Threat Researcher

Wiz · Tel Aviv, Israel
full-time senior Posted 8 hours ago

Before you apply

Build my evidence-backed draft — free Apply on company site →

Paste your relevant resume section or 2–4 true bullets. See supported requirements and honest gaps. No account and no application sent.

Get weekly job alerts like this →

About this role

Come join the organization that is redefining security for the AI era. As one of the fastest-growing startups ever, we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven track record of success and a culture that values world-class talent. Not to mention, we're now powered by Google , meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation. Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun! Minimum qualifications 5+ years of hands-on experience in security research, red-teaming, penetration testing, incident response, or vulnerability research. Strong understanding of network and application security, including core networking protocols (TCP/IP, DNS, TLS), web technologies, modern APIs, and real-world application- and network-layer exploitation techniques (e.g., OWASP API Security Top 10). Strong scripting and automation skills (using Python, Bash, or equivalent). Hands-on experience developing, customizing, using, or conducting research supporting vulnerability scanners (DAST / SAST / Network / Host scanners), writing detection rules, or building automated vulnerability and exploitability validation tools. Strong sense of ownership and the ability to independently lead projects from research to delivery. Strong writing and presentation skills in both English and Hebrew. Preferred qualifications Experience with developing or researching cloud environments (AWS, Azure, or GCP). Familiarity with security aspects of Kubernetes, containers, and/or CI/CD. Familiarity with AI-assisted development tools such as Claude Code or similar. Familiar with network and application scanning tools (Burp Suite, nmap, Metasploit, Nuclei, or similar). Published security research, exploits/PoCs, or contributed to open-source security tooling. About the job As a Threat Researcher in Exposure & Risk Detection, you will drive research projects end-to-end to identify emerging threats, CVEs, and misconfigurations, assessing their real-world exploitability and customer impact. In this role, you will investigate cloud services, frameworks, and commonly deployed technologies to uncover new attack surfaces, and build automations to validate, benchmark, and monitor AI-driven detection capabilities at scale. You will collaborate closely with Product and R&D teams to transform research findings and attack methodologies into impactful product capabilities, directly shaping how our customers stay secure. Check out some of our recent research: The Red Agent POV: How it Reasoned its Way to SSRF Under the Radar: Exploring Spring Boot Actuator Misconfigurations Beyond CVEs: The Exploitation of Everyday Misconfigurations React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182 Responsibilities Research emerging threats, CVEs, and misconfigurations to assess real-world exploitability and customer impact. Design, build, and test detection rules and scanning logic for exposed and vulnerable assets. Build automations to validate, benchmark, and monitor AI-driven detection capabilities at scale. Investigate cloud services, frameworks, and commonly deployed technologies to uncover new attack surfaces. Analyze large-scale scan results to identify and prioritize meaningful risks. Drive research projects end-to-end, from initial idea to production-ready detection. Collaborate closely with Product and R&D teams to transform research findings and attack methodologies into impactful product capabilities.   Applicants must have the legal right to work in the country where the position is based,  without the need for visa sponsorship. This role does not offer visa sponsorship . Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or o

Similar Jobs

Related searches:

On-site Jobs Senior Jobs On-site Senior Jobs Senior AI ResearchSenior AI Safety & Security AI Jobs in Tel Aviv AI Research in Tel AvivAI Safety & Security in Tel Aviv securityresearch

Get jobs like this delivered weekly

Free AI jobs newsletter. No spam.