Daylight Security

Senior Security Engineer

Daylight Security Tel Aviv, Tel-Aviv District, Israel

Computer and Network Security · 51-200 employees

Jul 22
Remote security Mid (2-5 yrs) Full-time Israel
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will lead investigations, build detection logic as code, and automate response workflows across cloud and network environments. Additionally, you will collaborate with platform and AI teams to integrate detection logic and support incident response efforts.

What they look for

Detection Engineering Incident Response Go Cloud Security AWS GCP Azure Digital Forensics Threat Hunting Automation CI/CD MITRE ATT&CK Threat Modeling Behavioral Detection Security Operations

Requirements

Candidates must have at least 3 years of experience in detection engineering, incident response, or blue team roles. Strong proficiency in automation, cloud-native security, and digital forensics is required.

Full description

Daylight is a security services company delivering Managed Agentic Security Services (MASS), including MDR, threat hunting, security data lake, and more, through a fundamentally different architecture than traditional security services providers.

Daylight's architecture combines an agentic platform that runs the full cycle from detection to response with security experts from IR and threat hunting backgrounds. The platform collects identity and business context across systems to investigate alerts and continuously learns your environment. Security experts validate decisions, feed insights into the platform, optimize detections, and take over in case of an incident.

The result: security teams move from firefighting to strategic work.

We're looking for a Senior Security Engineer to join our globally distributed, high-impact security engineering team. You will design and implement detection logic, investigate alerts, and automate response mechanisms. As an early hire, you'll work closely with our platform and AI teams to shape how autonomous threat detection and response is built and delivered at scale.

Responsibilities:

  • Lead Investigations: Triage, analyze, and respond to alerts across cloud, endpoint, and network environments with automation-first principles.
  • Build Detections: Write detection logic and behavioral rules as code that is clear, testable, and scalable.
  • Automate Response Workflows: Develop Go-based automation for enrichment, containment, and remediation playbooks.
  • Define Detection-as-Code Practices: Implement a detection and response framework with strong engineering fundamentals (testing, CI/CD, version
  • control).
  • Collaborate Across Functions: Partner with platform and AI teams to integrate detection logic into the broader Daylight stack.
  • Support DFIR: Participate in incident investigations and post-incident reviews; DFIR skills (memory, disk, or cloud forensics) are a strong plus.

Requirements:

  • Security Operations Experience: 3+ years in detection engineering, incident response, or blue team roles.
  • Automation Mindset: You automate what others manually repeat. Experience building or integrating automated response systems is key.
  • Cloud-Native Awareness: Familiarity with detecting and responding to threats in cloud environments (AWS, GCP, or Azure).
  • DFIR Skills: Practical experience in digital forensics and incident response — logs, memory, containers, cloud.
  • Threat-Informed Thinking: Comfort with attacker tactics and techniques (MITRE ATT&CK, behavioral detection, threat modeling).

Similar roles