# Security Automation & Detection Engineer

[Mergroup](https://gurify.com/jobs?q=Mergroup) · Or Yehuda, Israel · Posted 6 weeks ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://www.comeet.com/jobs/mergroup/0B.00B/security-automation--detection-engineer/0F.072)

## Job description

MER Group is looking for a Security Engineer with a developer mindset—someone who delivers results through code and automation rather than repetitive manual work.

The organization operates a full Microsoft 365 E5 environment, a SIEM and SOC, a Fortinet security fabric, and a multi-site infrastructure spanning Israel and international locations.

This position comes with a genuine mandate to deliver: authority to build, a dedicated training budget, a dedicated development environment, an organization-owned code repository, and access to approved enterprise AI tools.

### Key Responsibilities:

- Maximize the end-to-end value of the Microsoft 365 E5 security stack across identity, endpoints, cloud, and email.

- Build process automations using Microsoft Graph API, Logic Apps, and scripts, including employee lifecycle management, procurement and vendor approval, and request classification and routing.

- Integrate large language models (LLMs) as system components for classification, document information extraction, and summarization.

- Perform detection engineering: write and tune detection rules and reduce false positives.

- Build automated response playbooks using a controlled, phased approach.

- Lead the consolidation of overlapping tools and reduce licensing costs.

- Define security requirements for new systems and implementations, including identity, logging, permissions, and API availability.

### Requirements

### Mandatory Requirements:

- Experience: 4+ years in Security Engineering or Platform Engineering.

- Environment: 2+ years of hands-on experience with Microsoft 365 and Entra ID.

- Development: PowerShell and Python at a tool-building level—not one-off scripting.

- Integration: Experience integrating at least three systems using REST APIs and Microsoft Graph.

- Automation: Experience building multi-step workflows with error handling, idempotency, and logging.

- Identity and Access: Strong knowledge of RBAC, least privilege, service accounts, and secrets management.

- Working Practices: Experience with Git, version control, and written technical documentation.

- Languages: Hebrew and technical English.

### Significant Advantages:

- Experience with Microsoft Defender XDR or Microsoft Sentinel, including detection-rule and playbook development.

- Experience integrating LLMs into production systems—not merely using chat-based tools.

- Experience implementing DLP or cloud application controls.

- Background in networking and Fortinet firewalls.

- Relevant certifications: SC-200, SC-300, or AZ-500.

**Live in Mergroup’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- VI [Senior Application Security Engineer](https://gurify.com/job/senior-application-security-engineer-at-via-29d6a84848f6) Via · Tel Aviv · 2 days ago
- GU [Technical Product Manager - Security](https://gurify.com/job/technical-product-manager-security-at-guardio-860403bc546c) Guardio · Tel Aviv-Yafo, Israel · 3 days ago
- NO [Israel at Novee Security](https://gurify.com/job/israel-at-novee-security-at-noveesecurity-bc1ab103d07f) Noveesecurity · Tel Aviv-Yafo, Israel · 3 days ago
- VA [Senior Security Engineer](https://gurify.com/job/senior-security-engineer-at-vastdata-514171dde2fc) Vastdata · Tel Aviv-Yafo, Israel · 5 weeks ago
- DR [Senior Network & Security Engineer](https://gurify.com/job/senior-network-security-engineer-at-drivenets-a96e1dd1d282) Drivenets · Raanana, Israel · 3 weeks ago
- ON [Application Security Engineer - ONE ZERO](https://gurify.com/job/application-security-engineer-one-zero-at-onezerobank-2e8386af9bda) Onezerobank · Tel Aviv-Yafo, Israel · 4 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Automation \u0026 Detection Engineer","description":"\u003Cp\u003EMER Group is looking for a Security Engineer with a developer mindset\u2014someone who delivers results through code and automation rather than repetitive manual work.\u003C/p\u003E\u003Cp\u003EThe organization operates a full Microsoft 365 E5 environment, a SIEM and SOC, a Fortinet security fabric, and a multi-site infrastructure spanning Israel and international locations.\u003C/p\u003E\u003Cp\u003EThis position comes with a genuine mandate to deliver: authority to build, a dedicated training budget, a dedicated development environment, an organization-owned code repository, and access to approved enterprise AI tools.\u003C/p\u003E\u003Ch3\u003EKey Responsibilities:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EMaximize the end-to-end value of the Microsoft 365 E5 security stack across identity, endpoints, cloud, and email.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild process automations using Microsoft Graph API, Logic Apps, and scripts, including employee lifecycle management, procurement and vendor approval, and request classification and routing.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegrate large language models (LLMs) as system components for classification, document information extraction, and summarization.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPerform detection engineering: write and tune detection rules and reduce false positives.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild automated response playbooks using a controlled, phased approach.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead the consolidation of overlapping tools and reduce licensing costs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDefine security requirements for new systems and implementations, including identity, logging, permissions, and API availability.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Ch3\u003EMandatory Requirements:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience: 4\u002B years in Security Engineering or Platform Engineering.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnvironment: 2\u002B years of hands-on experience with Microsoft 365 and Entra ID.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelopment: PowerShell and Python at a tool-building level\u2014not one-off scripting.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegration: Experience integrating at least three systems using REST APIs and Microsoft Graph.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAutomation: Experience building multi-step workflows with error handling, idempotency, and logging.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentity and Access: Strong knowledge of RBAC, least privilege, service accounts, and secrets management.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking Practices: Experience with Git, version control, and written technical documentation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELanguages: Hebrew and technical English.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ESignificant Advantages:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience with Microsoft Defender XDR or Microsoft Sentinel, including detection-rule and playbook development.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience integrating LLMs into production systems\u2014not merely using chat-based tools.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience implementing DLP or cloud application controls.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBackground in networking and Fortinet firewalls.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERelevant certifications: SC-200, SC-300, or AZ-500.\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-automation-detection-engineer-at-mergroup-4740e1f968ef"},"url":"https://gurify.com/job/security-automation-detection-engineer-at-mergroup-4740e1f968ef","datePosted":"2026-08-24","validThrough":"2026-11-23T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Mergroup","sameAs":"https://www.comeet.com/jobs/mergroup"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"IL","addressLocality":"Or Yehuda"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Israel","item":"https://gurify.com/jobs/israel"},{"@type":"ListItem","position":3,"name":"Security Automation \u0026 Detection Engineer","item":"https://gurify.com/job/security-automation-detection-engineer-at-mergroup-4740e1f968ef"}]}
```
