SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Wiz is a rapidly growing cloud and AI security platform trusted by over 65% of the Fortune 100. The company recently became part of Google, leveraging Google's Threat Intelligence and Security Operations to enhance its AI-powered detection and prevention capabilities.
As a Threat Researcher in the Exposure & Risk Detection team, you will drive security research projects end-to-end to identify emerging threats, CVEs, and misconfigurations while assessing their real-world exploitability and customer impact. You will investigate cloud services, frameworks, and commonly deployed technologies to uncover new attack surfaces and build automations to validate, benchmark, and monitor AI-driven detection capabilities at scale.
Key responsibilities include:
- Researching emerging threats, CVEs, and misconfigurations to assess exploitability and customer impact
- Designing, building, and testing detection rules and scanning logic for exposed and vulnerable assets
- Building automations to validate, benchmark, and monitor AI-driven detection capabilities at scale
- Investigating cloud environments, container orchestration, and CI/CD pipelines for security vulnerabilities
- Collaborating with Product and R&D teams to transform research findings into impactful product capabilities
- Publishing security research and contributing to the broader security community
You will need 5+ years of hands-on experience in security research, red-teaming, penetration testing, incident response, or vulnerability research. Strong understanding of network and application security (TCP/IP, DNS, TLS, web technologies, APIs, OWASP Top 10) is essential. You must have strong scripting and automation skills (Python, Bash), hands-on experience with vulnerability scanners (DAST/SAST), and the ability to independently lead projects from research to delivery. Fluency in both English and Hebrew is required.
Preferred qualifications include cloud security experience (AWS, Azure, GCP), familiarity with Kubernetes and container security, knowledge of AI-assisted development tools, experience with security scanning tools (Burp Suite, nmap, Metasploit, Nuclei), and published security research or open-source contributions.