דרושים » אבטחת מידע וסייבר » SecOps Detection & Response

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
20/07/2026
משרה זו סומנה ע"י המעסיק כלא אקטואלית יותר
מיקום המשרה: תל אביב יפו
סוג משרה: משרה מלאה
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a hands-on role that balances deep technical work along with building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by.

Youre welcome to work in our offices in Tel Aviv, Israel.

Your responsibilities will include:

Build and lead global DFIR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders.
Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases.
Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction.
Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements.
Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR.
Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA).
Raise the teams technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness.
Requirements:
7+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise).
Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2).
Technical Expertise

Deep knowledge of Windows and Linux internals, with proven disk and memory forensics capability.
Strong cloud-native platform security: containers and Kubernetes, CI/CD, secrets management, cloud control planes, and IAM attack paths.
Fluency in attacker TTPs (MITRE ATT&CK, including the Cloud and Containers matrices), and hands-on experience with EDR, SIEM, and forensic tooling (e.g., Velociraptor, Volatility, X-Ways/EnCase).
Strong scripting and data-analysis skills (Python, PowerShell, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818167
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Data Protection Lead to join the Cyber Security organization.

This role combines hands-on Data Leakage Prevention (DLP) engineering with Data Security Posture Management (DSPM) to deliver end-to-end data protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will own the data protection lifecycle from discovery and classification through policy enforcement and incident response. The role requires deep technical proficiency in DLP platforms and DSPM tooling, combined with the ability to collaborate with Security, IT, Engineering, Product, Privacy and GRC teams to reduce data exposure risks and embed strong data governance practices.

Your responsibilities will include:
Lead and own the organizations data protection domain, including strategy, standards, and hands-on technical implementation
Engineer, deploy, and continuously tune DLP policies across endpoints, email, SaaS, network proxies, and cloud platforms - covering both inline and API-based enforcement modes.
Design and implement DSPM solutions to gain continuous visibility into sensitive data posture, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Drive data discovery initiatives to identify and inventory sensitive data across databases, SaaS applications, endpoints, and cloud storage.
Define and implement data classification frameworks, labeling standards, and data handling policies integrated with DLP and DSPM controls.
Build and maintain DLP detection rules, regular expressions, fingerprinting, and machine learning-based classifiers to minimize false positives and maximize coverage.
Integrate DSPM findings into DLP enforcement workflows to create a closed-loop data protection architecture.
Define and enforce data access governance, including least-privilege principles and monitoring of sensitive data access patterns.
Monitor, triage, and investigate DLP alerts and DSPM-identified risks, collaborating with SOC and Security teams on escalation and remediation.
Conduct risk assessments and identify gaps in data protection controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to data security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed data security controls into CI/CD pipelines, systems, and workflows.
Maintain documentation, runbooks, and guidelines for DLP operations, DSPM posture management, and data security practices.
דרישות:
6+ years of experience in cyber security, with a strong focus on data security, data protection, or information security.
Proven hands-on engineering experience with enterprise DLP platforms - including policy authoring, rule tuning, incident workflow configuration, and platform administration (e.g., Microsoft Purview DLP, Symantec DLP, Forcepoint, or equivalent).
Hands-on experience deploying and operating DSPM tools (e.g., Cyera, Varonis, Rubrik Security Cloud, Normalyze, Securiti, or equivalent) to manage cloud data exposure and classification at scale.
Deep understanding of DLP enforcement mechanisms: endpoint DLP, network DLP, email DLP, and cloud/API-based DLP controls.
Strong experience with data discovery and classification across cloud environments (AWS, Azure, GCP), SaaS platforms, and on-premises systems.
Ability to write and optimize detection logic - regular expressions, data fingerprinting, document fingerprinting, and EDM (Exact Data Matching).
Experience integrating DLP and DSPM tools with SIEM, SOAR, and ticketing systems for alert routing and automated response.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governanc המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818177
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
18/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Security Engineer with 1-2 years of experience to join our Internal Security team.
This role combines hands-on cloud and security operations with support for GRC and compliance activities.
You will be involved in securing our cloud, SaaS, and AI-driven systems, monitoring security events, and helping maintain our overall security posture. In parallel, you will support customer security questionnaires and compliance processes.

What You'll Do:
Monitor, triage, and investigate security alerts and incidents across cloud and security tools (EDR, CASB, ZTNA, SaaS security platforms, and identity providers), and support response and remediation activities
Assist in securing cloud environments (AWS/GCP/Azure), including IAM, access controls, network security, and CI/CD pipeline security
Work closely with DevOps and IT teams to implement and enforce security best practices across infrastructure, endpoints, and SaaS systems
Support vulnerability management processes, including scanning, prioritization, and remediation tracking
Support risk management processes by identifying, assessing, and tracking risks, including vulnerability management, remediation efforts, and control gaps
Support customer security questionnaires (RFPs/RFIs) with accurate technical responses
Assist in maintaining compliance with frameworks such as SOC 2 and ISO 27001, including preparing audit evidence and documentation
Requirements:
Who You Are?
1-2 years of experience in cybersecurity, cloud security, and security operations
Basic hands-on experience with cloud platforms (AWS, GCP, or Azure)
Understanding of core security concepts: IAM, networking, least privilege, and secure configurations
Experience or strong interest in collaborating with DevOps and IT teams, alongside a focus on AI security, data protection, and emerging technologies
Familiarity with security tools such as EDR, vulnerability scanners, or SaaS security solutions
Strong analytical and troubleshooting skills, with high attention to detail and the ability to manage multiple tasks
Good communication skills and ability to work cross-functionally
Willingness to learn and grow in both technical security and GRC domains
Nice to Have:
Experience with cloud security best practices and securing CI/CD pipelines and infrastructure-as-code (Terraform, etc.)
Familiarity with identity systems (Okta, Azure AD, etc.)
Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8787070
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Senior Security Engineer.
As a Senior Product Security Engineer, you will help ensure that security is built into the products, platforms, AI systems, and clinical workflows that support healthcare providers and patients at scale. This is a hands-on technical role focused on securing real systems in production, influencing architecture, and partnering closely with engineering, AI, DevOps, product, quality and regulatory.
You will work across cloud-native services, medical imaging workflows, healthcare integrations, AI/ML pipelines, APIs, data flows, and regulated product development processes. Your work will directly support ability to deliver secure, reliable, and trusted clinical AI solutions to healthcare organizations worldwide.
What Makes This Role Unique :
Clinical AI with real-world patient impact - we operate in an environment where security is not only about protecting systems and data. Security decisions can affect clinical workflows, care-team coordination, customer trust, and patient safety.
Highly sensitive healthcare data - You will help protect medical imaging data, clinical metadata, PHI/PII, customer environments, and AI-driven workflows that require strong privacy, access control, data protection, and auditability.
Security for AI/ML and medical imaging systems - The role extends beyond traditional AppSec into AI/ML security, data pipeline protection, inference integrity, model-related risks, and misuse scenarios in clinical workflows.
Complex healthcare integrations - we integrates with hospital systems and healthcare workflows that may include PACS, EHR, VNA, RIS/worklists, scheduling systems, and communication platforms. You will help secure the data flows, authentication models, APIs, and deployment patterns behind these integrations.
Engineering-driven security in a regulated environment - This is not a checkbox compliance role. However, because operates in healthcare and clinical AI, security must be practical, evidence-based, and aligned with regulatory, customer, and quality expectations.
Cloud-native scale and production ownership - You will work with modern cloud infrastructure, Kubernetes, containers, CI/CD pipelines, identity and access management, observability, vulnerability management, and software supply-chain controls.
דרישות:
5+ years of experience in Product Security, Application Security, Cloud Security, or a similar hands-on security engineering role.
Strong hands-on experience securing production systems, not only performing assessments or reviews.
Strong understanding of secure design, threat modeling, and architecture risk analysis.
Deep knowledge of application security, including OWASP Top 10, API security, authentication, authorization, access control, secure session handling, input validation, and modern attack vectors.
Experience securing distributed systems, APIs, web applications, backend services, and cloud-native architectures.
Strong experience with cloud environments, especially AWS and/or Azure, including IAM, network security, encryption, logging, monitoring, and workload security.
Experience with Kubernetes, containers, infrastructure-as-code, CI/CD pipelines, and modern DevOps workflows.
Practical experience with security tooling such as SAST, SCA, IaC scanning, container scanning, secrets detection, SBOM tools, vulnerability scanners, and cloud security tools.
Experience with vulnerability management, risk prioritization, remediation planning, and working with engineering teams to fix issues at scale.
Strong understanding of software supply-chain security, including dependency risk, build/release integrity, artifact security, and third-party component governance.
Experience working with modern development stacks such as Python, Java, JavaScript/TypeScript, React, microservices, APIs, and cloud-native services.
Ability to influence engineers through technical credibility, practical guidance, and strong collaboration.
Strong commu המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805560
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Security Engineering Lead to join the Cyber Security organization, reporting to the Corporate Security Engineering Manager under the CISO.

This is a senior technical lead role focusing on engineering and execution without direct people management responsibilities. This role combines hands-on security engineering to deliver end-to-end protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will be responsible for implementing, managing, integrating and maintaining security systems across the organizations IT landscape. The role requires deep technical proficiency in multiple platforms and tools, combined with the ability to collaborate with Security, IT, Engineering, Product, GRC and other business units to reduce risks and embed strong security practices.

Your responsibilities will include:

Engineer, deploy, and continuously tune systems such as Identity & Access, Threat Detection & Response, Cloud & Network Security.
Define, enforce and maintain security policies & configurations across endpoints, email, SaaS, network, and cloud platforms.
Design and implement solutions to gain continuous visibility into systems and processes, sensitive data, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Monitor, triage, and investigate security alerts and risks, collaborating with Security, IT, Network teams on escalation and remediation.
Conduct risk assessments and identify gaps in security controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed security controls into systems, and workflows.
Maintain documentation, runbooks, and guidelines for operations, security posture management, and security practices.
Requirements:
6+ years of experience in IT security, with a strong focus on System, Network, Information, Cyber. With at least 3 years in a Security Engineering role.
Proven hands-on engineering experience with enterprise security platforms - including policy authoring, tuning, incident workflow configuration, and platform administration.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governance principles.
Experience working cross-functionally with Security, IT, Engineering, Product, and GRC teams.
Strong analytical mindset with the ability to communicate security risks clearly to technical and non-technical stakeholders.
Excellent written and verbal communication skills in English.
Proactive, detail-oriented, and ownership-driven.
Hand-on experience with multiple technologies such as: XDR (Extended Detection & Response), SWG (Secure Web Gateway), DLP (Data Leakage Prevention), Email Security, Network security (Firewalls, NAC, NDR), IGA (Identity Governance & Administration), CASB (Cloud Access Security Broker), PAM (Privileged Access Management), EPM (Endpoint Privilege Management), BAS (Breach & Attack Simulation), Vulnerability Scanners, SIEM (Security Information & Event Management), SOAR (Security Orchestration, Automation & Response), CTI (Cyber Threat Intelligence), Patch Management, TPRM (Third-Party Risk Management), EASM (External Attack Surface Management).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817717
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are seeking an experienced Security Analyst - Tier 2 for its Security Operations Center (SOC). This role is a hands-on position built for depth, serving as the investigative core of the SOC, focused on evidence and grounded conclusions. This role reports to the SOC Manager, under the Detection and Response function within the CISO Office.

You are welcome to work in our offices in Tel Aviv, Israel.

Key Responsibilities
Investigate escalated security alerts across endpoint, identity, cloud, email, and network layers.
Determine scope, impact, and root cause using EDR, SIEM, and supporting telemetry.
Escalate suspected incidents to the Incident Response team and complex investigations to Tier 3.
Provide structured feedback to relevant stakeholders on detection or prevention quality, false-positive patterns, and coverage gaps discovered during investigations.
Contribute to and refine SOC runbooks, triage guides, and investigation procedures.
Review Tier 1 escalations, coach on handoff quality, and act as the analytical reference during triage.
Document investigations to a standard that supports handoff, quality review, and lessons learned.
Participate in the on-call rotation, acting as the investigative point of contact outside business hours.
Requirements:
Around 5-7 years of hands-on security operations experience, with proven depth in alert investigation.
Experience taking investigations to a clear verdict, including confirmed incidents.
Technical Expertise

Strong working command of EDR platforms and SIEM-based investigation, including writing and adapting queries independently.
Solid understanding of attacker techniques, with the ability to map findings to MITRE ATT&CK in analysis and reporting.
Investigation capability across at least two of: endpoint, identity, cloud, email, or network domains.
Windows and Linux internals at the depth required for log and artifact analysis: processes, authentication flows, and persistence mechanisms.
Solid networking fundamentals: TCP/IP, DNS, HTTP/S, and the ability to interpret network telemetry.
Scripting ability (Python or similar) for analysis at scale, and familiarity with SOAR platforms.
Certifications such as BTL2, OSDA, or CDSA are an advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818090
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
our companys Harmony SASE is looking for an Information Security Manager to join its staff.
This is a unique opportunity for you to work in the #1 worldwide Cyber Security Company, gain expertise and experience leading the information security program for the best of SASE (Secure Access Service Edge).
Key Responsibilities
As Information Security Manager you will:
Governance, Risk & Compliance
Lead and manage the Product Security team
Build, operate, and continuously improve the Harmony SASE Information Security Management System (ISMS), aligning policies, standards, and controls with our company and industry best practices.
Own the Harmony SASE compliance roadmap - lead and maintain certifications and attestations including ISO/IEC 27001, SOC 2 Type II, GDPR, IRAP and C5
Lead enterprise risk assessments and the third-party / vendor risk program, ensuring risks are identified, prioritized, and treated.
Coordinate internal and external audits, manage evidence collection, and remediate findings to closure.
Product & Application Security
Develop and implement a comprehensive AI - Secure Software Development Lifecycle (AI S-SDLC) framework, embedding security into every phase of the SDLC and CI/CD pipelines.
Conduct threat modeling and secure architecture reviews for new and existing Harmony SASE features, partnering with R&D to mitigate vulnerabilities by design.
Operate the application security tooling stack - ASPM, SAST, DAST, SCA, AI Security Scanning and secret scanning - at scale, and partner with development teams to drive findings to remediation while maintaining developer productivity.
Champion secure coding practices and OWASP Top 10 awareness across R&D.
Operational Security & Incident Response
Lead security incident response for Harmony SASE - preparedness, detection, containment, eradication, recovery, and lessons-learned - covering both product and information security incidents.
Oversee identity and access governance, ensuring least-privilege, segregation of duties, and access reviews across production and corporate environments.
Design and operate security automation to enhance the efficiency and coverage of security operations.
Security Culture & Enablement
Foster a culture of security awareness and continuous improvement; deliver targeted training for engineers, operations, and broader staff.
Lead responses to customer security questionnaires, RFPs, and due-diligence requests, representing Harmony SASEs security posture to customers and partners.
Stay current on the evolving Threats Landscape, regulations, and technologies, and translate them into pragmatic improvements to the security program.
Requirements:
We are looking for you:
Bachelors degree in computer science, Information Security, or related field.
Minimum of 5 years of experience in information security or application/product security, with at least 2 year in a leadership role.
Proven experience building or operating an Information Security Management System (ISMS) and leading certifications such as ISO/IEC 27001 and SOC 2.
Working knowledge of GDPR, PCI-DSS, and NIST CSF / 800-53; familiarity with HIPAA, FedRAMP, DORA, Cyber Essentials, C5, IRAP, AI Security Frameworks and the Cloud Controls Matrix (CCM).
Hands-on experience with S-SDLC, threat modeling, and application security tooling such as ASPM, SAST, and DAST in complex, high-scale environments.
Strong understanding of risk management, third-party risk, identity and access governance, and incident response.
Excellent communication and leadership skills, with the ability and passion to drive change across R&D and the broader organization.
Reports to the Harmony SASE Head of Architecture (R&D Director) and partners closely with R&D, DevOps, IT, Legal, and the company Corporate Security organization.
Relevant certifications such as CISM (preferred), CISSP, CCSP, ISO 27001 Lead Auditor / Lead Implementer, CCSP or CSSLP are desirable.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785659
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are seeking a deeply experienced Security Analyst - Tier 3 for its Security Operations Center (SOC). This role is a senior individual-contributor position, leading challenging investigations, setting the standards the SOC operates by. This role reports to the SOC Manager, under the Detection and Response function within the CISO Office.

Your responsibilities will include:

Lead complex, multi-stage, multi-domain investigations end to end, from scoping through deep technical analysis to a clear determination of impact and root cause.
Serve as the SOC's senior escalation point and the quality gate for investigations across the team.
Support the Incident Response team during confirmed incidents with continued telemetry investigation, scoping, and analytical depth.
Continuously sharpen how the SOC investigates, identifying gaps in methods, runbooks, and tooling through daily casework and turning them into concrete improvements.
Mentor Tier 1 and Tier 2 analysts through case reviews, coaching, and pairing during investigations.
Partner with Security Engineering, Platform Security, Threat Intelligence, SOC Automation, and additional teams to turn what the SOC learns into stronger detection and response across .
Participate in readiness activities - tabletops, post-incident reviews, and purple-team engagements.
Participate in the on-call rotation as the senior point of contact outside business hours.
Requirements:
Around 8-10 years of hands-on experience in security operations or incident response, with a track record of leading complex investigations.
Technical Expertise

Expert-level investigation capability across multiple domains: endpoint, identity, cloud, and network.
Solid understanding of cloud-native environments, including containers, Kubernetes.
Deep practical fluency with EDR, SIEM query languages, and log analysis.
Deep knowledge of Windows and Linux internals, applied to artifact and behavioral analysis.
Fluency in attacker TTPs (MITRE ATT&CK), including the Cloud and Containers matrices.
Strong scripting and data-analysis skills (Python, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
Advanced certifications such as GCIH, GCFA, GNFA, GCFE, or OSCP are an advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818085
סגור
שירות זה פתוח ללקוחות VIP בלבד