368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$101k – $229k per year (Estimated)
Location
In office (Israel)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Novartis is a Swiss multinational pharmaceutical company dedicated to the research, development, and manufacturing of innovative medicines. The organization focuses on addressing high-unmet patient needs across key therapeutic areas, including oncology, immunology, neuroscience, and cardiovascular-renal-metabolic diseases. Through its advanced technology platforms - such as gene and cell therapy, radioligand therapy, and xRNA - the firm aims to reimagine medicine to improve and extend lives worldwide.

Band

Level 5

Job Description Summary

Location: Tel-Aviv, Israel

#LI-Hybrid 3 days/week in office

Internal job title: Assoc. Dir. DDIT ISC Security Research

About the role:

The Defensive Cyber Security Researcher will be part of a new Think Tank group of security researchers that will challenge Novartis information security defenses, application security and data protection.

The Defensive Cyber Security Researcher will be responsible for participating in threat actor based investigations, creating new detection methodology and providing expert support to incident response and monitoring functions.

The focus of the Defensive Cyber Security Researcher is to detect, disrupt and eradicate threat actors from enterprise networks, including emerging AI-driven and AI-assisted threats. To execute this mission, the Defensive Cyber Security Researcher will use data analysis, threat intelligence, and cutting-edge security technologies - with a growing emphasis on understanding how AI can be weaponized against the organization and how it can be leveraged defensively.

The Defensive Cyber Security Researcher will identify and analyze patterns and changes in tactics, techniques and procedures used by attackers to attack Novartis IT infrastructure and management staff. The analysis will result in indicators of compromise, accurate understanding of the risk to Novartis IT infrastructure and prioritization of remediation efforts.

Job Description

Key Responsibilities:

  • Hunt through huge number of signals to identify new emerging threats, dissect them and extract meaningful insights and indicators of compromise.

  • Demonstrate adversary tactics to recognize and analyze malicious activity (techniques, tools and processes) based on a combination of behavioral activity and signature based analysis.

  • Participate in "hunting missions" using threat intelligence, analysis of anomalous log data and results of brainstorming sessions to detect and eradicate threat actors on the Novartis network.

  • Provide expert analytic investigative support of large scale and complex security incidents.

  • Perform analysis of security incidents for further enhancement of alert catalog; perform in-depth static and dynamic malware reverse engineering; preform ad hoc memory and disk forensics.

  • Produce detailed technical reports in support of malware / other hunting investigations.

  • Review alerts generated by detection infrastructure for effectiveness and recommend improvements.

  • In collaboration with the Security Operations Center: Develop dashboards and reports to identify potential threats, suspicious/anomalous activity, malware, etc.

  • Research and assess AI-specific security risks to the organization, including adversarial use of AI models, prompt injection attacks, data poisoning, shadow AI adoption, and LLM-assisted threat actor operations; translate findings into actionable defensive guidance and detection rules.

  • Collaborate with Cyber Threat Intelligence (CTI) teams to operationalize intelligence feeds, enrich hunting missions with external and internal threat data, and contribute research outputs (IOCs, TTPs, adversary profiles) back into intelligence pipelines.

Essential Requirements:

  • 5+ years of experience in Incident Response / CERT team or 5+ years of experience with malware investigations.

  • Critical understanding of the cyber attacker kills chain elements, with particular emphasis on attack objectives.

  • High familiarity and experience with Active Directory (AD) and Entra ID / Azure AD security - including AD attack paths (Kerberoasting, pass-the-hash, DCSync, Golden/Silver Ticket), BloodHound-based graph analysis, AD tiering models, and Conditional Access Policies; ability to identify misconfigurations that lead to privilege escalation and lateral movement.

  • Solid understanding of AI security risks and their organizational impact, including adversarial machine learning, prompt injection, data poisoning, shadow AI risks, and the use of generative AI tools by threat actors; ability to advise the organization on AI-related threat exposure and contribute to AI governance from a security perspective.

  • Proven ability to work effectively with Security Operations Center (SOC) teams: including joint detection engineering, alert tuning, escalation workflows, and acting as a subject matter expert during high-severity incident response; experience bridging the gap between research depth and SOC operational tempo.

  • Experience working with Cyber Threat Intelligence (CTI) teams: consuming and operationalizing intelligence products, contributing research outputs as structured intelligence (IOCs, TTPs, adversary profiles), and participating in joint threat briefings and intelligence-driven hunting operations.

  • Good familiarity with Red Teaming tools and operations, understanding of Wireshark, Cobalt Strike and more

  • Advanced programming skills with scripting languages such as Python/Perl/Ruby.

  • Familiarity with the current nation-state (“APT”) threat landscape and the various actors and groups.

  • Very strong team and interpersonal skills along with the ability to work independently and achieve individual goals, with effective oral and written communication skills.

Desirable requirements:

  • Relevant Technical Security Certifications (GIAC, EC-Council, Offensive Security, etc.)

Why Novartis?

Our purpose is to reimagine medicine to improve and extend people’s lives and our vision is to become the most valued and trusted medicines company in the world. How can we achieve this? With our people. It is our associates that drive us each day to reach our ambitions. Be a part of this mission and join us! Learn more here: https://www.novartis.com/about/strategy/people-and-culture

Join our Novartis Network: If this role is not suitable to your experience or career goals but you wish to stay connected to learn more about Novartis and our career opportunities, join the Novartis Network here: https://talentnetwork.novartis.com/network

Accessibility and accommodation:

Novartis is committed to working with and providing reasonable accommodation to all individuals. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the recruitment process, or in order to receive more detailed information about the essential functions of a position, please send an e-mail to and let us know the nature of your request and your contact information. Please include the job requisition number in your message.

Skills Desired

Communication Skills, Cyber-Security Regulation, Cyber Threat Hunting, Cyber Threat Intelligence (Cti), Cyber Threat Management, Cyber Vulnerabilities, Decision Making Skills, Digital Capabilities, Effective use of Technology, Influencing Skills, Information Security Risk Management
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Israel
$173k – $314k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • San Francisco
Apex
JavaScript
Node JS
Python
SQL
TypeScript
Apex
Lightning Web Components
AI/ML
Agentforce
AI Agents
Claude
Claude Code
Copilot
Cursor
LLM
RAG
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
Grafana
gRPC
Kubernetes
New Relic
Prometheus
Splunk
Marketing
Salesforce
QA
Cypress
JMeter
k6
Locust
Playwright
Postman
Rest-Assured
Selenium
Apply
$150k – $180k per year • In office • Full-Time • PhD • New York
Python
AI/ML
Anthropic
Anthropic SDK
Computer Vision
Fine-tuning
LangChain
LlamaIndex
LLM
OpenAI
OpenAI SDK
RAG
DevOps
AWS
Azure
GCP
Apply
$129k – $231k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Atlanta
SQL
AI/ML
AI Agents
Claude
Claude Code
DevOps
Azure
Design
Figma
Apply
$29k – $73k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree • Guadalajara
Python
DevOps
Amazon CloudWatch
Azure
CI/CD
Datadog
Docker
Kubernetes
Prometheus
Terraform
Apply
$38k – $91k per year (Estimated) • Remote • Full-Time • 8+ years exp • PhD • Guadalajara
PowerShell
Python
Databases
Amazon Aurora
DynamoDB
AI/ML
Amazon SageMaker
AWS Bedrock
AWS Bedrock AgentCore
Ray
DevOps
Amazon CloudWatch
Amazon EC2
Amazon ECS
Amazon EKS
Amazon EventBridge
Amazon S3
AWS
AWS Lambda
AWS Step Functions
Azure
CI/CD
Datadog
FinOps
GCP
Git
GitLab
GitLab CI
IAM
Jenkins
JFrog Artifactory
Kubernetes
New Relic
Service Mesh
Splunk
Terraform
Cybersecurity
HIPAA
ISO 27001
PCI DSS
SOC 2
Apply
$71k – $112k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austria
C#
C++
Python
Visual Basic
Apply
$25k – $56k per year (Estimated) • In office • Full-Time • Brazil
Analytics
Power BI
Marketing
Salesforce
Apply
$65k – $121k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Ljubljana
AI/ML
Computer Vision
Apply
$157k – $283k per year • Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • Hanover
Apex
Apex
Salesforce Data Cloud
Databases
Snowflake
AI/ML
LLM
Agentforce
OpenAI
Marketing
Salesforce
Apply
$153k – $283k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hanover
Apply
HLS specialist 2 hours ago
In office • Full-Time • Israel
DevOps
AWS
Azure
Apply
$39k – $124k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Israel
C#
Java
DevOps
Azure
Azure DevOps
CI/CD
Git
QA
Appium
TestNG
Apply
$26k – $109k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Israel
C#
Java
DevOps
Azure
Azure DevOps
CI/CD
Git
QA
Appium
TestNG
Apply
In office • Full-Time • Haifa
Chips/EDA
Cadence Virtuoso
Apply
$93k – $274k per year (Estimated) • In office • Full-Time • 1+ year exp • Bachelor's Degree • Tel Aviv • Yokneam
C++
AI/ML
Edge AI
NCCL
DevOps
Kubernetes
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.