דרושים » אבטחת מידע וסייבר » חוקר /ת סייבר!

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בהורייזן טכנולוגיות
לארגון ממשלתי גדול ומוביל טכנולוגית בתל אביב. דרוש/ה חוקר/ת סייבר!
עבודה במודל היברידי! 
מומחה/ית סייבר מוביל/ה לביצוע מחקר ופיתוח מתקדם בתחומי נוזקות, חולשות, פורנזיקה, הנדסה לאחור ומבדקי חדירות למערכות מורכבות.
התפקיד כולל פיתוח כלי מחקר מתקדמים וניתוח מערכות ופרוטוקולי תקשורת בסביבות מורכבות ובסקייל רחב ( Big Data ).
דרישות:
נדרש ניסיון של 7 שנים ומעלה!
ניסיון מוכח במחקר ופיתוח מתקדם בתחום סייבר, עם דגש על סביבת ענן.
ידע וניסיון בזיהוי, איתור ומתן התרעה על תקיפות סייבר בסביבות ענן מורכבות.
יכולת לפתח וליישם תפיסות חקירה מתקדמות, כולל מימוש שרשרת התקיפה והסקת מסקנות מחקרים.
ניסיון בגיבוש דוחות מחקר והעשרת מידע טכנולוגי לצוותי חקירות ולארגונים.
הבנה מעמיקה בפרוטוקולים, מערכות ענן וכלי מחקר טכנולוגיים מתקדמים. המשרה מיועדת לנשים ולגברים כאחד.
 
הסתר
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8585336
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
דרושים בפרולוג'יק
מיקום המשרה: תל אביב יפו
סוג משרה: משרה מלאה
לגוף ממשלתי גדול ויציב דרוש/ה חוקר/ת סייבר מנוסה!!
התפקיד כולל
עבודה מחקרית מול אחד או יותר מהתחומים הבאים:
מחקר נוזקות, מחקר חולשות, מחקר פורנזי, מחקר מתקדם של פרוטוקולי תקשורת, ביצוע מבדקי חדירות,
הנדסה לאחור חילוץ תובנות מחקריות ממידע מודעיני - טכנולוגי פיתוח כלים תומכים למחקר מתקדם, ביצוע מחקרים מבוססי Big Data
הובלת צוות מחקר מודעיני טכנולוגי במחקר קבוצות תקיפה אויב/ יריב, בניית 'תיקי תוקף' לטובת שיפור יכולת האיתור, זיהוי גילוי ומתן התרעה על תקיפות סייבר בהתאם למזהים שיטות וכלים בהם קבוצות התקיפה הרלוונטיות עושות שימוש, העשרת המידע של צוות החוקרים בשטח בטיפול ובחקירה של אירועי סייבר,
הכוונת הצוות לשימוש בכלים המתאימים, פיקוח ובקרה על התוצרים, גיבוש המענה המתאים על פי סוג האירוע
דרישות:
ניסיון של 5 שנים לפחות בביצוע מטלות התפקיד מעלה
השכלה רלוונטית
ניסיון מחקרי מקיף בתחומי מחקר בשניים או יותר מהתחומים הבאים: מחקר נוזקות, מחקר חולשות, מחקר פורנזי, מחקר מתקדם של פרוטוקולי תקשורת, ביצוע מבדקי חדירות, הנדסה לאחור, חילוץ תובנות מחקריות ממידע מודיעיני - טכנולוגי, פיתוח כלים תומכים למחקר מתקדם,
ביצוע מחקרים מבוססי Big Data.
ידע נרחב, מתקדם ומוכח במגוון מערכות ופרוטוקולים
מיקום: תל אביב
קיימת היברידיות של יום עבודה מהבית המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8771722
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בקונסיסט מערכות בע"מ
סוג משרה: משרה מלאה
- ביצוע מחקרי איומים ומערכי תקיפה
- ביצוע סקירות מודיעין יומיות ומעקב אחר קבוצות תקיפה
- חיפוש מידע במקורות גלויים (OSINT) ובמרחב ה-Darknet
- ניתוח מידע ממקורות שונים והצלבת נתונים
- ניתוח מדיה חברתית ומעקב אחר אירועים מתפתחים
- הכנת דוחות מחקר ותוצרים מודיעיניים
- פיתוח ושימוש בכלי אוטומציה למחקר
- השתתפות בתדריכים מודיעיניים וחקירות
- ביצוע מבדקי חדירות, מחקר רשתות וניתוח חולשות
- עבודה מול צוותי IT ואבטחת מידע.
דרישות:
- ניסיון של לפחות 3 שנים בתחומי מחקר הסייבר.
- ניסיון בלפחות שניים מהתחומים הבאים:
Threat Intelligence /OSINT/ Digital Forensics /מחקר רשתות/Incident Response/ Penetration Testing/ Big Data
- פיתוח כלי מחקר ואוטומציה. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8750693
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
דרושים בוואן פתרונות טכנולוגיים בע"מ
מיקום המשרה: רמת גן
סוג משרה: משרה מלאה
ביצוע מבדקי חדירות אפליקטיביים, תשתיתיים ובסביבות ענן.
הובלת סימולציות תקיפה (Red Team) מול מערכות קריטיות.
זיהוי חולשות אבטחה מורכבות והובלת תהליכי תיקון מול צוותי פיתוח ותשתיות.
עבודה שוטפת מול צוותי SOC, IR ואבטחת מידע.
כתיבת דוחות מקצועיים בעברית ובאנגלית.
שיפור ופיתוח מתודולוגיות תקיפה בארגון.
דרישות:
לפחות 5 שנות ניסיון בבדיקות חדירה (Penetration Testing) ו/או Red Team.
שליטה מעמיקה באבטחת Web, תקיפות תשתית ו-Active Directory.
ניסיון בעבודה עם Burp Suite, Nessus, Nmap, Metasploit ו-BloodHound.
ניסיון בכתיבת סקריפטים ב- Python, Bash או PowerShell.
היכרות מעמיקה עם רשתות תקשורת וסביבות ענן (AWS, Azure, GCP).
ניסיון בבדיקות API ו-Mobile - יתרון.
היכרות עם OWASP, NIST ו-MITRE ATT CK - יתרון.
הסמכות כגון OSCP, OSEP או OSWE - יתרון משמעותי. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8759057
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בקונסיסט מערכות בע"מ
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה
ביצוע מבדקי חדירות (Web, תשתיות וענן).
הובלת סימולציות תקיפה (Red Team).
איתור חולשות מורכבות וליווי תהליכי התיקון מול צוותי הפיתוח והתשתיות.
עבודה שוטפת מול צוותי SOC ו-IR.
כתיבת דוחות מקצועיים ברמה גבוהה.
שיפור ופיתוח מתודולוגיות תקיפה.
דרישות:
לפחות 5 שנות ניסיון בבדיקות חדירה (Penetration Testing) ו/או Red Team.
ניסיון מעשי בתקיפות Web בהתאם ל-OWASP Top 10.
ידע מעמיק ב-Active Directory, Kerberos ו-Lateral Movement.
שליטה במערכות Linux ו-Windows.
ניסיון בעבודה עם Burp Suite, Nessus, Nmap, Metasploit ו-BloodHound.
ניסיון בכתיבת סקריפטים ב-Bash, PowerShell או Python.
הבנה מעמיקה בפרוטוקולי תקשורת ורשתות.
ניסיון בסביבות ענן (AWS / Azure / GCP).
יכולת גבוהה לכתיבת דוחות בעברית ובאנגלית. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8760919
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 18 שעות
מיקום המשרה: תל אביב יפו
סוג משרה: משרה מלאה ועבודה היברידית
צוות ניהול סיכוני IT מתמחה בזיהוי, ניתוח והתמודדות עם סיכונים טכנולוגיים, ובבניית פתרונות לשיפור מערכות ותהליכי עבודה לצמצום פגיעה עסקית. המנהלים בצוות מובילים פרויקטים מול לקוחות מהותיים בישראל ובעולם, בשיתוף מומחים מקומיים ובעלי ניסיון גלובלי, תוך שימוש במתודולוגיות ייחודיות וכלים טכנולוגיים מתקדמים. הצוות מוביל פרויקטי IT Risk וניהול ממשל (GRC) עבור Deloitte US ועבור ארגונים מובילים בישראל, כולל בנקים וחברות טכנולוגיה נסחרות. תחומי האחריות כוללים הובלת מספר פרויקטים במקביל בתחומי אבטחת מידע, GRC, SOC2/SOC1, סקרי סיכוני מערכות מידע וסייבר, ביקורות פנימיות וחיצוניות, ייעוץ בנושא בקרה, אוטומציה, ענן, דיגיטל והרשאות/SoD, לצד עבודה שוטפת מול לקוחות, הנחיית צוותים זוטרים, ופיתוח קשרים עם הנהלה בכירה. עבודה היברידית.
דרישות:
תואר ראשון - חובה.

תואר שני - יתרון.

לפחות 5 שנות ניסיון בתחום אבטחת מידע/ GRC/ SOC2/ ISO27001 או ניהול סיכוני IT דומים - חובה.

ניסיון מוכח בהובלת צוותים או בניהול פרויקטים - חובה.

שליטה באנגלית ברמה גבוהה (דיבור וכתיבה) - חובה.

שפות נוספות - יתרון.

ידע וניסיון מעמיק בסטנדרטים ותקני אבטחה/ציות (Soc2, Soc3, FedRAMP, CJIS, GDPR, NIST 800-53 וכדומה).

יכולת אנליטית גבוהה ויכולות הצגה, תקשורת בין-אישית ועמידה מול קהל.

יכולת ניהול ובקרה על מספר פרויקטים במקביל, סדר עדיפויות גבוה ועמידה ביעדים תחת לחץ.

יתרון - ניסיון בעבודה עם צוותים או לקוחות גלובליים.

אנו ב-Deloitte מאמינים כי גיוון והכלה בקרב אנשינו הוא מרכיב קריטי בהצלחה שלנו ולכן אנו מטפחים תרבות ארגונית שמכילה ומאמצת גיוון על כל צורותיו המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8728427
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים ביוניטסק
סוג משרה: משרה מלאה ועבודה היברידית
לתפקיד מוביל ומאתגר בתחום הסייבר דרוש/ה ראש צוות IR לניהול והובלת צוות תגובה לאירועי סייבר ברמת Tier 3.
התפקיד כולל הובלה מקצועית של צוות Incident Response.

תיאור התפקיד:
ניהול והובלת צוות IR ותכנון תוכנית עבודה שנתית, כולל הצבת יעדים, תעדוף משימות וניהול שוטף
הובלת חקירות סייבר מורכבות מקצה לקצה (Tier 3) כולל Forensics ו-Threat Hunting
פיתוח ותחזוקה של חוקי זיהוי ב-EDR ובמערכות הגנה נוספות
עבודה על שיפור מתמיד של Playbooks והטמעת בקרות מבוססות Threat Intelligence ו-MITRE ATT CK
ניהול והפעלת ספק SOC חיצוני כולל SLA, KPI ובקרת איכות
אחריות על מוכנות לוגים ויכולת חקירה אפקטיבית
הובלת POCs, חדשנות ובחינת טכנולוגיות הגנה מתקדמות
הפעלת תהליכי Purple Team ו-Breach Attack Simulation לשיפור יכולות זיהוי ותגובה
עבודה שוטפת מול צוותי IT, ענן, תשתיות, BCP, מודיעין סייבר והנהלה
דרישות:
ניסיון של 3+ שנים בחקירות אירועי סייבר ברמת Tier 3 - חובה
ניסיון בניהול צוות טכני - חובה
ניסיון בעבודה ו/או ניהול SOC חיצוני כולל SLA - חובה
ניסיון בכתיבת חוקי זיהוי ב-EDR - חובה
ניסיון בעבודה עם SIEM (Sentinel / Splunk) וכתיבת שאילתות KQL / SPL - חובה
הבנה עמוקה בתשתיות IT: רשתות, Windows/ Linux, Active Directory / Entra ID - חובה
היכרות עם MITRE ATT CK ותרגום TTPs לבקרות - יתרון
ניסיון ב-Purple Team / Red Team / Pentest - יתרון
ניסיון עם מערכות סימולציה התקפית - יתרון
הסמכות רלוונטיות (GCIH / GCFA / OSCP / CRTO וכו) - יתרון
אנגלית ברמה גבוהה מאוד המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8723551
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
21/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
our mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our company values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day. our mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. In alignment with our company values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Responsibilities
Conduct investigations of advanced threat actor activity across cloud, identity, endpoint, and on-premises environments to identify intrusion methods, attacker objectives, and operational patterns.
Identify and track emerging threats, attacker techniques, campaigns, and trends to enable proactive detection, disruption, and defence before customer impact.
Develop detections, mitigations, and security guidance by identifying attack paths, security weaknesses, and opportunities to strengthen defensive coverage.
Build investigative tooling, automations, proof-of-concepts, and research capabilities that improve the scale and effectiveness of security investigations.
Drive product, detection, and engineering improvements by translating investigation findings into actionable changes across our company security platforms and services.
Providing recommendations to improve customers cybersecurity posture going forward and performing threat intelligence knowledge transfer to prepare customers to defend against todays threat landscape
Synthesize complex technical research into clear, actionable intelligence, reports, briefings, and recommendations for technical and executive audiences.
Advance understanding of nation-state, cybercriminal, and emerging threat actors through research, attribution, capability assessments, and adversary tracking.
Share findings, influence strategy, and drive organizational change through knowledge transfer, best practices, and adoption of security improvements.
Requirements:
4+ years of experience in Threat Hunting, Incident Response (DFIR), Threat Intelligence, or Security Research.
Experience investigating sophisticated cyber threats, including APT or nation-state activity.
Experience working with security telemetry, logs, and SIEM platforms.
Familiarity with KQL or equivalent query languages (Splunk, Humio, Kibana, etc.).
Experience with EDR and security monitoring technologies such as our company Defender, Sentinel, CrowdStrike, or similar platforms.
Ability to analyze security data, investigate attacker behavior, and identify indicators of compromise (IOCs), indicators of activity (IOAs), and TTPs.
Understanding of scripting or the ability to read and interpret code and automation workflows.
Strong communication skills in English and ability to work in a global team environment.
Preffered Qualifications
Industry certifications in cybersecurity, DFIR, incident response, or threat hunting (e.g., CISSP, GIAC).
Experience identifying novel attacker techniques and translating findings into scalable detections.
Experience performing malware analysis or reverse engineering.
Experience analyzing large-scale security telemetry and hunting across enterprise environments.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8748025
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a Threat Hunting Expert to join our team and shape the future of threat detection. In this role, you'll be at the forefront of identifying and analyzing emerging threats, helping to shape the features of our Threat Detection platform. You'll be crafting detection logic and hunting strategies that enable security teams to identify and respond to advanced threats across their entire environment.


WHAT YOU WILL DO

Work directly with customers to help them solve concrete security pain points and operational use cases using , primarily during POVs and onboarding.
Perform advanced threat hunting across customer datasets to identify meaningful security findings, including compromise evidence, exploitation indications, suspicious activities, and visibility or posture gaps.
Build and evolve internal tools and AI-powered capabilities that support threat hunting, anomaly detection, and exploratory analysis.
Translate immediate customer security needs into ad-hoc security content, including detections, threat hunting notebooks, and investigative workflows.
Participate in customer-facing sessions alongside Sales Engineers and Technical Account Managers to present findings, explain security context, and walk through capabilities and content.
Deliver technical demonstrations, workshops, trainings, and hands-on sessions that show customers how to use for their security workflows.
Research emerging threats, including new CVEs and active campaigns, in collaboration with the CTI team, and translate them into immediate detections and threat hunting content.
Publish public-facing technical content on threat hunting and SecOps, including blog posts, webinars, open-source tools, and research findings.
Requirements:
At least 6 years of hands-on experience in security operations, threat hunting, incident response, or detection engineering, working with real production data.
Strong hands-on experience investigating security events, performing advanced threat hunting, and identifying meaningful findings.
Deep familiarity with common attack techniques, attacker behavior, and modern threat landscapes across endpoint, identity, network, cloud, and application environments.
Comprehensive knowledge of security controls and security architectures across cloud, network, identity, application, and endpoint environments.
Experience working with large-scale security datasets and performing exploratory analysis, anomaly detection, and investigative research.
Ability to write efficient, readable code and scripts for analysis, automation, and internal tooling used by the team.
Comfort working directly with customers in technical discussions, explaining findings, tradeoffs, and investigative approaches clearly and practically.
Experience collaborating with product, engineering, or research teams to influence tooling, workflows, and platform capabilities.
Strong written communication skills, with the ability to produce clear technical documentation and public-facing content when needed.
Excellent English communication skills, both written and verbal.
Curiosity and initiative to research emerging threats, new techniques, and evolving attacker behavior, and apply that research in practice.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8762126
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/07/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
our company Research (CPR) is looking for a Threat Researcher to join its Threat Intelligence Analysis (TIA) team. The team is responsible of discovering, analyzing and tracking advanced threat actors and campaigns, with a strong focus on high-end cybercrime and state-sponsored activities. You will join a team of motivated, independent & highly technical individuals and contribute the effort to protect our company customers and empower the company brand.
Key Responsibilities
Identify, understand and monitor advanced campaigns using publicly available sources as well as internal telemetry.
Analyze malware and other hacking tools utilized by threat actors in active campaigns and intrusions.
Create technical research content for public and private intelligence reports.
Help build protections and detections based on deep understanding of advanced threat actors Tactics Techniques and Procedures (TTPs).
Collaborate with other security teams to assist threat intelligence and research tasks.
Requirements:
Your Knowledge & Skills
5+ years of experience as a threat researcher, incident responder, malware analyst, detection engineer or other relevant roles.
Practical experience in tracking state-sponsored or advanced financially motivated actors - including malware, infrastructure and TTPs.
Profound knowledge and understanding of malware and common attacking techniques.
Hands-on experience in automating and optimizing hunting and enrichment processes using code (preferably Python).
Familiarity with query languages and data exploration tools.
Ability to translate technical findings into actionable detection and prevention signatures.
Experience in writing technical blog posts and technical analysis reports.
Experience in public speaking and presentation of research in cyber security conferences .
Fluent English.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8723028
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a SecOps Lead , you will own the core of the security operations function: detection, response, automation, and the processes that connect them. You will guide incident response from first alert through post-mortem, keeping efforts structured and stakeholders informed along the way. You will shape how the team detects, triages, and resolves, and communicate that work clearly to leadership, engineering, and customers.

This is a hands-on role with broad ownership. You should be comfortable writing a detection rule, coordinating a live incident, and walking stakeholders through a post-incident review.

Key Responsibilities

Lead Incident Response: Own the end-to-end incident response lifecycle across infrastructure and enterprise browser platform, driving investigations, coordinating responders, and ensuring timely resolution and post-incident improvements.
Own the IR Framework: Build, maintain, and continuously improve incident response processes, including runbooks, severity definitions, escalation paths, on-call procedures, and communication standards.
Drive Detection Engineering: Design, implement, and continuously improve high-fidelity detections across SIEM, EDR, cloud, and endpoint security platforms, closing visibility gaps and strengthening detection coverage.
Automate Security Operations: Build automation and AI-driven workflows that streamline triage, investigation, enrichment, and response, reducing manual effort and improving operational efficiency.
Threat Hunting & Research: Proactively hunt for threats, leverage threat intelligence, and identify emerging attack techniques relevant to modern enterprise environments.
Own Security Operations: Serve as the technical owner for Security Operations within Product Security, driving strategy, setting best practices, and continuously improving detection and response capabilities.
Partner Across Engineering: Collaborate closely with Engineering, IT, Infrastructure, and Compliance teams to embed security into new services, infrastructure changes, FedRAMP initiatives, and customer-facing security requirements.
Communicate During Incidents: Provide clear, timely communication throughout incident response, keeping technical teams, leadership, and stakeholders aligned on impact, progress, risks, and next steps.
Requirements:
5+ years of hands-on experience in Security Operations, Incident Response, or Detection Engineering.
Proven experience leading end-to-end incident response for high-severity security incidents in cloud or enterprise environments.
Strong understanding of detection engineering, threat hunting, and modern security operations, with hands-on experience using SIEM, EDR, and cloud security platforms.
Experience building and improving incident response processes, including runbooks, severity frameworks, escalation paths, and post-incident reviews.
Hands-on experience automating security operations using SOAR platforms and AI-powered workflows (Torq, Tines, or similar).
Solid understanding of AWS security fundamentals, including IAM, CloudTrail, and containerized environments (EKS is an advantage).
Strong knowledge of modern attack techniques, threat intelligence, detection methodologies, and investigation best practices.
Excellent written and verbal communication skills, with the ability to communicate effectively during incidents and present findings to both technical and non-technical stakeholders.
Experience collaborating across Engineering, Infrastructure, IT, and Compliance teams to improve security posture.
Experience mentoring engineers or leading cross-functional security initiatives is an advantage.
Familiarity with SOC2, FedRAMP, or other regulated compliance frameworks is a plus.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769437
סגור
שירות זה פתוח ללקוחות VIP בלבד