Skip to content

Open nowPosted 24 hours ago

Senior Security Analyst (MDR)

Artemis21 open roles

Where
Israel
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Analyst (MDR)Artemis · Israel
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Artemis's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 24 hours ago

The posting

Artemis is building the future of AI-driven defense - helping companies detect and defend themselves effectively in an era where AI is fighting AI on the cyber battlefield.

We're backed by First Round Capital, Brightmind, and a group of the cybersecurity industry's most prominent Operators.

Our founders, Shachar (ex-Palo Alto Networks, AWS, Demisto) and Dan (ex-Abnormal Security, Twitter) have previously built, launched, and scaled cybersecurity products loved and trusted by tens of thousands of customers, and have the customer, technology, and security know-hows to deliver this vision.

Our exceptionally strong team includes software engineers, AI researchers, security engineers, and product designers hailing from Google, Abnormal AI, Wiz, Meta, AWS, CERN, SentinelOne, and more.

We are growing our team and looking for passionate builders to join us and support our expanding customer base.

Job Overview

We're looking for a Senior Security Analyst to join Apollo, the managed detection and response service Artemis delivers on top of its platform, as one of its founding analysts. Apollo analysts are the senior security minds our customers count on: the people who determine what a threat really is, what it means for that business, and what happens next. You will be one of the few who establish how that work gets done before the team scales.

The Artemis platform is built to give you the strongest possible starting position. Detections are written for each customer's environment, cases arrive with the investigation done and the evidence assembled, response actions come staged and impact-checked, and the platform already holds a living picture of every user, device, account, and AI agent in the environment. The routine work that fills most analysts' days is handled, which means your day is spent on the work that actually calls for an expert.

You will lead investigations across cloud, identity, endpoint, and SaaS, own the decision on the cases you take, guide customers through what matters and why, and carry incidents from first signal to a clean resolution. Because you work across the full range of environments we protect, you will build fluency in modern attacker tradecraft far faster than a single environment allows. And your reach extends well past the case. You sit with the engineers building the platform, so what you learn in one investigation can ship into the product and go on protecting every customer we defend.

Responsibilities

- Own the investigation and the decision - Take cases from pickup to close: establish what happened, determine the impact and blast radius, set the verdict and severity, and put your reasoning on the record. You are the one who makes the call.

- Investigate with real depth - Reconstruct attacker activity across identity, cloud, endpoint, and SaaS telemetry: initial access, lateral movement, persistence, and exfiltration. Pair AI-assisted investigation with hands-on log analysis, and know which one to lean on for what.

- Drive response, with the customer in control - Recommend and execute containment within each customer's authorized limits, with every action impact-previewed and reversible before it runs. Where the decision belongs to the customer, bring them the recommended action, its full impact, and a clear next step.

- Move at the speed the threat demands - Work by risk, acknowledge and reach a verdict inside the response targets for each severity, and keep the most consequential work moving first.

- Be the security partner customers trust - You are the voice the customer hears. Your summaries, your reasoning, and your final analysis reach them in your own words.

- Hunt what nothing has alerted on yet - Run hypothesis-driven and AI-assisted threat hunts across customer environments, and turn what you surface into new cases and new detections.

- Help design the service, not just deliver it - Founding analysts shape what Apollo becomes: the investigative standards, the response workflows, the reporting customers receive, and the console the team works in. You will be in the room where those decisions get made, and the improvements you argue for get built.

- Make the platform sharper - Your verdicts, your reasoning, and the patterns you recognize feed straight into detection engineering and product, so a problem you solve once gets engineered away rather than worked twice.

Qualifications

- 4+ years of hands-on security operations experience in a SOC, MSSP, or MDR environment, at a senior or Tier 3 level where the investigation ended with your decision

- Proven investigation depth across identity (Okta, Entra ID), cloud (AWS, Azure, GCP), endpoint (EDR), and SaaS (Microsoft 365, Google Workspace)

- Fluency in attacker tactics, techniques, and procedures (MITRE ATT&CK) and how they present in real telemetry

- Rigor about evidence: you know what separates suspicious from confirmed, and exactly what you need to see to close that gap

- Hands-on experience working with AI-assisted investigation or automation, and the judgement to know where it is strong and where it needs you

- Strong customer-facing instincts. You have walked the people affected by a live security situation through what is happening and what to do about it

- Excellent written communication. What you write reaches the customer as you wrote it

- A high personal bar for the quality of your analysis, and a preference for being measured on it

- Comfortable working a defined shift as analyst coverage expands to 24x7

Bonus

- Experience in a multi-tenant MDR or MSSP practice, working across several customer environments

- Experience writing or tuning detection rules (Sigma, YARA-L, SPL, KQL, or similar)

- Incident command experience, including customer executive briefings

- Dedicated threat hunting or DFIR background

- Daily hands-on use of AI or agentic coding tools to build your own tooling

Why Work at Artemis?

- Join early enough to shape it. A founding analyst leaves fingerprints on all of it: how the service is designed, the standards the team holds, and what customers receive. The way you work a case becomes the standard the analysts who follow you learn from.

- Make a real world impact. Every case you work and every call you make protects a real company and the people who depend on it. You are not working theoretical security problems, you are on the front lines of active defense, with customers who rely on the quality of your judgement.

- Range you cannot get anywhere else. You work across the full set of environments we protect and the full spectrum of attacker behavior we see, so a quarter here builds experience that years inside one environment cannot.

- Be challenged to be better than ever before. Our team includes some of the smartest and most driven people in the world. We guarantee you will learn more in 1 year here than 10 years in another place.

- Push the boundaries of technology. The platform handles the detection, investigation, and prioritization that consume most analysts' days, so your time goes to judgement, response, and the customer. You will help define what an AI-native SOC actually looks like.

- Innovative culture. We obsess about customers, move fast with high quality, and value open communication, mentorship and learning. You will have the autonomy to drive investigations, shape the platform, and own outcomes, not just follow a runbook.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Artemis's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Artemis's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Artemis's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.