# Security Automation & Detection Engineer

[Mergroup](https://gurify.com/jobs?q=Mergroup) · Or Yehuda, Israel · Posted yesterday

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://www.comeet.com/jobs/mergroup/0B.00B/security-automation--detection-engineer/0F.072)

## Job description

MER Group is looking for a Security Engineer with a developer mindset—someone who delivers results through code and automation rather than repetitive manual work.

The organization operates a full Microsoft 365 E5 environment, a SIEM and SOC, a Fortinet security fabric, and a multi-site infrastructure spanning Israel and international locations.

This position comes with a genuine mandate to deliver: authority to build, a dedicated training budget, a dedicated development environment, an organization-owned code repository, and access to approved enterprise AI tools.

### Key Responsibilities:

- Maximize the end-to-end value of the Microsoft 365 E5 security stack across identity, endpoints, cloud, and email.

- Build process automations using Microsoft Graph API, Logic Apps, and scripts, including employee lifecycle management, procurement and vendor approval, and request classification and routing.

- Integrate large language models (LLMs) as system components for classification, document information extraction, and summarization.

- Perform detection engineering: write and tune detection rules and reduce false positives.

- Build automated response playbooks using a controlled, phased approach.

- Lead the consolidation of overlapping tools and reduce licensing costs.

- Define security requirements for new systems and implementations, including identity, logging, permissions, and API availability.

### Requirements

### Mandatory Requirements:

- Experience: 4+ years in Security Engineering or Platform Engineering.

- Environment: 2+ years of hands-on experience with Microsoft 365 and Entra ID.

- Development: PowerShell and Python at a tool-building level—not one-off scripting.

- Integration: Experience integrating at least three systems using REST APIs and Microsoft Graph.

- Automation: Experience building multi-step workflows with error handling, idempotency, and logging.

- Identity and Access: Strong knowledge of RBAC, least privilege, service accounts, and secrets management.

- Working Practices: Experience with Git, version control, and written technical documentation.

- Languages: Hebrew and technical English.

### Significant Advantages:

- Experience with Microsoft Defender XDR or Microsoft Sentinel, including detection-rule and playbook development.

- Experience integrating LLMs into production systems—not merely using chat-based tools.

- Experience implementing DLP or cloud application controls.

- Background in networking and Fortinet firewalls.

- Relevant certifications: SC-200, SC-300, or AZ-500.

**Live in Mergroup’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- VE [Cyber Security Training Engineer](https://gurify.com/job/cyber-security-training-engineer-at-vega-733d7970297c) Vega · Tel Aviv-Yafo, Israel · yesterday
- CL [Network Security Engineer](https://gurify.com/job/network-security-engineer-at-classiq-8fadbac800f5) Classiq · Tel Aviv-Yafo, Israel · yesterday
- ZE [AI Agent Security | Product Security Engineer](https://gurify.com/job/ai-agent-security-product-security-engineer-at-zenity-f5b9cf85b08a) Zenity · Tel Aviv-Jaffa, Israel · 3 weeks ago
- OL [DevOps Engineer (U.S Citizen) - Oligo Security](https://gurify.com/job/devops-engineer-u-s-citizen-oligo-security-at-oligosecurity-2bf93bd623c4) Oligosecurity · Tel Aviv-Yafo, Israel · 3 weeks ago
- SO [Cyber Security Engineer](https://gurify.com/job/cyber-security-engineer-at-somekhchaikin-5ed9c1882d55) Somekhchaikin · Tel Aviv-Yafo, Israel · 2 weeks ago
- CR [AI Security Engineer](https://gurify.com/job/ai-security-engineer-at-crossriver-14ec056f6cbd) Crossriver · Jerusalem, Israel · 3 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Automation \u0026 Detection Engineer","description":"\u003Cp\u003EMER Group is looking for a Security Engineer with a developer mindset\u2014someone who delivers results through code and automation rather than repetitive manual work.\u003C/p\u003E\u003Cp\u003EThe organization operates a full Microsoft 365 E5 environment, a SIEM and SOC, a Fortinet security fabric, and a multi-site infrastructure spanning Israel and international locations.\u003C/p\u003E\u003Cp\u003EThis position comes with a genuine mandate to deliver: authority to build, a dedicated training budget, a dedicated development environment, an organization-owned code repository, and access to approved enterprise AI tools.\u003C/p\u003E\u003Ch3\u003EKey Responsibilities:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EMaximize the end-to-end value of the Microsoft 365 E5 security stack across identity, endpoints, cloud, and email.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild process automations using Microsoft Graph API, Logic Apps, and scripts, including employee lifecycle management, procurement and vendor approval, and request classification and routing.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegrate large language models (LLMs) as system components for classification, document information extraction, and summarization.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPerform detection engineering: write and tune detection rules and reduce false positives.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild automated response playbooks using a controlled, phased approach.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead the consolidation of overlapping tools and reduce licensing costs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDefine security requirements for new systems and implementations, including identity, logging, permissions, and API availability.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Ch3\u003EMandatory Requirements:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience: 4\u002B years in Security Engineering or Platform Engineering.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnvironment: 2\u002B years of hands-on experience with Microsoft 365 and Entra ID.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelopment: PowerShell and Python at a tool-building level\u2014not one-off scripting.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegration: Experience integrating at least three systems using REST APIs and Microsoft Graph.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAutomation: Experience building multi-step workflows with error handling, idempotency, and logging.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentity and Access: Strong knowledge of RBAC, least privilege, service accounts, and secrets management.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking Practices: Experience with Git, version control, and written technical documentation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELanguages: Hebrew and technical English.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ESignificant Advantages:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience with Microsoft Defender XDR or Microsoft Sentinel, including detection-rule and playbook development.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience integrating LLMs into production systems\u2014not merely using chat-based tools.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience implementing DLP or cloud application controls.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBackground in networking and Fortinet firewalls.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERelevant certifications: SC-200, SC-300, or AZ-500.\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-automation-detection-engineer-at-mergroup-4740e1f968ef"},"url":"https://gurify.com/job/security-automation-detection-engineer-at-mergroup-4740e1f968ef","datePosted":"2026-08-24","validThrough":"2026-10-09T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Mergroup","sameAs":"https://www.comeet.com/jobs/mergroup"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"IL","addressLocality":"Or Yehuda"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Israel","item":"https://gurify.com/jobs/israel"},{"@type":"ListItem","position":3,"name":"Security Automation \u0026 Detection Engineer","item":"https://gurify.com/job/security-automation-detection-engineer-at-mergroup-4740e1f968ef"}]}
```
