A corporate group is looking for an Information Security & Cyber Security Expert for a cross-functional, hands-on role, including monitoring security systems, handling cyber incidents, vulnerability management, and implementing information security processes.
This is a mid-level position, suited to professionals with practical experience who can investigate incidents in real time, make decisions, and lead response efforts in coordination with IT, infrastructure, development, and external vendors.
Reports to: CTO
Role Responsibilities
Monitor alerts from SOC and SIEM systems, investigate incidents, and assess their severity.
Lead the handling of information security incidents through to closure, including escalation and engaging relevant stakeholders.
Manage security vulnerabilities, track CVEs, and prioritize patching.
Work with WAF and Firewall systems: log analysis, rule review, handling blocks and exceptions, and access reduction.
Handle phishing incidents and suspicious activity, including checking links, files, and sender identity.
Conduct phishing simulations and deliver training sessions for employees.
Write and implement information security procedures and conduct periodic controls.
Document incidents, prepare reports, and track risks and open tasks.
Participate in a 24/7 on-call rotation and respond to unusual incidents outside working hours, including weekends and holidays.
Requirements: 3-5 years of hands-on experience in information security, cyber operations, or Security Operations.
Experience working with SIEM, a SOC, and handling real-time security incidents.
Ability to read and analyze logs from security systems, servers, and network components.
Hands-on experience with Firewall and WAF systems.
Experience in vulnerability management, CVE tracking, and prioritization.
Knowledge of communication protocols, IP, ports, DNS, HTTP, and HTTPS.
Familiarity with Windows environments, Active Directory, permissions, and endpoints.
Experience handling phishing incidents and suspicious emails.
Ability to write procedures, working documents, and investigation reports.
Ability to work independently, manage multiple tasks, and make decisions under pressure.
Ability to work with both technical and business stakeholders and deliver clear training sessions.
Willingness to participate in on-call duty, connect remotely, and respond quickly during incidents.
Good technical English.
Advantages (Nice to Have)
Experience working with Radware WAF.
Experience working with an external SOC or MSSP.
Familiarity with Microsoft 365, Azure, or cloud environments.
Experience with EDR, DLP, antivirus, or email filtering systems.
Familiarity with ISO 27001, NIST, CIS Controls, and Israeli privacy protection regulations.
Certifications such as Security+, CySA+, CEH, or equivalent.
This position is open to all candidates.