- Home
- Jobs
- Threat & AI Research
- Threat Researcher

Threat Researcher at Wiz
Tel AvivFull-timeThreat & AI ResearchPosted about 1 month ago
Apply with PipelineAbout the Role
<div class="content-intro"><p>Come join the organization that is redefining security for the AI era. As one of the<a href="https://www.wiz.io/blog/100m-arr-in-18-months-wiz-becomes-the-fastest-growing-software-company-ever"> fastest-growing startups ever,</a> we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven<a href="https://www.g2.com/products/wiz-wiz/reviews"> track record of success</a> and a culture that values world-class talent. Not to mention, we're now<a href="https://cloud.google.com/blog/products/identity-security/google-completes-acquisition-of-wiz"> powered by Google</a>, meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation.</p>
<p>Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun!</p></div><p><strong><span data-markdown-start-index="383">Minimum qualifications</span></strong></p>
<ul>
<li><span data-markdown-start-index="410">5+ years of hands-on experience in security research, red-teaming, penetration testing, incident response, or vulnerability research.</span></li>
<li><span data-markdown-start-index="544">Strong understanding of network and application security, including core networking protocols (TCP/IP, DNS, TLS), web technologies, modern APIs, and real-world application- and network-layer exploitation techniques (e.g., OWASP API Security Top 10).</span></li>
<li><span data-markdown-start-index="795">Strong scripting and automation skills (using Python, Bash, or equivalent).</span></li>
<li><span data-markdown-start-index="872">Hands-on experience developing, customizing, using, or conducting research supporting vulnerability scanners (DAST / SAST / Network / Host scanners), writing detection rules, or building automated vulnerability and exploitability validation tools.</span></li>
<li><span data-markdown-start-index="1121">Strong sense of ownership and the ability to independently lead projects from research to delivery.</span></li>
<li><span data-markdown-start-index="1222">Strong writing and presentation skills in both English and Hebrew.</span></li>
</ul>
<p><strong><span data-markdown-start-index="1291">Preferred qualifications</span></strong></p>
<ul>
<li><span data-markdown-start-index="1320">Experience with developing or researching cloud environments (AWS, Azure, or GCP).</span></li>
<li><span data-markdown-start-index="1404">Familiarity with security aspects of Kubernetes, containers, and/or CI/CD.</span></li>
<li><span data-markdown-start-index="1480">Familiarity with AI-assisted development tools such as Claude Code or similar.</span></li>
<li><span data-markdown-start-index="1560">Familiar with network and application scanning tools (Burp Suite, nmap, Metasploit, Nuclei, or similar).</span></li>
<li><span data-markdown-start-index="1666">Published security research, exploits/PoCs, or contributed to open-source security tooling.</span></li>
</ul>
<p><strong><span data-markdown-start-index="1760">About the job<br></span></strong><br><span data-markdown-start-index="1775">As a <strong>Threat Researcher</strong> in Exposure & Risk Detection, you will drive research projects end-to-end to identify emerging threats, CVEs, and misconfigurations, assessing their real-world exploitability and customer impact. In this role, you will investigate cloud services, frameworks, and commonly deployed technologies to uncover new attack surfaces, and build automations to validate, benchmark, and monitor AI-driven detection capabilities at scale. You will collaborate closely with Product and R&D teams to transform research findings and attack methodologies into impactful product capabilities, directly shaping how our customers stay secure.</span></p>
<p><span data-markdown-start-index="1775"><span data-markdown-start-index="1657">Check out some of our recent research:</span></span></p>
<ul>
<li><span data-markdown-start-index="1775"><span data-markdown-start-index="1657"><a href="https://www.wiz.io/blog/red-agent-pov-ssrf">The Red Agent POV: How it Reasoned its Way to SSRF</a></span></span></li>
<li><span data-markdown-start-index="1775"><span data-markdown-start-index="1657"><a href="https://www.wiz.io/blog/spring-boot-actuator-misconfigurations">Under the Radar: Exploring Spring Boot Actuator Misconfigurations</a></span></span></li>
<li><span data-markdown-start-index="1775"><span data-markdown-start-index="1657"><a href="https://www.wiz.io/blog/beyond-cves-the-exploitation-of-everyday-misconfigurations">Beyond CVEs: The Exploitation of Everyday Misconfigurations</a></span></span></li>
<li><span data-markdown-start-index="1775"><span data-markdown-start-index="1657"><a href="https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive">React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182</a></span></span></li>
</ul>
<p><strong><span data-markdown-start-index="2424">Responsibilities</span></strong></p>
<ul>
<li><span data-markdown-start-index="2444">Research emerging threats, CVEs, and misconfigurations to assess real-world exploitability and customer impact.</span></li>
<li><span data-markdown-start-index="2557">Design, build, and test detection rules and scanning logic for exposed and vulnerable assets.</span></li>
<li><span data-markdown-start-index="2652">Build automations to validate, benchmark, and monitor AI-driven detection capabilities at scale.</span></li>
<li><span data-markdown-start-index="2750">Investigate cloud services, frameworks, and commonly deployed technologies to uncover new attack surfaces.</span></li>
<li><span data-markdown-start-index="2858">Analyze large-scale scan results to identify and prioritize meaningful risks.<br></span></li>
<li><span data-markdown-start-index="2937">Drive research projects end-to-end, from initial idea to production-ready detection.<br></span></li>
<li><span data-markdown-start-index="3023">Collaborate closely with Product and R&D teams to transform research findings and attack methodologies into impactful product capabilities.</span></li>
</ul>
<p> </p><div class="content-conclusion"><p><em><span class="TextRun SCXW149741735 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW149741735 BCX0">Applicants must have the legal right to work in the country where the position is based, </span><span class="NormalTextRun SCXW149741735 BCX0">without the need for</span> <span class="NormalTextRun SCXW149741735 BCX0">visa </span><span class="NormalTextRun SCXW149741735 BCX0">sponsorship.</span> <span class="NormalTextRun SCXW149741735 BCX0">This</span><span class="NormalTextRun SCXW149741735 BCX0"> role does not offer</span> <span class="NormalTextRun SCXW149741735 BCX0">visa</span></span> <span class="TextRun SCXW149741735 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW149741735 BCX0">sponsorship</span><span class="NormalTextRun SCXW149741735 BCX0">.</span></span></em></p>
<p>Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. </p>
<p>By submitting your application, you acknowledge that Wiz will process your personal data in accordance with <a href="https://www.wiz.io/legal/privacy" target="_blank">Wiz's Privacy Policy.</a></p></div>