Security Researcher (Cloud Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Researcher (Cloud Security): Drive runtime threat research for Cloud Detection and Response (CDR) by studying attacker behavior inside live cloud workloads and converting findings into detections with an accent on compute, containers, Kubernetes, serverless, and detection coverage validation. Focus on analyzing AWS/GCP/Azure telemetry, running threat simulations/attack emulation, tracking emerging threats and CVEs, and mentoring junior researchers while producing publishable research.
Location: Tel Aviv
Company
builds cloud security detection and response capabilities.
What you will do
- Research attacker tradecraft against live cloud workloads (compute, containers, Kubernetes, serverless), including execution, privilege escalation, persistence, lateral movement, and evasion
- Analyze telemetry from AWS CloudTrail, GCP Audit Logs, Azure Activity Logs, and runtime/sensor data to investigate threats and translate findings into detection logic
- Collaborate with sensor and detection engineers on feasibility, coverage, and signal quality
- Run threat simulations and attack emulation to validate coverage and identify gaps
- Track emerging threats and CVEs across AWS, Azure, and GCP and feed them into detection priorities
- Publish externally (blog posts, whitepapers, threat reports) and represent Orca at conferences and webinars; mentor a junior researcher
Requirements
- 4+ years in security research, threat research, or detection engineering, ideally in cloud/cloud-native environments
- Strong Linux and cloud infrastructure foundation with an attacker-oriented mindset
- Deep familiarity with attacker TTPs (MITRE ATT&CK for Cloud/Containers)
- Hands-on experience turning runtime/host/network security events into detections
- Proficiency in Python (Go is a plus)
- Strong written and spoken English to explain complex topics clearly
Nice to have
- eBPF/runtime sensor experience and Linux kernel internals
- Kubernetes/container, API, or application security background
- Offensive security, red teaming, or vulnerability research experience
- Large-scale telemetry analysis (SQL/Elastic)
- AI/ML-assisted security research experience
- Conference speaking, published research, CVEs, or open-source contributions
Culture & Benefits
- High-growth environment with a focus on disruptive cloud security innovation
- Respectful and transparent culture with accessible leadership and knowledge sharing
- Opportunity to publish research and represent the company externally
- Mentorship responsibilities as a senior member of the team
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →