Full-Time

MDR Security Engineer

Updated on 9/3/2026

Varonis

Varonis

1,001-5,000 employees

Data security platform with threat detection

No salary listed

Remote in India

Remote

Category
Cybersecurity (1)
Required Skills
PowerShell
Bash
Python
Incident Response
Data Visualization
Git
Observability
REST APIs
DevOps

Get referred to Varonis

See people who can refer or advise you

Requirements
  • At least 4 years of experience in Security Operations, managed detection and response, Incident Response, or Security Engineering.
  • At least 2–3 years of hands-on experience with Security Orchestration, Automation and Response platforms and security automation.
  • Proven experience owning and operating production-grade automation workflows in a security operations center or managed detection and response environment.
  • Strong understanding of security operations center operations, alert triage, escalation workflows, and incident response.
  • Experience with enterprise security technologies including Security Information and Event Management, Security Orchestration, Automation and Response, Endpoint Detection and Response/Extended Detection and Response, and Identity and Access Management/Active Directory.
  • Strong scripting and development skills in Python, PowerShell, and Bash, with experience building application programming interfaces and integrations.
  • Experience with continuous integration and continuous delivery, Git version control, and deploying automation at scale.
  • Strong analytical thinking and problem-solving skills, with the ability to translate complex workflows into automation.
  • Excellent communication and collaboration skills across engineering and operations teams.
Responsibilities
  • Maintain the design, development, and lifecycle of Security Orchestration, Automation and Response playbooks, workflows, and integrations across the managed detection and response platform.
  • Build and operate production-grade automation systems supporting alert triage, enrichment, investigation, and response.
  • Define and drive automation strategy by identifying high-impact, high-volume security operations center processes and scaling them through automation.
  • Develop integrations across Security Information and Event Management, Endpoint Detection and Response/Extended Detection and Response, identity, cloud, and ticketing systems using application programming interfaces and scripting.
  • Partner with managed detection and response analysts, incident response, threat hunters, and engineering teams to translate operational workflows into scalable automation.
  • Improve detection and response quality through automation of enrichment, investigation, and containment workflows.
  • Contribute to incident response and root-cause analyses by delivering tooling that improves investigation speed, accuracy, and consistency.
  • Evaluate and implement new automation capabilities, including artificial-intelligence-assisted workflows and data-driven decision-making.
  • Define and own automation key performance indicators, including automation coverage, mean time to detect and mean time to respond improvement, false-positive reduction, signal-to-noise improvement, analyst time saved, and throughput increase.
  • Build and maintain dashboards and reporting to measure automation impact on security operations center performance and service-level agreements.
  • Ensure production reliability and stability of automation systems by monitoring workflow success and failure rates and execution latency, tracking integration and application programming interface health, errors, and retry behavior, and implementing logging, alerting, and observability across automation pipelines.
  • Continuously optimize workflows based on data, feedback, and operational performance to ensure consistent 24/7 managed detection and response operation.
Desired Qualifications
  • Experience with artificial-intelligence-enhanced automation or large-scale workflow orchestration.
  • Experience in high-volume managed detection and response or security operations center environments.
  • Familiarity with threat hunting or detection engineering.

Varonis Systems focuses on protecting sensitive information from cyber threats by offering a data security platform that continuously monitors data, detects threats, and automates responses through advanced analytics and automation. The platform helps large enterprises, government agencies, and educational institutions secure data and meet regulatory requirements via subscription-based access, with a heavy emphasis on data monitoring, threat detection, and automated response. The company differentiates itself through a strong recurring revenue model (95% recurring) and high renewal rates (90%), reflecting steady income and high customer satisfaction, alongside a broad customer base. Its goal is to help customers protect data, prevent breaches, and stay compliant while growing its subscription-based business.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

New York City, New York

Founded

2005

Get referred to Varonis

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 revenue reached $180 million, up 18%, and guidance increased.
  • SaaS ARR reached $726 million by June 30, 2026, with renewal above 90%.
  • Snowflake Marketplace access and Cursor support expand Varonis' sales channels in 2026.

What critics are saying

  • Proofpoint acquisition talks on September 2, 2026 can freeze customers and employees.
  • Microsoft, Snowflake, and AI-native security vendors compress Varonis pricing and differentiation.
  • If takeover talks collapse, Varonis faces standalone rerating and deal-slippage pressure into 2027.

What makes Varonis unique

  • Varonis controls sensitive data inline across SaaS, AI agents, and coding tools.
  • Snowflake named Varonis a Premier Partner on September 1, 2026.
  • Atlas now blocks prompts and agent actions before Claude or Cursor executes them.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

0%
Yahoo Finance
Sep 2nd, 2026
Thoma Bravo's Proofpoint weighs bid for Varonis Systems, stock jumps 10%

Shares of Varonis Systems jumped 10% on Wednesday after reports emerged that Proofpoint, owned by Thoma Bravo, is in talks to acquire the data security company. The Wall Street Journal reported the discussions, noting no deal is guaranteed. Miami-based Varonis has spent three years transitioning from licensed software to a cloud subscription model, finishing the shift two years ahead of schedule. By end-2025, SaaS accounted for 86% of its annual recurring revenue. In Q2 2026, Varonis reported revenue of $180 million, up 18% year-over-year, with SaaS annual recurring revenue reaching $726 million. The company held over $900 million in cash as of 30 June. Proofpoint, acquired by Thoma Bravo in 2021 for $12.3 billion, specialises in email and collaboration security.

Bloomberg
Sep 2nd, 2026
Thoma Bravo's Proofpoint is said in talks to acquire Varonis.

Thoma Bravo's Proofpoint is said in talks to acquire Varonis. September 2, 2026 at 12:01 PM PDT Updated on September 2, 2026 at 1:57 PM PDT Takeaways by bloomberg aisubscribe. Thoma Bravo-backed Proofpoint Inc. is in talks to acquire cybersecurity company Varonis Systems Inc., which would be one of the biggest technology take-privates since the steep selloff in software stocks earlier this year, according to people familiar with the matter. Proofpoint is negotiating the terms of a potential deal with Varonis, which has been working with advisers to field takeover interest, said the people, asking not to be identified because the information is private. A transaction could be announced in the coming weeks, assuming the talks don't fall apart, they said.

GlobeNewswire
Sep 1st, 2026
Varonis achieves Snowflake Premier Partner status.

Varonis achieves Snowflake Premier Partner status. Expanded collaboration and inclusion on the Snowflake Marketplace make it easier than ever for customers to secure the data and AI they build and run in Snowflake. MIAMI, Sept. 01, 2026 (GLOBE NEWSWIRE) - Varonis Systems, Inc. (NASDAQ: VRNS), the data and AI security leader, announced two milestones that deepen its integration with Snowflake: Varonis is now a Premier Partner and is available on Snowflake Marketplace. AI agents, copilots, and LLMs now read, write, and act on data flowing through data lakes, warehouses, and everywhere in between. Varonis helps enterprises secure Snowflake environments so they can innovate fast with confidence. Premier Partner status shows how deep the Varonis integration with Snowflake goes, and it opens the door to closer collaboration on joint customer outcomes, co-selling, and roadmap alignment. With Varonis for Snowflake, organizations can: * Discover and classify sensitive data. Automatically scan every Snowflake database, schema, table, and column to pinpoint sensitive data wherever it lives. * Map effective permissions. Cut through nested role inheritance to show exactly who can reach what, and right-size access automatically. * Detect and stop threats. Varonis builds behavior baselines, so you can monitor access patterns that indicate real risk, such as an AI system accessing data it shouldn't. Get contextual alerts on real threats rather than noise. Snowflake customers can now find Varonis on the Snowflake Marketplace and put a portion of their committed capacity toward Varonis through the Snowflake Marketplace Capacity Drawdown (MCD) program. "Companies use Snowflake to unlock data for AI. Varonis gives them the confidence to do that safely," said Ashi Aber, Vice President of Strategic Partnerships at Varonis. "Together, Varonis and Snowflake help customers move faster with AI without losing control of their data." "Our customers are building and running critical AI workloads on Snowflake, and they need to trust the security of that data every step of the way," said Rodrigo Rocha, Vice President, Global ISV & Enterprise Technology Partnerships at Snowflake. "Varonis' premier partnership status with Snowflake reflects the strength of this integration and our shared commitment to helping customers innovate securely." Varonis offers a free Data Risk Assessment that shows, within 24 hours, where your data lives, who can access it, and what's putting it at risk. Additional Resources About Varonis Varonis (Nasdaq: VRNS) secures AI and the data that powers it. The Varonis platform gives organizations automated visibility and control over their critical data wherever it lives and helps ensure safe and trustworthy AI from code to runtime. Backed by 24x7x365 managed detection and response, Varonis gives thousands of organizations worldwide the confidence to adopt AI, reduce data exposure, and stop AI-powered threats. Investor Relations Contact: Tim Perz Varonis Systems, Inc. 646-640-2112 [email protected] News Media Contact: Rachel Hunt Varonis Systems, Inc. 877-292-8767 (ext. 1598) [email protected]

Varonis
Aug 7th, 2026
Varonis Atlas now integrates with Claude Inference hooks to extend real-time AI data protection.

Varonis Atlas now integrates with Claude Inference hooks to extend real-time AI data protection. Varonis Atlas enforces data protection policy inline before a prompt ever reaches the model and extends coverage to Claude Chat and Claude Design. Last updated August 7, 2026 Varonis Atlas now integrates with Claude Inference hooks, routing prompts through an AI security server for real-time allow-or-deny verdicts before inference runs. That inspection happens ahead of Claude ever seeing the prompt - the request is sent off for review and policy evaluation first. If it violates policy, it never reaches the model. Support for Inference hooks helps security teams prevent sensitive data exposure, prompt injection attempts, and other risky activity. As Anthropic continues to expand the Claude ecosystem, AI security platforms have to move quickly to keep data secure. Just a few weeks ago, Varonis Systems, Inc. brought Atlas coverage to the entire Claude enterprise suite, including Claude Enterprise, Claude Platform, Claude Code, and Claude Cowork. Atlas has also enhanced support for Claude Chat and Claude Design. How Atlas prevents prompts that fall outside policy Atlas now sits in the request path itself. When a user submits a prompt, Anthropic sends the conversation transcript to Atlas, which evaluates it against an expansive set of customizable policies, including PII exposure, malicious URL, and prompt injection. Atlas then returns a verdict - allow or deny - before inference proceeds. A denied prompt never reaches Claude at all. How Atlas enforces the verdict Because Atlas understands sensitivity, permissions, and access across an organization's data, prompts aren't evaluated in a vacuum. That context determines the risk and informs an appropriate response. For example, a prompt asking Claude to summarize a spreadsheet depends on whether the spreadsheet contains public marketing copy or unmasked customer PII. With Inference hooks, that context now drives inline decisions: AI runtime guardrails. Atlas inspects the transcript and attachment text on every prompt and takes action in real time, including denying requests that would expose regulated, classified, or sensitive data before a response is generated. A consistent verdict, everywhere Claude runs. Atlas enforces consistent policies and guardrails across the entire Claude enterprise suite, including Claude Chat, Claude Design, Claude Enterprise, Claude Platform, Claude Cowork, and Claude Code. Complete audit trail. Atlas creates a record of every prompt and response alongside the actions it took, leveraging Inference hooks to provide an intuitive audit trail for security, governance, and compliance teams. Complete security for the Claude enterprise suite Most AI security solutions tell you which AI systems exist, not whether data is at risk. Varonis Atlas connects AI risk to data - where the damage happens. That same context now applies to every Claude interaction, from a governed prompt in Claude Chat to a multi-step Claude Cowork task to an agent running in Claude Code. With Inference hooks, that connected view extends into the request path itself, including posture management and security testing before an AI system goes live, runtime guardrails and inline enforcement, and compliance reporting. AI security cannot live in silos or point solutions. Atlas support for Claude is one piece of an end-to-end approach to AI security. As organizations scale AI, they also increase exposure. The only way forward is security that understands both how AI behaves and what data it can access. AI isn't the risk, uncontrolled AI is. Ready to build and secure everything you run with AI? Learn how Varonis can help your organization reduce risk and safely scale AI with confidence. See how Varonis secures AI environments: Schedule a demo of Varonis Atlas to understand what AI agents can access - and how to control actions on sensitive data. Discover your AI data exposure: Its free Data Risk Assessment shows what data agentic AI can reach and how to reduce risk before it's exploited. Learn how to secure AI at scale: Follow Varonis on LinkedIn, YouTube, and X for practical insights on AI security, agent risk, and protecting the data that powers your AI initiatives. Nolan Necoechea Nolan Necoechea is a product marketing strategist at Varonis. He has spent more than a decade working with data and AI innovators.

BleepingComputer
Aug 4th, 2026
Varonis Agent IBAC keeps AI agents within their intended boundaries.

Varonis Agent IBAC keeps AI agents within their intended boundaries. Sponsored by * August 4, 2026 * 10:00 AM * 0 Yesterday, Varonis announced Agent Intent-Based Access Control (IBAC), a new capability in Varonis Atlas that lets businesses connect AI agents to their enterprise data with safeguards that stop dangerous or out-of-policy behavior. Agents are making headlines for going rogue, exposing sensitive company data and, in one case, deleting an entire production database. Agent IBAC compares the instruction an agent received to its reasoning and the tools and data it reaches for, then responds in real time to actions that don't align, including alerting or blocking. When an agent crosses the line, Atlas can quarantine the identity behind it and block everything that follows for a defined window. Agent IBAC can be tuned to take appropriate action based on the potential impact. For example: * Clear deviation puts data at risk: A user asks an agent to check the weather. Instead, it invokes a migration tool. This is a clean mismatch between intent and action. Agent IBAC can automatically block the tool call. * Drift but nothing at stake: A user asks an agent to check the weather. The agent sets up a recurring daily reminder instead of providing a one-time answer. The agent's action has drifted, but no data is at risk. Agent IBAC can simply log the deviation rather than interrupt an over-eager attempt to help. With Agent IBAC, Varonis Atlas gives enterprises confidence that their agents are acting within the intended scope, without unnecessarily slowing productivity. Agent IBAC is a critical component of agentic security and a core part of Atlas's end-to-end approach to AI security. At Varonis, ASMGi is building the security layer that lets enterprises say 'yes' to agents. Watch this quick 3-minute demo to see Agent IBAC in action. Agents don't wait for permission. Agents need broad access to data and tools to be useful, which is precisely what makes them risky. Role-based access control was never built to judge what a non-human identity does with the access it has. Static controls can't stop an agent that finds ways to circumvent them entirely, like elevating its own privileges, calling tools, and acting on data it was never meant to touch. Agent permissions must be enforced at runtime. "The question is no longer 'Can a user access this data?' but 'In this context, should this agent be allowed to take action on this data?'," explains Ron Bennatan, Vice President of AI & Data Strategy, Varonis. Whether you're on a red team, a blue team, or needing to gain CPE credits, this is your chance to learn by doing. Breach at the Beach is free and available to play online: https://breachatthebeach.com Varonis Atlas Agent IBAC. Agent IBAC closes the gap between what an agent is allowed to do and what it was designed to do. Drift is determined in part by monitoring behavior. Agent IBAC evaluates every action an agent takes across a session and compares those actions to the instruction that set the agent in motion, whether that instruction came from a person, system prompt, or another agent. Because Atlas sees the full context around an action, it doesn't rely on blanket restrictions. The sensitivity of detection and the action taken in response can each be tuned appropriately. Agent IBAC at a glance: * Intent drift detection: Compares the instruction an agent received to its reasoning and the tools it calls, with lenient, balanced, and strict sensitivity settings. * Full-session evaluation: Reviews every prompt, response, and tool call in a session to catch drift that builds gradually, including multi-turn jailbreak attempts. Teams can also write their own session policies in plain language. * Runtime guardrails: Alert, block, modify, log, or route an action to a person for approval, configured per policy. * Quarantine: Blocks an identity or session for a window the customer sets, with admin controls to lift, extend, or make it permanent. * Complete audit trail: Records every prompt, response, and tool execution alongside the action Atlas took, for security, governance, and compliance teams. Importantly, Atlas sits inline between the agent and the model that drives it. Every prompt, every model response, and every tool call flows through Atlas before it reaches its destination. That's what makes enforcement possible in real time. Atlas is not reading logs after the fact. It is in the path, and it can stop an action before it executes. Intent drift detection. Agent IBAC uses an LLM evaluator, the same engine behind all Atlas guardrails, to judge whether an agent's action follows from the instruction it was given. Intent drift detection includes determining whether the agent is accessing data it shouldn't, attempting unauthorized exfiltration or download of data, or expanding the scope beyond what the user intended. The evaluator reads the agent loop: the reasoning the agent produces, the tools it selects, and the parameters it passes to them. It then asks a simple question: "Do these steps align with the request?" Sensitivity is tunable across three levels. Lenient gives agents room to improvise and flags only clear mismatches. Balanced is the default. Strict requires close alignment between the request and the action, and is the right setting for agents that touch regulated or high-value data. Full-session evaluation. Agent IBAC evaluates the agent's action across the entire session: every prompt, response, and tool call. That's what allows Agent IBAC to catch intent drift that unfolds gradually, where no single action looks alarming, but the cumulative path leads somewhere the user never intended. The same full-session view also makes it possible to detect multi-turn attacks, such as jailbreak attempts spread across several prompts that appear benign individually. Sessions are tracked by the conversation ID the AI tool assigns, so a single evaluation can span everything from the first prompt to the last. That matters because agents carry memory forward. A later prompt can lean on context established several turns earlier, which is precisely how a patient attacker assembles a jailbreak out of pieces that each look harmless. Teams can also write their own session policies in plain language and set how many events must accumulate before evaluation runs. Runtime guardrails & quarantine. Every intent-based detection is paired with AI runtime guardrails that take action in real time. The actions are customizable, including alerting, blocking, modifying (e.g., redacting sensitive data), logging activity, or requiring human-in-the-loop approval. Runtime guardrails can be customized to allow low-risk drift while stopping high-risk actions. For example, a user asks an agent to summarize a customer account. The agent starts pulling records for a much larger set of accounts than requested. This isn't necessarily malicious, but the scope creep touches more sensitive data than the request warrants. In this case, Agent IBAC can flag it for human-in-the-loop approval before it proceeds. Quarantine goes one step further. When a violation warrants more than stopping a single action, Atlas can quarantine the identity behind the session. Every prompt that follows is blocked for a window the customer sets, from a couple of minutes to a full day. Administrators see every quarantined identity in one place and can lift a quarantine, extend it, or make it permanent. Detection tells you an agent went off course. Quarantine stops the next attempt. Complete audit trail. Atlas records every action and the intent behind it, giving investigators a complete trail: what the agent did, whether each action followed from the request, and which guardrails fired. A conversation view shows the exchange the way the user experienced it. An execution view expands it to include the tool calls underneath, the steps that never surface in the chat window and where most agent risk actually lives. Trust is the ultimate metric for agentic success. Agentic success in the enterprise won't be measured by how many agents get deployed. It will be measured by how many of them can be trusted. Agent IBAC is part of how Varonis Atlas makes that possible, giving security teams a way to confirm agents are acting as intended, in real time, without slowing the business. It's one piece of Atlas' broader approach to securing the agents an organization builds and runs, alongside capabilities, like AI-SPM, AI Red Teaming, and AI Detection & Response. Agent IBAC is available today to Varonis Atlas customers. Sponsored and written by Varonis.