Cloud Security Researcher
Location: Tel Aviv-Yafo, Tel Aviv-Yafo, Israel
Description
About Us
Act Security is an action-first cloud security platform built for the AI era.
For years, organizations have piled up access they never use. That debt was survivable when attacks moved at human speed. It isn’t anymore. AI now finds and exploits access paths faster than any team can triage them, and AI agents are operating inside production systems with real autonomy to act. Access has become the attack surface, and chasing findings one at a time is a losing game.
Act systematically shrinks the access surface across your cloud, enforcing deterministic boundaries on what people, workloads, and AI agents can reach. We reason across identity, network, and AI access together — the three control planes that decide what anything can touch — and we enforce through the cloud-native controls you already own. No agents, nothing new to deploy, nothing taken offline. The result is a cloud that’s structurally harder to attack and a security posture that holds between audits instead of quietly eroding.
We’re early-stage, well-funded, and moving fast – built by repeat security operators who previously created Medigate (acquired by Claroty). If you want to build something that matters from the ground up and ship to production within days, this is the place.
Our Culture
We live by three values: Win, Learn, Have Fun. We play to win- we set ambitious goals and hold ourselves to high standards. We learn constantly- from customers, from each other, and from our mistakes. And we have fun doing it: we believe great work happens when people enjoy working together.
About the Role
We’re looking for a Cloud Security Researcher to join our Research team and drive the technical core of our platform: understanding how access really works- and really breaks- across AWS, Azure, GCP, and the cloud-adjacent technologies built on top of them.
This is curiosity-driven security research. You’ll dig into how cloud providers actually behave, uncover the implicit and undocumented mechanics that create real risk, find non-obvious access paths and privilege-escalation routes, and turn those findings into the detection logic, policies, and product capabilities our customers rely on. Your research won’t sit in a slide deck- it ships.
What You’ll Do
- Research how identity and network access work across AWS, Azure, and GCP- IAM, trust policies, SCPs/RCPs, permission boundaries, RBAC, VNet peering, Private Link, service endpoints, cross-account and cross-tenant paths- and uncover the behaviors and misconfigurations that lead to real exposure.
- Extend that research into additional cloud providers and the cloud-adjacent technologies layered on top- Kubernetes and container platforms, infrastructure-as-code, CI/CD pipelines, SaaS applications, identity providers, and secrets management- wherever access and risk cross boundaries.
- Research how AI is reshaping cloud access- the AI agents, workloads, and identities that now request and hold permissions- and how to secure the access sprawl that comes with them.
- Analyze large sets of cloud configuration and access data, modeling access paths in our graph to surface privilege escalation, lateral movement, and unintended reachability.
- Translate research into product: detection logic, policy and guardrail capabilities, and risk-classification frameworks that work against real customer environments.
- Prototype AI- and LLM-powered approaches that scale your research- automating analysis, surfacing risk, and generating policy and remediation guidance.
- Validate findings against live cloud environments and help shape new detections from what you uncover.
- Track the cloud threat landscape- new services, provider changes, public research, and real-world attack techniques- and feed it back into the roadmap.
- Partner closely with Product and Engineering to get findings into production, and represent the research externally through blogs, talks, and the security community.
Requirements:
- 3+ years of experience in cybersecurity, security research, or data analysis- the exact domain matters less than sharp analytical instincts and real curiosity about how systems work.
- Hands-on experience with at least one major cloud (AWS, Azure, or GCP) is a strong plus- and if cloud is newer to you, a genuine appetite to go deep on it.
- A solid grasp of security fundamentals: identity and access, network security, or how attackers find and exploit weaknesses.
- A track record of investigative, analytical work- digging into how things behave, finding patterns in data, and surfacing non-obvious findings.
- Strong sense of ownership, clear communication, and the ability to translate findings into real-world impact.
- Startup mindset- comfortable iterating quickly, owning ambiguity, and learning as you go.
Nice to Have
- Experience with graph-based data or knowledge systems, especially for access-path or reachability analysis.
- Hands-on depth with cloud-adjacent technologies- Kubernetes, infrastructure-as-code, CI/CD, or SaaS and identity-provider security.
- Familiarity with applying AI/LLMs to security research and automation- we’re an AI-native team and use these tools as part of how we build.
Why Join Us
- Real ownership- this is an early-stage company where engineers drive decisions
- AI-native environment- you’ll join an AI-native team. We help customers secure their AI workloads, build intelligent automation into our product, and use AI tools every day as part of how we build and ship.
- Top-tier team- founders with deep security and product experience, surrounded by a team of experts and backed by leading investors
- Competitive package- strong salary, meaningful equity, and the upside of joining early