# Threat Researcher

**Company:** [Wiz](https://hotfix.jobs/companies/wiz)
**Location:** Tel Aviv, Israel
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Python, Bash, TCP/IP, DNS, Tls, Web Security, Api Security, Vulnerability Scanning, DAST, SAST, Cloud Security, Kubernetes, Burp Suite, Nmap, Metasploit
**Posted:** 2026-08-30

> Conduct end-to-end security research on emerging threats, CVEs, misconfigurations, and cloud attack surfaces, then turn findings into scalable detection capabilities. Requires at least five years of security research or related experience, strong scripting skills, and expertise in network and application security.

## Job Description

## Responsibilities
- Research emerging threats, CVEs, and misconfigurations to assess real-world exploitability and customer impact.
- Design, build, and test detection rules and scanning logic for exposed and vulnerable assets.
- Build automations to validate, benchmark, and monitor AI-driven detection capabilities at scale.
- Investigate cloud services, frameworks, and commonly deployed technologies to uncover new attack surfaces.
- Analyze large-scale scan results to identify and prioritize meaningful risks.
- Drive research projects end-to-end, from initial idea to production-ready detection.
- Collaborate with Product and R&D teams to transform research findings and attack methodologies into product capabilities.

## Requirements
- 5+ years of hands-on experience in security research, red-teaming, penetration testing, incident response, or vulnerability research.
- Strong understanding of network and application security, including TCP/IP, DNS, TLS, web technologies, modern APIs, and application- and network-layer exploitation techniques.
- Strong scripting and automation skills using Python, Bash, or equivalent.
- Experience developing, customizing, using, or researching vulnerability scanners, including DAST, SAST, network, or host scanners.
- Experience writing detection rules or building automated vulnerability and exploitability validation tools.
- Ability to independently lead projects from research through delivery.
- Strong writing and presentation skills in English and Hebrew.

## Preferred Qualifications
- Experience developing or researching cloud environments such as AWS, Azure, or Google Cloud.
- Familiarity with security aspects of Kubernetes, containers, and CI/CD.
- Familiarity with AI-assisted development tools such as Claude Code or similar.
- Familiarity with Burp Suite, nmap, Metasploit, Nuclei, or similar scanning tools.
- Published security research, exploits or proof-of-concepts, or contributions to open-source security tooling.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Information Security Manager](https://hotfix.jobs/jobs/ccc96673-5cad-40d0-a14b-bc1844e083a6) - Viz.ai - Tel Aviv, Israel
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Security Engineer, Security Incident Response Team - EMEA](https://hotfix.jobs/jobs/33cbe57c-bb91-44ff-8901-3cde1ac976a7) - GitLab - Remote

**Apply:** https://hotfix.jobs/jobs/bb443443-936e-4115-b157-d05e093e19f1
**Canonical:** https://hotfix.jobs/jobs/bb443443-936e-4115-b157-d05e093e19f1