Turn this role into an interview — a resume and cover letter built around what this employer wants.
Snowbit, part of the Coralogix group, seeks an experienced Senior Threat Hunting & Incident Response Engineer to join the Managed Detection and Response (MDR) team. The role focuses on proactive threat hunting, threat intelligence, and incident analysis across customer environments, with specialization in cloud environments and Kubernetes.
You will influence detection engineering and build systems to extend hunting coverage, collaborating across multiple customer tenants and their diverse log
Job DescriptionSnowbit is a cybersecurity technology innovator with a vision to empower organizations across the globe to quickly, efficiently, and cost-effectively ready themselves to address omnipresent cyber risk. Built off years of Israeli cybersecurity experience, Snowbit is looking to offer the broadest managed detection and response offering available today. Snowbit is part of the Coralogix group, with Coralogix rebuilding the path to observability by offloading the burden of indexing and providing deep insights, at an infinite scale, for less than half the cost.Snowbit is looking for an experienced Senior Threat Hunting & Incident Response Engineer to join our Managed Detection and Response (MDR) team. This role requires expertise in incident response, threat hunting, with a strong emphasis on cloud environments and Kubernetes. You will lead efforts to protect our customers from advanced cyber threats while contributing to the continuous improvement of Snowbit’s methodologies, processes, and technology stack.
We are hiring a senior engineer to run proactive threat hunts and deliver log-based incident analysis across our customers' Coralogix environments. The role sits in the Threat Detection & Response (TDR) team and exists because hunt coverage is constrained by analyst hours, not by data. We are closing that gap by building agentic hunting capability, so this hire both hunts and builds the systems that hunt.
TDR's scope is threat hunting, incident response support and threat intelligence. We own detection engineering and proactive hunting rather than queue-driven alert triage. This is a build-and-investigate role, where the work is forming the hypothesis, proving or disproving it in the data, and turning what we learn into durable detection logic.We work across multiple customer Coralogix tenants, each with its own log sources, naming conventions and data quality. A hunt written once has to be adapted, validated and re-run per environment, which is where most of the craft lives.