Platform Security Researcher

Location
Ramat Gan
Workplace
On-site

About this role

Upwind is a next-generation cloud security platform that uses runtime context to identify and prioritize the risks that actually matter. Our eBPF-powered sensors and agentless posture discovery give us a unique view of cloud environments- from the first commit to the running workload

We're looking for a Cloud Security Researcher to join the platform research team. This is a chance to shape the platform end to end- expand what it sees, define how it thinks about risk, and build the AI systems that act on what it finds

What You'll Do

  • Integrate new systems and domains- from cloud to shift-left tooling and AI providers- model their data, analyze and enrich it with context from across the platform to generate meaningful insights
  • Map risk vectors, build threat models, and translate them into actionable posture recommendations
  • Define how the platform should reason about risk, advancing posture management beyond static rules toward dynamic approaches like graph traversal and reachability analysis
  • Shape how AI is applied on top of the platform's findings - from agentic systems for insight, context analysis, and remediation to smarter prioritization and prevention
  • Lead research initiatives end-to-end, working with product and engineering to turn them into shipped capabilities

Requirements

  • 5+ years in security research, cloud security, or DevSecOps
  • Hands-on experience with at least one major cloud provider (AWS, GCP, or Azure), including its identity and data services
  • Strong understanding of modern DevOps environments: CI/CD pipelines, Infrastructure-as-Code, containers, and Kubernetes
  • Hands-on coding skills (e.g., Python) and comfort with query languages (e.g., SQL) and reasoning about data flows.
  • Ability to own research initiatives end-to-end in a fast-moving environment
  • Excellent written and spoken English

Advantages

  • Experience building AI/LLM-based or agentic systems, or securing AI/ML pipelines
  • Experience with DSPM, data classification, or data security tooling
  • Background in supply chain security (SBOM, dependency and artifact security)
  • Open-source contributions, published research, or conference talks

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?