AYN

Cloud Security Researcher

Upwind Security · Ramat Gan, Tel Aviv District · hybrid

Upwind is a next-generation cloud security platform that uses runtime context to identify and prioritize the risks that actually matter. Our eBPF-powered sensors and agentless posture discovery give us a unique view of cloud environments- from the first commit to the running workload

We're looking for a Cloud Security Researcher to join the platform research team. This is a chance to shape the platform end to end- expand what it sees, define how it thinks about risk, and build the AI systems that act on what it finds

What You'll Do

- Integrate new systems and domains- from cloud to shift-left tooling and AI providers- model their data, analyze and enrich it with context from across the platform to generate meaningful insights

- Map risk vectors, build threat models, and translate them into actionable posture recommendations

- Define how the platform should reason about risk, advancing posture management beyond static rules toward dynamic approaches like graph traversal and reachability analysis

- Shape how AI is applied on top of the platform's findings - from agentic systems for insight, context analysis, and remediation to smarter prioritization and prevention

- Lead research initiatives end-to-end, working with product and engineering to turn them into shipped capabilities

Requirements- 5+ years in security research, cloud security, or DevSecOps

- Hands-on experience with at least one major cloud provider (AWS, GCP, or Azure), including its identity and data services

- Strong understanding of modern DevOps environments: CI/CD pipelines, Infrastructure-as-Code, containers, and Kubernetes

- Hands-on coding skills (e.g., Python) and comfort with query languages (e.g., SQL) and reasoning about data flows.

- Ability to own research initiatives end-to-end in a fast-moving environment

- Excellent written and spoken English

Advantages

- Experience building AI/LLM-based or agentic systems, or securing AI/ML pipelines

- Experience with DSPM, data classification, or data security tooling

- Background in supply chain security (SBOM, dependency and artifact security)

- Open-source contributions, published research, or conference talks

Apply on the employer’s site