Tal Katz

Senior Security Engineer · Wiz (Google)

on-call
active
tier
3 · cloud security
uptime
7y 9m
contact
email · linkedin

On a wider screen this page also has a keyboard layer, a live policy ledger and a working shell.

overview

Senior Security Engineer at Wiz, now part of Google. I build detection and automation — turning alerts into code, and code into things that page a human only when a human is actually needed.

Seven years from IT support to security engineering: helpdesk, then threat operations, then security engineering. I have run a SOC alone for six months, cut alert MTTR by a fifth with automation, and moved a SIEM into version control.

7+ years in tech 2020 pivoted to security GOSI SANS certified −20% alert MTTR

alerts

Senior Security Engineer Wiz · Google

P12024-08 → present

scopecloud security · detection engineering

  • Promoted from Security Engineer to Senior.
  • TODO — three to five lines on what you own here. Scope and ownership only; no internal tooling, no detection logic, no incident specifics.

Security Operations Engineer Axonius

P22022-09 → 2024-08

scopedetection-as-code · SOAR platform

  • Led the Tines SOAR implementation from scratch — 10+ production workflows.
  • Cut alert MTTR by 20% with an automated user-interaction system.
  • Ran Panther as a code-managed SIEM: detections in version control, GitHub Actions for CI/CD.
  • Built security infrastructure with Terraform.
  • Code review, security testing, incident and vulnerability response.

Security Operations Engineer Cellebrite

P22021-11 → 2022-09

scope700+ users · multi-region

  • Designed, implemented and maintained secure systems and networks.
  • Ran security assessments and audits, then drove the remediation.
  • Protected data for 700+ users across multiple geographies.
  • Trained and mentored junior analysts.

Threat Operations Analyst Cellebrite

P32020-11 → 2021-11

scopesole coverage · 6 months

  • Sole team member covering all threat-operations activity for six months.
  • QRadar in depth: DSM editor, rule creation, custom action scripts, automation.
  • Python webhook server feeding events into the SIEM over syslog.
  • Automated anonymised-traffic blocking at the WAF edge.
  • Onboarded and trained two new analysts.

IT Support Specialist Cellebrite

P42018-11 → 2020-11

scope800 endpoints worldwide

  • Kept 800 employees running worldwide across macOS and Windows.
  • Full Active Directory and Azure AD administration.
  • Led the Webex rollout — 32 conference rooms worldwide.
  • Python automations for password expiry, connectivity testing and alerting.

detections

Things I built and run.

Tines SOAR PlatformBuilt from zero. 10+ production workflows covering triage, enrichment and user interaction.TinesPythonWebhooks
Detection-as-CodePanther SIEM managed entirely from a Git repo — detections reviewed, versioned and shipped through GitHub Actions.PantherGitHub ActionsYAML
MTTR AutomationAutomated user-interaction loop that confirms or dismisses suspicious activity with the human involved. Cut alert MTTR by 20%.TinesSlackSIEM
Syslog Webhook BridgePython web server receiving vendor webhooks and forwarding them into the SIEM over syslog, so sources without native integrations still land in one place.PythonSyslogQRadar
WAF Auto-BlockingScheduled job pulling anonymised-traffic exit nodes and pushing them to the WAF edge automatically.PythonImpervaThreat intel
Security Infra as CodeTerraform modules standing up the infrastructure behind security tooling, reproducibly.TerraformAWS
AI Security Assistant open sourceAn assistant wiring Axonius asset context into Panther detections, so an analyst gets the asset story without leaving the alert.PythonAxoniusPanther
This SiteThree hand-written files, no framework, no build step, no third-party requests. Strict CSP. Type detect in the terminal.Vanilla JSCSPNo deps

coverage

detection & responsePanther · IBM QRadar · CrowdStrike · Varonis · incident response
automation & codePython · Bash · Tines SOAR · SQL · Terraform
cloud & platformAWS · Wiz · Linux · Active Directory / Entra · GitHub Actions
network & edgeCheck Point · F5 · Imperva WAF · Forcepoint · Netskope

credentials

2024GIAC OSINT GOSI · SANS
2022Ethical Hacker See Security College · top of cohort
2019Python Master iNT Institute of Innovation & Technology
2019MCSA + CCNA Network management & cloud — John Bryce
2015Combat Medic Israel Defense Forces

console

A real shell. Type help. Some commands are not in the list.

tal@talkatz — zsh