Software Development Engineer - Applied Research

BeyondTrust
Tel Aviv
Workplace: HybridFull timeFunction: Research & Scientific (R&D)Experience: 3+ yearsSkills: ["Technical communication","Investigative problem-solving","Teamwork","Debugging","Collaboration"]

Build and optimize detection logic that secures non-human identities and cloud entitlements. Study how service accounts, IAM roles, workload identities, and API tokens use permissions, then model least-privilege gaps across AWS, Azure/Entra ID, and GCP IAM. Write heuristics and statistical routines to flag risky patterns, turn attack paths into automated detection coverage, and prototype models that scale into production with product engineering.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
BeyondTrust
BeyondTrust
2 days ago

Software Development Engineer - Applied Research

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 12 hours agoStatus: Live

Job Summary

Build and optimize detection logic that secures non-human identities and cloud entitlements. Study how service accounts, IAM roles, workload identities, and API tokens use permissions, then model least-privilege gaps across AWS, Azure/Entra ID, and GCP IAM. Write heuristics and statistical routines to flag risky patterns, turn attack paths into automated detection coverage, and prototype models that scale into production with product engineering.
Location: Tel Aviv
Workplace: Hybrid
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Build and optimize detection logic for over-permissioned identities, excessive entitlements, and least-privilege gaps
  • •Study permission usage by service accounts, IAM roles, workload identities, and API tokens, and identify where behavior diverges from granted permissions
  • •Model effective permissions programmatically across AWS IAM, Azure RBAC and Entra ID, or GCP IAM
  • •Write heuristics and statistical routines to flag risky permission patterns and create automated detection coverage for attack paths like privilege escalation and credential misuse
  • •Prototype solutions and work with product engineering to scale models into production

Key Requirements

  • •3+ years writing clean, maintainable backend code, ideally Python or Go
  • •Strong understanding of IAM mechanics across AWS, Azure/Entra ID, or GCP (policies, roles, authorization flow)
  • •Ability to build analytical logic or heuristics from structured data, logs, or permission models
  • •Methodical approach to complex debugging and deep interest in security
  • •Strong technical communication with engineering and product colleagues
Experience:3+ yearsSecurityCloud IAM
Skills:Technical communicationInvestigative problem-solvingTeamworkDebuggingCollaboration
Tech Stack:PythonGoAWSAzureEntra IDGCPAWS IAMAzure RBACGCP IAM

Company Brief

BeyondTrust
Provides privileged access management, vulnerability management, and secure remote access solutions to help organizations protect credentials, manage privileges, and secure endpoints across on-premises and cloud environments.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Phoenix, United States
WebsiteLinkedIn