focus on translating threat findings into actionable product requirements and mentoring other researchers.
Location: Tel Aviv, IL. Hybrid work environment.
Company
hirify.global preemptively detects and stops attacks before damage is done, connecting Cloud, SaaS, AI, and Identity into one panoramic forensic system.
What you will do
- Own and drive critical research initiatives from threat hypothesis through detection logic, product integration, and external publication.
- Set the technical direction for cloud threat research across AWS, Azure, and GCP, identifying emerging attack surfaces and novel techniques.
- Investigate real-world cloud and SaaS security incidents, dissecting attacker tradecraft and extracting insights.
- Represent hirify.global as a thought leader through research publications, conference presentations, and open-source contributions.
- Translate threat findings into actionable product requirements, working closely with engineering and product teams.
- Mentor and grow other researchers through research reviews, pair investigations, code reviews, and methodology best practices.
Requirements
- 8+ years in security research, threat research, or closely related fields.
- Deep multi-cloud expertise with hands-on experience across at least two of the major cloud providers (AWS, Azure, GCP).
- A track record of original research through blog posts, conference talks, open-source tools, or vulnerability discoveries.
- Strong adversarial mindset and critical thinking to model threat scenarios and map out attack paths.
- Ability to operate autonomously on ambiguous, high-stakes problems.
Nice to have
- Experience with cloud forensics and incident response (DFIR in cloud/SaaS environments).
- Background in red teaming or penetration testing targeting cloud environments.
- Familiarity with Kubernetes security, container escape techniques, and cloud-native supply chain risks.
- Experience building or contributing to threat intelligence frameworks or detection content libraries.
Culture & Benefits
- Competitive compensation package with stock options, educational fund, cibus.
- Cell phone and cell phone charges covered.
- Top of the line equipment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →