AllJobs, located in Netanya, is looking for an Information Security & Cybersecurity Specialist.
Responsibilities
Ongoing monitoring of security systems, including alerts received from SOC and SIEM platforms.
Receiving alerts and providing initial response to information security incidents as part of a 24/7 on-call rotation.
Conducting initial investigations of security alerts and incidents, assessing their severity, and determining the appropriate course of action.
Escalating critical incidents and engaging IT, infrastructure, development teams, and external security vendors as needed.
Managing information security incidents and tracking them through full resolution.
Continuously monitoring security vulnerabilities and CVEs relevant to the company’s systems.
Assessing vulnerability severity, prioritizing remediation efforts, and coordinating the installation of security updates.
Working with Radware WAF systems, including log analysis, reviewing blocked traffic, handling exceptions, and updating security rules.
Working with Firewall systems, including reviewing rules, opening network access, reducing permissions, and analyzing logs.
Handling employee reports regarding phishing messages or suspicious activity.
Reviewing links, attachments, sender identity, and additional recipients in suspected phishing incidents.
Conducting phishing simulations for employees, analyzing results, and producing insights and recommendations.
Delivering training sessions and presentations to raise awareness of information security and cyber risks.
Writing, updating, and implementing information security policies and procedures across the group of companies.
Conducting periodic audits related to permissions, data retention, data transfer, and system access.
Documenting security incidents, findings, actions taken, and recommendations for future improvement.
Preparing periodic reports covering incidents, open vulnerabilities, remediation status, and key risks.
Requirements: 3–5 years of hands-on experience in information security, cyber operations, or Security Operations roles.
Experience working with SIEM systems or with a SOC team.
Ability to read, analyze, and investigate logs from security systems, servers, and network components.
Hands-on experience responding to information security alerts and incidents in real time.
Experience working with Firewall systems and analyzing network rules.
Hands-on experience working with WAF systems.
Experience in vulnerability management, CVE monitoring, and prioritizing security updates.
Strong understanding of network protocols, IP addresses, ports, DNS, HTTP, and HTTPS.
Good knowledge of Windows environments, Active Directory, user permissions, and endpoints.
Experience handling phishing incidents and suspicious email messages.
Ability to write procedures, working documents, and incident investigation reports.
Ability to work independently and make decisions under pressure.
Ability to manage multiple incidents and tasks simultaneously and follow them through to completion.
Ability to work effectively with both technical and non-technical stakeholders.
Ability to deliver clear and accessible security training to employees.
Willingness to participate in a 24/7 on-call rotation and handle information security incidents outside regular working hours, including evenings, nights, weekends, and holidays, depending on the nature and severity of the incident.
Ability to respond quickly, connect remotely, and begin investigating and handling critical incidents.
Availability to engage IT, infrastructure, development teams, and external vendors when required.
Good technical English.
Advantages
Hands-on experience with WAF systems.
Experience working with an external SOC or MSSP.
Experience working within a group of companies or in a multi-system environment.
Familiarity with Microsoft 365, Azure, or another cloud environment.
This position is open to all candidates.