Senior SecOps Engineer

Semperis Tel Aviv, Israel Publicerat 11 augusti 2026
full_timeonsitesenior
At Semperis, our mission is to be a Force for Good. Starting with being a great place to work. We believe that when people feel valued, supported, and empowered, they do their best work. That’s why we focus on creating an employee experience rooted in purpose, growth, and balance. Semperis has been recognized as one of America’s Fastest-Growing Cybersecurity Companies by the Inc. 5000, a DUNS 100 Top Startup to Work For, and a multi-year Inc. Best Workplace awardee. Semperis is looking for a hands-on Senior Security Operations Engineer who wants to do more than monitor alerts and hand off tickets. In this role, you will have the rare opportunity to identify security problems, understand their root causes, and work directly with the teams responsible for fixing them. You will strengthen Semperis’ threat detection, incident response, vulnerability management, and cloud security operations through a combination of investigation, engineering, and automation. You will design and tune detections, lead investigations and response efforts, prioritize and route vulnerabilities and CSPM/CWP findings, improve security telemetry, and build capabilities that reduce manual effort and help the organization respond faster. This is an engineering-focused SecOps role- not a traditional alert-monitoring position. You will be expected to turn operational insights into durable improvements: better detections, stronger controls, cleaner telemetry, streamlined workflows, and measurable risk reduction. You will work closely with Cloud Security, Identity and IT, AppSec, Product Engineering, Platform Engineering, GRC, and service owners to secure Semperis’ corporate and cloud environments. You will also help shape how Semperis secures AI-enabled tools, agents, and automation as they become part of the way we work. If you enjoy moving from signal to solution—and want the autonomy and cross-functional access to make security improvements stick—this role is built for you. What You Will Do Threat Detection and Incident Response - Operate and improve SIEM, EDR, cloud, identity, email, and security monitoring capabilities. - Develop and tune detection rules, analytics, dashboards, alert routing, and investigation playbooks. - Investigate security alerts and incidents, including scoping, evidence collection, containment, remediation coordination, and recovery tracking. - Support high-severity incident response and contribute to post-incident improvements. Vulnerability and Cloud Security Operations - Lead SecOps triage of vulnerability, exposure, endpoint patching, and CSPM/CWP findings across endpoints, third-party applications, cloud environments, and other technology assets. - Validate findings, assess risk using business and technical context, assign ownership, establish remediation priorities, track patching and other corrective actions, manage exceptions, and verify closure. - Partner with Cloud Security on posture-management rules, alert tuning, cloud logging, and recurring misconfiguration analysis. - Define monitoring and detection requirements for new cloud services, SaaS capabilities, and significant architecture changes. - Monitor privileged activity, develop detections for risky identity, endpoint, and cloud administration behavior, and support endpoint-hardening efforts focused on least privilege, reduce local-administrator access, and secure configuration. Automation, Metrics, and Engineering - Build scripts, integrations, workflows, and playbooks that improve triage, enrichment, notification, containment, remediation tracking, and reporting. - Monitor log-source and connector health and improve telemetry coverage across cloud, identity, endpoint, SaaS, and network sources. - Maintain metrics covering MTTD, MTTR, alert quality, incident trends, detection coverage, vulnerability risk, CSPM/CWP exposure, and remediation performance. - Maintain clear runbooks, technical documentation, and operational records. AI Security, Guardrails, and Monitoring - Assess AI tools, agents, plugins, and MCP integrations for data access, identity, execution, retention, and supply chain risk. - Design and operate guardrails for least-privilege identities, read-only-by-default connectors, sandboxed execution, network-egress restrictions, and human approval before irreversible actions. - Monitor prompts, retrieved content, model outputs, tool calls, agent actions, and administrative changes for prompt injection, indirect prompt injection, sensitive data exposure, unsafe code, abnormal behavior, and policy violations. - Onboard AI audit and runtime telemetry into the SIEM and build detections and response playbooks for rogue tools, connector misuse, suspicious tool calls, data exfiltration, and agent compromise. - Run controlled pilots and adversarial tests, measure false positives and user impact, and promote controls from monitor or flag to block based on evidence. Cross-Functional Security Engineering - Translate security findings into clear actions, owners, priorities, and deadlines. - Provide practical security guidance to engineering and IT teams. - Mentor analysts and engineers through technical reviews, incident walkthroughs, and knowledge sharing. - Balance risk, engineering effort, availability, customer impact, and business priorities when recommending actions. What You Will Bring - 5+ years of hands-on experience in Security Operations, Security Engineering, Detection Engineering, Incident Response, or related field. - Strong experience with SIEM operations, detection engineering, alert triage, investigation, and incident response. - Practical experience with vulnerability management, endpoint patching and hardening, CSPM/CWP, cloud security posture, or attack-surface analysis. - Experience with Azure, AWS, or comparable cloud environments; multi-cloud experience is a plus. - Strong understanding of identity and access risks, privileged activity, risky sign-ins, and cloud adminis

Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.

Visa jobbet och ansök

Ursprunglig annons: jobs.ashbyhq.com