Security Researcher

Guardz

Tel Aviv, Israel
On-site
Identity, email, and endpoint threats
Attacker abuse patterns and misconfigurations
Real-world attack data analysis
Conduct in-depth research and analysis of identity, email, and endpoint threats, investigating attacker abuse patterns, misconfigurations, and security gaps across Entra ID, Microsoft 365, Google Identity, and Google Workspace

Job Summary

  • Conduct in-depth research and analysis of identity, email, and endpoint threats, investigating attacker abuse patterns, misconfigurations, and security gaps across Entra ID, Microsoft 365, Google Identity, and Google Workspace.
  • Analyze real-world attack data to identify emerging techniques, trends, and detection gaps, and translate complex threat scenarios and research insights into actionable detection rules, policies, and product controls.
  • Collaborate closely with product and engineering teams to transform research into impactful security features and customer protections, and support red-teaming efforts to validate detection effectiveness.

Matching Summary

Conduct in-depth research and analysis of identity, email, and endpoint threats, investigating attacker abuse patterns, misconfigurations, and security gaps across Entra ID, Microsoft 365, Google Identity, and Google Workspace.

Skills & Requirements

Must-have

  • identity, email, and endpoint threats
  • attacker abuse patterns and misconfigurations
  • real-world attack data analysis
  • actionable detection rules and policies
  • Python or similar scripting languages
  • Microsoft 365 and Google Workspace environments

Nice-to-have

  • strengthening Guardz' detection capabilities
  • collaborative research team environment
  • fostering a safer digital landscape

Key Requirements

  • 3+ years of experience in security research, threat analysis, or security misconfiguration assessment
  • 3+ years of hands-on experience in Tier 2 / Tier 3 security operations
  • 2+ years of focused experience in Identity Security
  • Strong proficiency in SQL
  • Solid experience with cybersecurity frameworks (MITRE ATT&CK, Cyber Kill Chain)
  • Hands-on experience with red-teaming, penetration testing, or detection & response
  • Proficiency in Python or similar scripting/programming languages
  • Broad technical understanding of network, OS, and cloud security technologies
  • Excellent written and verbal communication skills; fluent English

Work Rights

Not specified

Tailored Resume

Cover Letter