Security Automation & Detection Engineer
Description
MER Group is looking for a Security Engineer with a developer mindset— someone who delivers results through code and automation rather than repetitive manual work. The organization operates a full Microsoft 365 E5 environment, a SIEM and SOC, a Fortinet security fabric, and a multi-site infrastructure spanning Israel and international locations. This position comes with a genuine mandate to deliver: authority to build, a dedicated training budget, a dedicated development environment, an organization-owned code repository, and access to approved enterprise AI tools.
Key Responsibilities
- Maximize the end-to-end value of the Microsoft 365 E5 security stack across identity, endpoints, cloud, and email.
- Build process automations using Microsoft Graph API, Logic Apps, and scripts, including employee lifecycle management, procurement and vendor approval, and request classification and routing.
- Integrate large language models (LLMs) as system components for classification, document information extraction, and summarization.
- Perform detection engineering: write and tune detection rules and reduce false positives.
- Build automated response playbooks using a controlled, phased approach.
- Lead the consolidation of overlapping tools and reduce licensing costs.
- Define security requirements for new systems and implementations, including identity, logging, permissions, and API availability.
Requirements
Mandatory Requirements
Experience: 4+ years in Security Engineering or Platform Engineering. Environment: 2+ years of hands-on experience with Microsoft 365 and Entra ID. Development: PowerShell and Python at a tool-building level—not one-off scripting. Integration: Experience integrating at least three systems using REST APIs and Microsoft Graph. Automation: Experience building multi-step workflows with error handling, idempotency, and logging. Identity and Access: Strong knowledge of RBAC, least privilege, service accounts, and secrets management. Working Practices: Experience with Git, version control, and written technical documentation. Languages: Hebrew and technical English.
Significant Advantages
Experience with Microsoft Defender XDR or Microsoft Sentinel, including detection-rule and playbook development. Experience integrating LLMs into production systems—not merely using chat-based tools. Experience implementing DLP or cloud application controls. Background in networking and Fortinet firewalls. Relevant certifications: SC-200, SC-300, or AZ-500.
Every role in the library, ranked against your CV.
Rewritten from your real, matching experience for the job you pick.
Your whole pipeline in one place, with a fresh move every morning.