Full-Time

MDR Security Engineer

Varonis

Varonis

1,001-5,000 employees

Data security platform with threat detection

No salary listed

Morrisville, NC, USA

Hybrid

Hybrid role; some on-site days in Morrisville/Raleigh area.

Category
IT & Security
Required Skills
PowerShell
Bash
Python
Git
REST APIs
DevOps

Get referred to Varonis

See people who can refer or advise you

Requirements
  • 4+ years of experience in Security Operations, MDR, Incident Response, or Security Engineering
  • 2–3+ years of hands-on experience with SOAR platforms and security automation
  • Proven experience owning and operating production-grade automation workflows in a SOC/MDR environment
  • Strong understanding of SOC operations, alert triage, escalation workflows, and incident response
  • Experience with enterprise security technologies (SIEM, SOAR, EDR/XDR, IAM/AD)
  • Strong scripting/development skills (Python, PowerShell, Bash) and experience building APIs and integrations
  • Experience with CI/CD, version control (Git), and deploying automation at scale
  • Strong analytical thinking and problem-solving skills with the ability to translate complex workflows into automation
  • Excellent communication and collaboration skills across engineering and operations teams
Responsibilities
  • Upkeep the design, development, and lifecycle of SOAR playbooks, workflows, and integrations across the MDR platform
  • Build and operate production-grade automation systems supporting alert triage, enrichment, investigation, and response
  • Define and drive automation strategy by identifying high-impact, high-volume SOC processes and scaling them through automation
  • Develop integrations across SIEM, EDR/XDR, identity, cloud, and ticketing systems using APIs and scripting
  • Partner with MDR analysts, IR, threat hunters, and engineering teams to translate operational workflows into scalable automation
  • Improve detection and response quality through automation of enrichment, investigation, and containment workflows
  • Contribute to incident response and RCAs by delivering tooling that improves investigation speed, accuracy, and consistency
  • Evaluate and implement new automation capabilities, including AI-assisted workflows and data-driven decisioning
  • Define and own automation KPIs, including: Automation coverage (% of alerts handled or augmented)
  • MTTD / MTTR improvement
  • False positive reduction and signal-to-noise improvement
  • Analyst time saved and throughput increase
  • Build and maintain dashboards and reporting to measure automation impact on SOC performance and SLAs
  • Ensure production reliability and stability of automation systems, including: Monitoring workflow success/failure rates and execution latency
  • Tracking integration and API health, errors, and retry behavior
  • Implementing logging, alerting, and observability across automation pipelines
  • Continuously optimize workflows based on data, feedback, and operational performance to ensure consistent 24/7 MDR operation
Desired Qualifications
  • Experience with AI-enhanced automation or large-scale workflow orchestration
  • Experience in high-volume MDR/SOC environments
  • Familiarity with threat hunting or detection engineering

Varonis Systems focuses on protecting sensitive information from cyber threats by offering a data security platform that continuously monitors data, detects threats, and automates responses through advanced analytics and automation. The platform helps large enterprises, government agencies, and educational institutions secure data and meet regulatory requirements via subscription-based access, with a heavy emphasis on data monitoring, threat detection, and automated response. The company differentiates itself through a strong recurring revenue model (95% recurring) and high renewal rates (90%), reflecting steady income and high customer satisfaction, alongside a broad customer base. Its goal is to help customers protect data, prevent breaches, and stay compliant while growing its subscription-based business.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

New York City, New York

Founded

2005

Get referred to Varonis

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 revenue hit $180 million, up 18%, and SaaS ARR reached $598.1 million.
  • Management raised 2026 revenue guidance to $735 million-$739 million on July 28.
  • Agent IBAC launched August 3, 2026, unlocking enterprise AI-security cross-sell.

What critics are saying

  • Bloomberg reported June 23, 2026 takeover talks with Blackstone, Thoma Bravo, and Vista.
  • Large deals slipped late in Q2 after sale rumors, delaying revenue conversion into July.
  • If agentic security stalls, Microsoft and Palo Alto Networks commoditize Atlas before 2027.

What makes Varonis unique

  • Varonis Atlas now enforces AI-agent intent controls across Cursor, Claude Code, and Copilot.
  • Its unstructured-data mapping and permission graph target overexposed files, secrets, and identities.
  • Renewals above 90% and SaaS-heavy revenue show durable workflow embedment.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

0%
BleepingComputer
Aug 4th, 2026
Varonis Agent IBAC keeps AI agents within their intended boundaries.

Varonis Agent IBAC keeps AI agents within their intended boundaries. Sponsored by * August 4, 2026 * 10:00 AM * 0 Yesterday, Varonis announced Agent Intent-Based Access Control (IBAC), a new capability in Varonis Atlas that lets businesses connect AI agents to their enterprise data with safeguards that stop dangerous or out-of-policy behavior. Agents are making headlines for going rogue, exposing sensitive company data and, in one case, deleting an entire production database. Agent IBAC compares the instruction an agent received to its reasoning and the tools and data it reaches for, then responds in real time to actions that don't align, including alerting or blocking. When an agent crosses the line, Atlas can quarantine the identity behind it and block everything that follows for a defined window. Agent IBAC can be tuned to take appropriate action based on the potential impact. For example: * Clear deviation puts data at risk: A user asks an agent to check the weather. Instead, it invokes a migration tool. This is a clean mismatch between intent and action. Agent IBAC can automatically block the tool call. * Drift but nothing at stake: A user asks an agent to check the weather. The agent sets up a recurring daily reminder instead of providing a one-time answer. The agent's action has drifted, but no data is at risk. Agent IBAC can simply log the deviation rather than interrupt an over-eager attempt to help. With Agent IBAC, Varonis Atlas gives enterprises confidence that their agents are acting within the intended scope, without unnecessarily slowing productivity. Agent IBAC is a critical component of agentic security and a core part of Atlas's end-to-end approach to AI security. At Varonis, ASMGi is building the security layer that lets enterprises say 'yes' to agents. Watch this quick 3-minute demo to see Agent IBAC in action. Agents don't wait for permission. Agents need broad access to data and tools to be useful, which is precisely what makes them risky. Role-based access control was never built to judge what a non-human identity does with the access it has. Static controls can't stop an agent that finds ways to circumvent them entirely, like elevating its own privileges, calling tools, and acting on data it was never meant to touch. Agent permissions must be enforced at runtime. "The question is no longer 'Can a user access this data?' but 'In this context, should this agent be allowed to take action on this data?'," explains Ron Bennatan, Vice President of AI & Data Strategy, Varonis. Whether you're on a red team, a blue team, or needing to gain CPE credits, this is your chance to learn by doing. Breach at the Beach is free and available to play online: https://breachatthebeach.com Varonis Atlas Agent IBAC. Agent IBAC closes the gap between what an agent is allowed to do and what it was designed to do. Drift is determined in part by monitoring behavior. Agent IBAC evaluates every action an agent takes across a session and compares those actions to the instruction that set the agent in motion, whether that instruction came from a person, system prompt, or another agent. Because Atlas sees the full context around an action, it doesn't rely on blanket restrictions. The sensitivity of detection and the action taken in response can each be tuned appropriately. Agent IBAC at a glance: * Intent drift detection: Compares the instruction an agent received to its reasoning and the tools it calls, with lenient, balanced, and strict sensitivity settings. * Full-session evaluation: Reviews every prompt, response, and tool call in a session to catch drift that builds gradually, including multi-turn jailbreak attempts. Teams can also write their own session policies in plain language. * Runtime guardrails: Alert, block, modify, log, or route an action to a person for approval, configured per policy. * Quarantine: Blocks an identity or session for a window the customer sets, with admin controls to lift, extend, or make it permanent. * Complete audit trail: Records every prompt, response, and tool execution alongside the action Atlas took, for security, governance, and compliance teams. Importantly, Atlas sits inline between the agent and the model that drives it. Every prompt, every model response, and every tool call flows through Atlas before it reaches its destination. That's what makes enforcement possible in real time. Atlas is not reading logs after the fact. It is in the path, and it can stop an action before it executes. Intent drift detection. Agent IBAC uses an LLM evaluator, the same engine behind all Atlas guardrails, to judge whether an agent's action follows from the instruction it was given. Intent drift detection includes determining whether the agent is accessing data it shouldn't, attempting unauthorized exfiltration or download of data, or expanding the scope beyond what the user intended. The evaluator reads the agent loop: the reasoning the agent produces, the tools it selects, and the parameters it passes to them. It then asks a simple question: "Do these steps align with the request?" Sensitivity is tunable across three levels. Lenient gives agents room to improvise and flags only clear mismatches. Balanced is the default. Strict requires close alignment between the request and the action, and is the right setting for agents that touch regulated or high-value data. Full-session evaluation. Agent IBAC evaluates the agent's action across the entire session: every prompt, response, and tool call. That's what allows Agent IBAC to catch intent drift that unfolds gradually, where no single action looks alarming, but the cumulative path leads somewhere the user never intended. The same full-session view also makes it possible to detect multi-turn attacks, such as jailbreak attempts spread across several prompts that appear benign individually. Sessions are tracked by the conversation ID the AI tool assigns, so a single evaluation can span everything from the first prompt to the last. That matters because agents carry memory forward. A later prompt can lean on context established several turns earlier, which is precisely how a patient attacker assembles a jailbreak out of pieces that each look harmless. Teams can also write their own session policies in plain language and set how many events must accumulate before evaluation runs. Runtime guardrails & quarantine. Every intent-based detection is paired with AI runtime guardrails that take action in real time. The actions are customizable, including alerting, blocking, modifying (e.g., redacting sensitive data), logging activity, or requiring human-in-the-loop approval. Runtime guardrails can be customized to allow low-risk drift while stopping high-risk actions. For example, a user asks an agent to summarize a customer account. The agent starts pulling records for a much larger set of accounts than requested. This isn't necessarily malicious, but the scope creep touches more sensitive data than the request warrants. In this case, Agent IBAC can flag it for human-in-the-loop approval before it proceeds. Quarantine goes one step further. When a violation warrants more than stopping a single action, Atlas can quarantine the identity behind the session. Every prompt that follows is blocked for a window the customer sets, from a couple of minutes to a full day. Administrators see every quarantined identity in one place and can lift a quarantine, extend it, or make it permanent. Detection tells you an agent went off course. Quarantine stops the next attempt. Complete audit trail. Atlas records every action and the intent behind it, giving investigators a complete trail: what the agent did, whether each action followed from the request, and which guardrails fired. A conversation view shows the exchange the way the user experienced it. An execution view expands it to include the tool calls underneath, the steps that never surface in the chat window and where most agent risk actually lives. Trust is the ultimate metric for agentic success. Agentic success in the enterprise won't be measured by how many agents get deployed. It will be measured by how many of them can be trusted. Agent IBAC is part of how Varonis Atlas makes that possible, giving security teams a way to confirm agents are acting as intended, in real time, without slowing the business. It's one piece of Atlas' broader approach to securing the agents an organization builds and runs, alongside capabilities, like AI-SPM, AI Red Teaming, and AI Detection & Response. Agent IBAC is available today to Varonis Atlas customers. Sponsored and written by Varonis.

Yahoo Finance
Jul 28th, 2026
Varonis exceeds Q2 guidance with $180M revenue, raises full-year outlook

Varonis Systems reported Q2 2026 results exceeding guidance, with revenue rising 18% year-over-year to $180 million. SaaS annual recurring revenue, excluding conversions, increased 25% to $598.1 million, whilst net income reached $5.3 million. The SaaS renewal rate exceeded 90%. Management attributed growth to demand for data security and AI security offerings, particularly Atlas, Interceptor and Database Activity Monitoring. CEO Yaki Faitelson noted SaaS ARR from new customers grew over 20%. Several large deals slipped late in the quarter amid media speculation about a potential transaction, though some closed in July. The company raised its full-year outlook, targeting 20-21% growth in SaaS ARR excluding conversions and revenue of $735-739 million.

Yahoo Finance
Jul 28th, 2026
Varonis Systems beats Q2 revenue estimates with $180M but stock drops despite raised guidance

Varonis Systems reported second-quarter revenue of $180 million, beating analyst estimates of $176.9 million and representing 18.3% year-on-year growth. The data security company's non-GAAP earnings of $0.04 per share significantly exceeded the $0.01 consensus estimate. The company raised its full-year revenue guidance to $737 million at the midpoint from $734 million. Management also increased full-year adjusted earnings per share guidance to $0.15 at the midpoint, a 26.1% rise. SaaS annual recurring revenue excluding conversions grew 25% in the quarter. Operating margin improved to negative 22.6% from negative 24% in the same quarter last year, whilst free cash flow margin declined to 11.1% from 28.3% in the previous quarter. The company's market capitalisation stands at $5.36 billion.

MarketBeat
Jul 28th, 2026
Varonis Systems Q2 earnings call highlights.

Varonis Systems Q2 earnings call highlights. July 28, 2026 Key points. * Varonis exceeded its Q2 2026 guidance, with revenue rising 18% year over year to $180 million and SaaS ARR excluding conversions increasing 25% to $598.1 million. Net income grew to $5.3 million, while the SaaS renewal rate exceeded 90%. * Demand is growing for Varonis' data- and AI-security offerings, particularly Atlas, Interceptor and Database Activity Monitoring. Management said AI adoption is increasing customer requirements for controls over sensitive data, models and agents. * The company raised its full-year outlook, targeting 20%-21% growth in SaaS ARR excluding conversions, revenue of $735 million-$739 million and free cash flow of $105 million-$110 million. * MarketBeat previews top five stocks to own in August. Varonis Systems NASDAQ: VRNS reported second-quarter 2026 results that exceeded the company's guidance range, as management cited continued demand for data security and AI security capabilities, growth in new-customer activity, and rising adoption of newer products. SaaS annual recurring revenue, excluding conversions from the company's self-hosted platform, rose 25% year over year to $598.1 million. Total SaaS ARR, including conversions, was $726 million. Chief Executive Officer Yaki Faitelson said SaaS ARR from new logos grew more than 20% during the quarter. Management said several large deals slipped late in the quarter amid media rumors regarding a potential transaction involving the company. Varonis declined to discuss the speculation further, but said it had closed some of the delayed transactions in July, including a seven-figure deal. Chief Financial Officer and Chief Operating Officer Guy Melamed said the third quarter had begun strongly and the company retained a healthy pipeline for the second half of the year. Second-Quarter financial results. Total revenue increased 18% year over year to $180 million in the second quarter. SaaS revenue was $171.7 million, while term license subscription revenue totaled $4.2 million and maintenance and services revenue was $4.1 million. The company's SaaS renewal rate exceeded 90%. On a non-GAAP basis, gross profit was $139.9 million, representing a 77.7% gross margin, compared with 80.6% in the prior-year quarter. Operating income was $3.7 million, or a 2.1% operating margin, compared with an operating loss of $1.9 million a year earlier. Net income was $5.3 million, or $0.04 per diluted share, compared with $3.8 million, or $0.03 per diluted share, in the second quarter of 2025. Financial income was approximately $7 million, primarily driven by interest income on cash, deposits and marketable securities. For the first six months of 2026, Varonis generated $69.1 million in free cash flow, compared with $82.7 million a year earlier. Melamed said the decline reflected the previously disclosed headwind associated with the end-of-life announcement for the company's on-premise platform, as well as approximately $11.9 million in acquisition-related costs. Excluding those acquisition-related costs, year-to-date free cash flow would have been about $81 million, he said. Discover more Stock Screener Tool Financial News Stock Market Holidays As of June 30, Varonis had $911.5 million in cash equivalents, short-term deposits and marketable securities. AI security demand and product adoption. Faitelson said the growing adoption of AI is increasing the value and risk associated with enterprise data. He argued that organizations need to understand where sensitive data resides, who or what can access it, and whether access is appropriate as AI models and agents are connected to data environments. "AI security and data security cannot be treated as separate problems," Faitelson said, describing automation as central to managing AI-driven risk. He said customers are seeking controls around AI models, agents and pipelines, including insight into the data they can access, the permissions they inherit and whether their activity is normal. The company highlighted growing momentum for Atlas, Interceptor and Database Activity Monitoring, or DAM. Management said Atlas had been sold for roughly three and a half months and was appearing frequently in customer conversations. Melamed said the company was "pleasantly surprised" by Atlas' contribution in the second quarter, though it expects a more meaningful contribution in the second half. Varonis said customers are increasingly buying more of its platform upfront and connecting it to more AI systems. Management said the primary buyer remains the chief information security officer, though chief AI officers are increasingly involved in conversations. * A healthcare organization with more than 40,000 employees became a customer after seeking guardrails for more than 100 AI projects and automated remediation of overexposed HIPAA and personally identifiable information data. * A financial services customer expanded its Varonis deployment following a vendor-consolidation review, adding Atlas Complete, Interceptor DAM, and coverage for infrastructure-as-a-service environments, Salesforce and Microsoft 365. Management said DAM is aimed at both new and existing customers, including opportunities to replace incumbent products from Imperva and IBM Guardium. Interceptor has primarily been sold into Varonis' existing customer base alongside the company's MDDR offering, according to Melamed. Raised full-year outlook. For the third quarter, Varonis forecast SaaS ARR growth of 22% to 23%, excluding conversions; revenue of $185 million to $188 million; non-GAAP operating income of $2.5 million to $3.5 million; and non-GAAP earnings of $0.02 to $0.03 per diluted share. For full-year 2026, the company raised its outlook for SaaS ARR excluding conversions to growth of 20% to 21%. It expects total SaaS ARR of $819 million to $850 million, representing growth of 28% to 33%, and said its implied SaaS ARR excluding conversions outlook is $769 million to $775 million, a $5 million increase from its prior forecast. Varonis also lifted its full-year free-cash-flow forecast by $5 million to $105 million to $110 million. The company projected full-year revenue of $735 million to $739 million, up 18% to 19%; non-GAAP operating income of $11 million to $13 million; and non-GAAP earnings per diluted share of $0.14 to $0.15. Melamed said the company expects sales productivity to continue improving as it moves upmarket and sells a broader platform. He also said Varonis did not assume a positive contribution from the federal vertical in its third-quarter outlook, describing that part of the business as de-risked in the guidance. About Varonis Systems (NASDAQ:VRNS). Varonis Systems is a cybersecurity firm specializing in the protection and management of unstructured data. The company's flagship Data Security Platform provides advanced analytics for monitoring file systems, email servers, collaboration platforms and cloud storage. By continuously mapping and analyzing data permissions and user behavior, Varonis enables organizations to detect insider threats, verify compliance and remediate exposed data in real time. Founded in 2005 and headquartered in New York City, Varonis serves a diverse global customer base across financial services, healthcare, media, manufacturing and government. This instant news alert was generated by narrative science technology and financial data from MarketBeat in order to provide readers with the fastest reporting and unbiased coverage. Please send any questions or comments about this story to [email protected]. Before you consider Varonis Systems, you'll want to hear this. MarketBeat keeps track of Wall Street's top-rated and best performing research analysts and the stocks they recommend to their clients on a daily basis. MarketBeat has identified the five stocks that top analysts are quietly whispering to their clients to buy now before the broader market catches on... and Varonis Systems wasn't on the list. While Varonis Systems currently has a Moderate Buy rating among analysts, top-rated analysts believe these five stocks are better buys. With the proliferation of data centers and electric vehicles, the electric grid will only get more strained. Download this report to learn how energy stocks can play a role in your portfolio as the global demand for energy continues to grow.

Yahoo Finance
Jul 8th, 2026
Is Varonis Systems, Inc. (VRNS) among the Best Cybersecurity Stocks to Buy and Hold for the Long Term?

Is Varonis Systems, Inc. (VRNS) among the Best Cybersecurity Stocks to Buy and Hold for the Long Term? Sajjl Nooranne