תיאור המשרה
Company Description
About The role 
Hunt, investigate, and analyze advanced persistent threat (APT) activity across endpoints, servers, cloud, and network infrastructure. partner with our Threat Intelligence team to resolve complex intrusions in customer networks. You'll uncover stealthy adversary behavior, reconstruct attack chains, and build the tools and methods that make our hunting and forensics better. You'll also present original research at top-tier industry conferences and  
Job Description
Hunt and investigate targeted intrusions, long-dwell compromises, and espionage- driven activity across enterprise, cloud, identity, and network environments. 
Perform advanced forensics across operating systems, cloud, memory, and network telemetry; correlate signals to determine the scope of compromise. 
Build innovative tooling, research systems, and hunting/investigation workflows; identify capability gaps and propose automations to close them. 
Produce clear reports, forensic timelines, threat-actor assessments, and actionable detection and remediation guidance. 
Support internal security, threat intelligence, detection engineering, and investigation teams with expert forensic findings and technical analysis. 
Partner with the Threat Intelligence team to resolve complex intrusions in customer networks. 
Represent the organization through conference talks, workshops, and original research. 
Qualifications
Extensive hands-on APT hunting, intrusion investigation, and digital forensics. 
Deep understanding of APT tradecraft - stealth, persistence, credential abuse, defense evasion, living-off-the-land, custom tooling, supply-chain compromise, and command-and-control. 
Broad forensic expertise across operating systems, cloud platforms, network and edge infrastructure, and memory, using industry-standard forensic and hunting tools. 
Telemetry analysis across security platforms (EDR, SIEM, network, and identity systems) and the ability to build detection and hunting logic. 
Strong development skills in Python (and ideally another language such as Go, C/C++, or PowerShell) to build tooling, automations, and analysis pipelines. 
Strong communication for technical and executive audiences, including conference-grade presentations. 
Represents the organization publicly, delivering talks, workshops, and research at top-tier cybersecurity and forensics conferences. 
  Nice to Have 
Malware analysis and reverse engineering. 
Experience with enterprise EDR/XDR and SIEM platforms. 
Container, SaaS, and hybrid-cloud investigation experience. 
Threat-intel collaboration; published research or prior conference talks. 
Referral Category: Standard Position
CP Department: Products - R&D
Office Location: Tel-Aviv
Career site Category: R&D