All jobs

Security Automation & Detection Engineer

Mer Group

Where
Or Yehuda, Israel, on-site
Language, from the listing
Mentions Hebrew. Mentions English
Dates
Found 27 Sept 2026
Last checked on the employer's site
5 h ago (6 Oct 2026)
Source
Employer career page (Comeet)

The full listing

Description MER Group is looking for a Security Engineer with a developer mindset—someone who delivers results through code and automation rather than repetitive manual work. The organization operates a full Microsoft 365 E5 environment, a SIEM and SOC, a Fortinet security fabric, and a multi-site infrastructure spanning Israel and international locations. This position comes with a genuine mandate to deliver: authority to build, a dedicated training budget, a dedicated development environment, an organization-owned code repository, and access to approved enterprise AI tools. Key Responsibilities: • Maximize the end-to-end value of the Microsoft 365 E5 security stack across identity, endpoints, cloud, and email. • Build process automations using Microsoft Graph API, Logic Apps, and scripts, including employee lifecycle management, procurement and vendor approval, and request classification and routing. • Integrate large language models (LLMs) as system components for classification, document information extraction, and summarization. • Perform detection engineering: write and tune detection rules and reduce false positives. • Build automated response playbooks using a controlled, phased approach. • Lead the consolidation of overlapping tools and reduce licensing costs. • Define security requirements for new systems and implementations, including identity, logging, permissions, and API availability. Requirements Mandatory Requirements: • Experience: 4+ years in Security Engineering or Platform Engineering. • Environment: 2+ years of hands-on experience with Microsoft 365 and Entra ID. • Development: PowerShell and Python at a tool-building level—not one-off scripting. • Integration: Experience integrating at least three systems using REST APIs and Microsoft Graph. • Automation: Experience building multi-step workflows with error handling, idempotency, and logging. • Identity and Access: Strong knowledge of RBAC, least privilege, service accounts, and secrets management. • Working Practices: Experience with Git, version control, and written technical documentation. • Languages: Hebrew and technical English. Significant Advantages: • Experience with Microsoft Defender XDR or Microsoft Sentinel, including detection-rule and playbook development. • Experience integrating LLMs into production systems—not merely using chat-based tools. • Experience implementing DLP or cloud application controls. • Background in networking and Fortinet firewalls. • Relevant certifications: SC-200, SC-300, or AZ-500.