Senior SecOps Engineer
Tel Aviv-Yafo, Israel
At Semperis, our mission is to be a Force for Good. Starting with being a great place to work. We believe that when people feel valued, supported, and empowered, they do their best work. That’s why we focus on creating an employee experience rooted in purpose, growth, and balance. Semperis has been recognized as one of America’s Fastest-Growing Cybersecurity Companies by the Inc. 5000, a DUNS 100 Top Startup to Work For, and a multi-year Inc. Best Workplace awardee.
Semperis is looking for a hands-on Senior Security Operations Engineer who wants to do more than monitor alerts and hand off tickets. In this role, you will have the rare opportunity to identify security problems, understand their root causes, and work directly with the teams responsible for fixing them.
You will strengthen Semperis’ threat detection, incident response, vulnerability management, and cloud security operations through a combination of investigation, engineering, and automation. You will design and tune detections, lead investigations and response efforts, prioritize and route vulnerabilities and CSPM/CWP findings, improve security telemetry, and build capabilities that reduce manual effort and help the organization respond faster.
This is an engineering-focused SecOps role- not a traditional alert-monitoring position. You will be expected to turn operational insights into durable improvements: better detections, stronger controls, cleaner telemetry, streamlined workflows, and measurable risk reduction. You will work closely with Cloud Security, Identity and IT, AppSec, Product Engineering, Platform Engineering, GRC, and service owners to secure Semperis’ corporate and cloud environments.
You will also help shape how Semperis secures AI-enabled tools, agents, and automation as they become part of the way we work. If you enjoy moving from signal to solution—and want the autonomy and cross-functional access to make security improvements stick—this role is built for you.
What You Will Do
Threat Detection and Incident Response
Operate and improve SIEM, EDR, cloud, identity, email, and security monitoring capabilities.
Develop and tune detection rules, analytics, dashboards, alert routing, and investigation playbooks.
Investigate security alerts and incidents, including scoping, evidence collection, containment, remediation coordination, and recovery tracking.
Support high-severity incident response and contribute to post-incident improvements.
Vulnerability and Cloud Security Operations
Lead SecOps triage of vulnerability, exposure, endpoint patching, and CSPM/CWP findings across endpoints, third-party applications, cloud environments, and other technology assets.
Validate findings, assess risk using business and technical context, assign ownership, establish remediation priorities, track patching and other corrective actions, manage exceptions, and verify closure.
Partner with Cloud Security on posture-management rules, alert tuning, cloud logging, and recurring misconfiguration analysis.
Define monitoring and detection requirements for new cloud services, SaaS capabilities, and significant architecture changes.
Monitor privileged activity, develop detections for risky identity, endpoint, and cloud administration behavior, and support endpoint-hardening efforts focused on least privilege, reduce local-administrator access, and secure configuration.
Automation, Metrics, and Engineering
Build scripts, integrations, workflows, and playbooks that improve triage, enrichment, notification, containment, remediation tracking, and reporting.
Monitor log-source and connector health and improve telemetry coverage across cloud, identity, endpoint, SaaS, and network sources.
Maintain metrics covering MTTD, MTTR, alert quality, incident trends, detection coverage, vulnerability risk, CSPM/CWP exposure, and remediation performance.
Maintain clear runbooks, technical documentation, and operational records.
AI Security, Guardrails, and Monitoring
Assess AI tools, agents, plugins, and MCP integrations for data access, identity, execution, retention, and supply chain risk.
Design and operate guardrails for least-privilege identities, read-only-by-default connectors, sandboxed execution, network-egress restrictions, and human approval before irreversible actions.
Monitor prompts, retrieved content, model outputs, tool calls, agent actions, and administrative changes for prompt injection, indirect prompt injection, sensitive data exposure, unsafe code, abnormal behavior, and policy violations.
Onboard AI audit and runtime telemetry into the SIEM and build detections and response playbooks for rogue tools, connector misuse, suspicious tool calls, data exfiltration, and agent compromise.
Run controlled pilots and adversarial tests, measure false positives and user impact, and promote controls from monitor or flag to block based on evidence.
Cross-Functional Security Engineering
Translate security findings into clear actions, owners, priorities, and deadlines.
Provide practical security guidance to engineering and IT teams.
Mentor analysts and engineers through technical reviews, incident walkthroughs, and knowledge sharing.
Balance risk, engineering effort, availability, customer impact, and business priorities when recommending actions.
What You Will Bring
5+ years of hands-on experience in Security Operations, Security Engineering, Detection Engineering, Incident Response, or related field.
Strong experience with SIEM operations, detection engineering, alert triage, investigation, and incident response.
Practical experience with vulnerability management, endpoint patching and hardening, CSPM/CWP, cloud security posture, or attack-surface analysis.
Experience with Azure, AWS, or comparable cloud environments; multi-cloud experience is a plus.
Strong understanding of identity and access risks, privileged activity, risky sign-ins, and cloud administration.
Understanding modern AI security risks, including prompt injection, indirect prompt injection, excessive agency, data leakage, tool misuse, and AI supply-chain risk.
Ability to query and analyze security data using KQL, SQL, or equivalent language.
Ability to automate using Python, PowerShell, JavaScript, or a comparable language, including API integration.
Experience with endpoint, email, SaaS, cloud, and identity security telemetry.
Strong technical writing and communication skills, including the ability to work with distributed, cross-functional teams.
Ability to work independently, make sound decisions under pressure, and manage competing priorities.
Preferred Qualifications
Experience with Microsoft Sentinel, Microsoft Defender, Log Analytics, SOAR, or comparable platforms.
Familiarity with MITRE ATT&CK, Sigma, YARA, threat hunting, or detection testing.
Experience with infrastructure-as-code, CI/CD, containers, or Kubernetes security.
Experience securing LLMs, AI agents, MCP or plugin ecosystems, AI-enabled SaaS tools, or AI runtime environments is a plus.
Experience with endpoint security capabilities such as endpoint privilege management, privileged access workstations, application control, and other least-privilege or attack-surface-reduction measures.
Experience supporting SOC 2, ISO 27001, NIST, FedRAMP, or similar assurance requirements.
Relevant security certifications or equivalent practical experience.
Success Measures
Improved detection coverage and alert quality across priority security signals.
Consistent, risk-based triage and remediation of vulnerability, endpoint patching, and CSPM/CWP findings, with measurable improvement in patch compliance and endpoint-hardening coverage.
Reduced time to detect, investigate, contain, and recover from security incidents.
Increased automation and reduced manual effort in recurring SecOps workflows.
Reliable operational metrics, current playbooks, and measurable improvement actions.
Strong execution across SecOps, Cloud Security, Identity and IT, AppSec, and Engineering teams.
AI tools and agent workflows operate with risk-based guardrails, auditable telemetry, actionable detections, and clear escalation paths.
Controlled AI pilots demonstrate the least privilege, sandboxing, human approval, and safe handling of sensitive data before wider rollout.
#LI-TI1
Why Join Semperis?
You’ll be part of a global team on the front lines of cybersecurity innovation. At Semperis, we celebrate curiosity, integrity, and people who take initiative. If you’re someone who sees the glass as half full, embraces challenges as growth opportunities, and values a healthy balance between work and life—we’d love to meet you.
**Semperis maintains office locations in several cities across the globe. Where the job description specifies a required location, candidates will follow our hybrid work model. This includes working up to three days per week and remotely the remaining days.