← Back to jobs
N

Senior Defensive Cybersecurity Researcher

Novartis·Israel·
HybridFull-timeSecurity EngineeringPharmaceuticals

Join an internal security research team investigating threat actors, improving enterprise defenses, and supporting incident response, monitoring, and detection operations. The role is based in Tel Aviv with three office days per week.

Responsibilities

  • Hunt through security signals to identify emerging threats, analyze malicious activity, and extract indicators of compromise
  • Conduct threat-actor investigations using behavioral analysis, signatures, threat intelligence, and anomalous log data
  • Provide expert investigative support for complex security incidents
  • Perform malware reverse engineering, memory forensics, and disk forensics
  • Improve alert catalogs and detection infrastructure based on incident and malware analysis
  • Develop security dashboards and reports with security operations teams
  • Research AI-specific security risks and translate findings into defensive guidance and detection rules
  • Operationalize threat intelligence and contribute indicators, tactics, techniques, and adversary profiles to intelligence pipelines
  • Produce detailed technical reports for malware and threat-hunting investigations

Requirements

  • At least 5 years of experience in incident response, CERT operations, or malware investigations
  • Strong understanding of the cyber attack lifecycle and attacker objectives
  • Experience securing Active Directory and Entra ID/Azure AD, including attack-path analysis, tiering, and Conditional Access
  • Understanding of AI security risks, including adversarial machine learning, prompt injection, data poisoning, shadow AI, and AI-assisted threats
  • Experience with SOC teams, detection engineering, alert tuning, escalation workflows, and high-severity incident response
  • Experience working with cyber threat intelligence teams and operationalizing intelligence products
  • Familiarity with red-team operations, Wireshark, Cobalt Strike, and the nation-state threat landscape
  • Advanced scripting skills in Python, Perl, Ruby, or similar languages
  • Strong written and verbal communication skills, with the ability to work independently and collaboratively

Nice to have

  • Relevant technical security certification such as GIAC, EC-Council, or Offensive Security

Benefits

  • Reasonable accommodation during the recruitment process
  • Professional and personal development support

Relevance

More opportunities

Similar jobs

The newest open roles in Security Engineering.

Questions, answered

Frequently asked questions