Confidential mandate

Cyber-Telemetry Streaming Evidence Director — Cloud Security

Planned Hiring / New

Cyber-Telemetry Streaming Evidence Director mandate in Tel Aviv, Israel · Cloud Detection and Response

An Israeli cloud-security provider commissions a four-month redesign of its cyber-telemetry stream, creating provable detection coverage, controlled degradation and an accepted operating model across high-volume customer signals.

The mandate

Rapid customer growth has pushed endpoint, identity, cloud-control and network signals beyond the assumptions of the original event architecture. During regional bursts, the platform samples or delays lower-priority telemetry without showing which detections become blind. Product metrics emphasise ingestion volume and alert latency, but customers and detection researchers cannot trace loss, transformation or late arrival to changes in actual threat coverage.

The deliverable is a Cyber-Telemetry Evidence and Degradation Architecture containing signal criticality, provenance contracts, loss accounting, back-pressure policy, detection dependency maps, regional recovery and customer disclosure rules. A production-shadow implementation across twelve priority detections must demonstrate how the system behaves when capacity, sensor quality or a data region deteriorates, including which protection claims remain supportable.

Milestone one by week three provides the end-to-end loss ledger and detection-dependency census. Week seven closes milestone two with target contracts and degraded-mode policies. At week twelve, milestone three supplies shadow results from burst, corruption and regional-failure experiments. The accepted architecture, economics, migration sequence and internal validation kit form milestone four at week seventeen.

Acceptance requires detection researchers to reproduce coverage impact for each injected telemetry failure, reliability teams to reconcile sampled input events to storage and detection outcomes within agreed tolerance, and Product to approve customer-visible limitation language. Two unseen stress scenarios must invoke the intended priority and disclosure behaviour automatically. Joint CTO and product-chief sign-off completes acceptance, not deployment of a new broker alone.

The client will provide anonymised production-flow metrics, event schemas, transformation code, detection logic, sampling policies, regional topology, incident histories, customer commitments and infrastructure cost. Named sensor, stream, detection and SRE owners will support weekly experiments inside controlled environments. Product Legal will review disclosure wording, and the CTO will decide contested signal priorities within forty-eight hours.

Why this is external work

Ingestion teams are rewarded for throughput, detection teams for coverage and product leaders for broad protection claims; no internal owner can neutrally expose how resource choices weaken another team’s measure. The required combination of streaming reliability and detection semantics is also scarce. External work creates a testable evidence position without selling additional infrastructure as the predetermined answer.

What you will own

  • Trace endpoint, identity, control-plane and network events through sensor, transport, transform, enrichment, storage and detection consumption with explicit loss accounting.
  • Rank telemetry using detection consequence, substitutability, customer promise, jurisdiction, time sensitivity and forensic value rather than raw event volume.
  • Define schema, provenance, lateness and completeness contracts that let researchers determine whether a detection result remains interpretable.
  • Design back-pressure and degraded-mode policies that preserve critical signals, expose lost coverage and prevent silent sampling from becoming normal operation.
  • Execute burst, poison-event, enrichment-delay, regional-loss and sensor-quality experiments against mapped detection dependencies and customer commitments.
  • Model capacity and retention choices against coverage, recovery, investigation need and infrastructure cost across distinct customer and threat scenarios.
  • Transfer the experiment harness, evidence dashboards, decision register and quarterly degradation review to internal security-data and product owners.

Candidate qualifications

  • Architected high-volume security telemetry supporting production detection and response across endpoint, identity, cloud or network signal families.
  • Connected streaming loss, delay and transformation behaviour to specific detection efficacy rather than reporting infrastructure throughput in isolation.
  • Designed graceful degradation and back-pressure for event systems where incorrect prioritisation could create material and undisclosed security blindness.
  • Ran adversarial or failure-injection experiments spanning sensors, stream processors, enrichment, storage and detection-rule consumption.
  • Balanced customer claim, forensic retention, jurisdiction, performance and unit cost in a security-data platform operating across multiple regions.
  • Delivered an implementation-independent architecture and internal validation kit without commercial attachment to a broker, SIEM or cloud provider.

Non-negotiables

  • The named director must lead threat-coverage mapping and stress reviews in Tel Aviv; delegation to a general data-engineering team is unacceptable.
  • No commercial, referral or investment interest may exist in streaming, storage, SIEM or observability products likely to be considered.
  • Customer telemetry must remain anonymised and inside approved regional test environments throughout analysis and experimentation.
  • Product protection claims cannot be preserved where stress evidence shows an uncommunicated detection limitation.
  1. 49 words maximum. Explain how a streaming failure changed one detection’s effective coverage even though aggregate ingestion remained within target.
  2. 49 words maximum. How would you prioritise telemetry when back-pressure forces a choice between forensic depth and immediate detection?
  3. 49 words maximum. Which experiments prove that degraded-mode security claims are accurate under regional or enrichment failure?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.