Threat Detection Researcher (cloud)

Wiz Wiz · Enterprise · Tel Aviv, Israel · Threat & AI Research

The Threat Detection Researcher will design behavioral baselines for cloud environments, develop high-fidelity detections, expand the detection engine with novel telemetry sources, conduct research into cloud services to uncover attack vectors, and investigate real-world attacks. The role involves hunting and analyzing emerging threats targeting cloud ecosystems.

What you'd actually do

  1. Design behavioral baselines for complex cloud environments using diverse signals, and develop high-fidelity detections based on those baselines.
  2. Expand Wiz's detection engine with novel and high-impact telemetry sources, pushing the boundaries of what can be detected in modern cloud environments.
  3. Conduct deep technical research into complex cloud services to uncover novel attack vectors.
  4. Investigate real-world attacks across cloud environments, identity providers (IDPs), and infrastructure-as-a-service (IaaS) platforms.
  5. Hunt and analyze emerging threats and active campaigns targeting cloud ecosystems.

Skills

Required

  • 6+ years of hands-on experience in security or threat research
  • Strong self-motivation and ability to independently drive complex research projects from concept to delivery
  • Clear and effective communicator with excellent collaboration skills

Nice to have

  • Experience conducting data-driven research and working with large-scale telemetry
  • Familiarity with cloud infrastructure (AWS, GCP, Azure), Kubernetes, and modern cloud-native architectures
  • Background in incident response, red teaming, or threat hunting
  • Hands-on experience building and shipping security detections as part of a product
  • Proficiency in Python, Go, and query languages (e.g., KQL, SQL)

What the JD emphasized

  • proven track record of driving investigations to actionable, real-world impact
  • hands-on experience building and shipping security detections as part of a product