Principal Cloud Security Researcher
פורסם 29 ביולי · 0 מועמדים
התפקיד במילים פשוטות
זהו תפקיד הובלה טכנית בכיר בצוות המחקר, ללא ניהול ישיר של עובדים. התפקיד כולל הובלת מחקרי איומי ענן מקצה לקצה על פני AWS, Azure ו-GCP, זיהוי משטחי תקיפה חדשים, חקירת אירועי אבטחה אמיתיים ופיתוח לוגיקות זיהוי עבור המוצר. בנוסף, העבודה כוללת פרסום ממצאים מקצועיים, הרצאות בכנסים וחניכה של חוקרים אחרים בצוות.
- 8+ years in security research, threat research, or closely related fields (offensive security, detection engineering, incident response, cloud security engineering)
- Multi-cloud hands-on experience across at least two major cloud providers (AWS, Azure, GCP), with working knowledge of the third
- Track record of original research (published blog posts, conference talks, open-source tools, or vulnerability discoveries)
- Adversarial mindset and threat modeling targeting cloud infrastructure, SaaS platforms, identity systems, and Kubernetes
- Ability to operate autonomously on ambiguous, high-stakes problems
- Experience with cloud forensics and incident response (DFIR in cloud/SaaS environments)
- Background in red teaming or penetration testing targeting cloud environments
- Familiarity with Kubernetes security, container escape techniques, and cloud-native supply chain risks
- Experience building or contributing to threat intelligence frameworks or detection content libraries
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים לחוקרי אבטחה בעלי ניסיון עמוק של 8 שנים ומעלה (או רקורד יוצא דופן) במחקר איומים, אבטחת ענן והנדסת זיהוי, עם פרסומים מקצועיים והבנה מעמיקה במספר ספקי ענן. הוא פחות מתאים למי שמחפש תפקיד ניהולי של כוח אדם או לחוקרים בתחילת דרכם הזקוקים להנחיה צמודה.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןWe’re looking for Principal Cloud Security Researcher with a strong security background to join our innovative Research team. Why Mitiga? EDR protects the endpoint. Mitiga protects everything else, anticipating and disrupting active attacks across the modern stack and stopping them before they reach the business. Mitiga is the leader in Zero-Impact Breach Prevention, delivered through Agentic Runtime Security for the modern infrastructure — cloud, SaaS, identity, and AI. By delivering the runtime detection and response that security teams already rely on for endpoints, extended to the infrastructure endpoint tools can’t see, Mitiga provides Zero-Impact Breach Prevention, in runtime. The Role We're looking for a Principal Cloud Security Researcher to serve as a senior technical leader within our Research team. This is a high-impact individual contributor role -- you won't manage people, but you'll shape the direction of our entire research function, mentor researchers, and act as a force multiplier across the organization. You'll be the person who takes a vague threat signal and turns it into a detection strategy, a published finding, or a product capability. You'll operate as a trusted deputy to the research team lead, owning the most complex and ambiguous research challenges while raising the technical bar for the team. What You'll Do Drive Groundbreaking Research • Own and drive Mitiga's most critical research initiatives end-to-end - from initial threat hypothesis through detection logic, product integration, and external publication. • Set the technical direction for cloud threat research across AWS, Azure, and GCP, identifying emerging attack surfaces and novel techniques before they become mainstream threats. • Investigate real-world cloud and SaaS security incidents, dissecting attacker tradecraft and extracting insights that evolve our detection capabilities. • Pioneer new forensic investigation techniques and detection methodologies for cloud-native and SaaS environments - pushing the state of the art, not just following it. Be a Voice in the Community • Represent Mitiga as a thought leader through high-quality research publications, conference presentations (BlackHat, DEF CON, RSA, fwd:cloudsec, and similar venues), and open-source contributions. • Build and maintain Mitiga's reputation as a research-driven company that advances the field - not just a vendor with a blog. • Engage with the broader security research community, fostering relationships and collaborative knowledge-sharing. Shape the Product • Bridge research and product - translate threat findings into actionable product requirements, working closely with engineering and product teams to ensure our CDR platform stays ahead of evolving threats. • Design and develop advanced detection algorithms that directly feed into Mitiga's platform, closing the gap between research insight and customer protection. Elevate the Team • Act as the team's go-to technical authority. When researchers hit a wall on complex cloud attack chains, IAM edge cases, or detection gaps - you're who they turn to. • Mentor and grow other researchers through research reviews, pair investigations, code reviews, and by setting quality standards and methodology best practices. • Influence technical decisions org-wide - contributing to architecture, tooling, and strategic research priorities. • Step in as the research team lead's deputy when needed - driving prioritization, representing research cross-functionally, and ensuring continuity.
Requirements: Who You Are • 8+ years in security research , threat research, or closely related fields (offensive security, detection engineering, incident response, cloud security engineering). Fewer years are fine if your depth and track record are exceptional. • Deep multi-cloud expertise - strong hands-on experience across at least two of the major cloud providers (AWS, Azure, GCP), with working knowledge of the third. You understand the IAM models, logging pipelines, APIs, and attack surfaces that matter in each. • A track record of original research - you've published meaningful technical findings through blog posts, conference talks, open-source tools, or vulnerability discoveries that moved the needle. We want someone who doesn't just consume research - you produce it. • Strong adversarial mindset and critical thinking - you think like an attacker targeting cloud infrastructure, SaaS platforms, identity systems, and Kubernetes. You can model threat scenarios, map out attack paths, and poke holes in defenses. • Ability to operate autonomously on ambiguous, high-stakes problems. You don't wait for detailed specs - you identify what matters and drive it forward. It Would Be Nice If You Also Had • Experience with cloud forensics and incident response (DFIR in cloud/SaaS environments). • Background in red teaming or penetration testing targeting cloud environments. • Familiarity with Kubernetes security, container escape techniques, and cloud-native supply chain risks. • Experience building or contributing to threat intelligence frameworks or detection content libraries.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- היברידי
- 8+ years in security research, threat research, or closely related fields (offensive security, detection engineering, incident response, cloud security engineering), Multi-cloud hands-on experience across at least two major cloud providers (AWS, Azure, GCP), with working knowledge of the third, Track record of original research (published blog posts, conference talks, open-source tools, or vulnerability discoveries), Adversarial mindset and threat modeling targeting cloud infrastructure, SaaS platforms, identity systems, and Kubernetes, Ability to operate autonomously on ambiguous, high-stakes problems