דרושים » אבטחת מידע וסייבר » Incident Response Engineer

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an Incident Response Engineer to join the IR team. This technical role focuses on active investigation, threat mitigation, and the continuous improvement of the security organizations posture through detection engineering and automation development.
The successful candidate will be responsible for the full lifecycle of security incidents, from initial triage to recovery. Beyond reactive response, this role involves tuning SIEM correlation rules and developing SOAR workflows to increase operational efficiency.
What Youll Be Doing:
Incident Management: Execute the IR lifecycle (Triage, Containment, Eradication, Recovery) for complex security events.
Technical Investigation: Perform root cause analysis and forensic examination across Windows, Mac, and Linux environments.
Detection & Tuning: Collaborate with the IR team to create, test, and tune SIEM rules and dashboards to reduce false positives and improve visibility.
Automation Engineering: Build and refine SOAR playbooks and automated response actions to streamline repetitive investigation tasks.
Cloud Security: Monitor and mitigate cloud-native threats across Azure, AWS, and GCP environments.
Requirements:
Experience as a SecOps/IR Analyst or Engineer with a heavy focus on active investigation.
Deep understanding of the Incident Response lifecycle (Triage, Containment, Eradication, Recovery).
Hands-on experience handling and managing security alerts, performing root cause analysis, and leading investigations.
Experience working across cloud providers (Azure, AWS, GCP) to identify and mitigate cloud-native threats.
Strong knowledge of operating systems (Mac, Windows, Linux) and their respective artifacts.
Proficiency with Splunk or other SIEM platforms for log analysis and threat hunting.
Experience with XSOAR or other security automation tools from an end-user/analyst perspective.
Strong knowledge of security technologies, including EDR, Mail Relay, Vulnerability Scanning, Secure Access, and MDM.
Scripting experience with Python or Bash to assist in data parsing and investigation tasks.
Nice to Have:
Detection Engineering: Ability to build and improve SIEM rules, correlations, and dashboards.
Automation Development: Experience developing new SOAR workflows, automated actions, and response playbooks.
Technical Literacy: Familiarity with REST APIs and Regex for advanced querying and tool integration.
Container Security: Familiarity and experience with K8S (Kubernetes).
Consultative Skills: Ability to guide best practices in Cloud Security and SIEM operations.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8794710
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a Security Operations Engineer , you will be a core member of the SecOps team, owning incident detection, triage, and response across infrastructure and enterprise browser platform. You will work closely with the SecOps Lead to mature our IR capabilities, build the automation and tooling that power our operational workflows, and help keep and its customers ahead of real-world threats.

This is a hands-on, build-and-operate role - ideal for someone who is equally comfortable writing a detection rule, investigating a live incident, and shipping a Torq workflow before end of day.

Key Responsibilities

Incident Response: Lead and participate in the full incident lifecycle - detection, triage, investigation, containment, and post-mortem. Own runbooks and ensure they reflect current threat landscape and tooling.
Detection Engineering: Develop, tune, and maintain detection rules across SIEM, EDR, and security audits. Minimize false positives; maximize signal value.
Security Automation: Build and improve automated response workflows using platforms like Torq; reduce manual toil on alert triage, enrichment, and escalation paths.
Threat Monitoring & Hunting: Continuously monitor the environment for anomalies and indicators of compromise; proactively hunt for threats aligned to our threat model.
Cloud Security Operations: Investigate and triage findings from cloud-native security tooling (Wiz, AWS CloudTrail); collaborate with engineering teams on remediation of infrastructure-level issues.
Tooling & Integrations: Contribute to the ongoing development of the SecOps toolchain - integrating alert sources, building dashboards, and improving the Jira-based alert center.IR Documentation: Maintain incident.io flows, response playbooks, and post-incident reports; contribute to the team's runbook hub.
Requirements:
3+ years of hands-on experience in security operations, incident response, or detection engineering.
Practical experience with SIEM, EDR, and cloud security platforms - Wiz, Coralogix, or equivalents.
Proficiency in scripting and automation; experience building or extending security automation workflows (Torq, Tines, SOAR, or similar).
Strong grasp of attacker techniques, common detection evasion methods, and incident investigation methodology.
Ability to work independently and drive initiatives end-to-end; comfortable in a fast-moving environment with shifting priorities.
Experience with threat intelligence operationalization is a plus.
Familiarity with compliance frameworks (SOC2 or equivalent) is a plus.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769447
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a SecOps Lead , you will own the core of the security operations function: detection, response, automation, and the processes that connect them. You will guide incident response from first alert through post-mortem, keeping efforts structured and stakeholders informed along the way. You will shape how the team detects, triages, and resolves, and communicate that work clearly to leadership, engineering, and customers.

This is a hands-on role with broad ownership. You should be comfortable writing a detection rule, coordinating a live incident, and walking stakeholders through a post-incident review.

Key Responsibilities

Lead Incident Response: Own the end-to-end incident response lifecycle across infrastructure and enterprise browser platform, driving investigations, coordinating responders, and ensuring timely resolution and post-incident improvements.
Own the IR Framework: Build, maintain, and continuously improve incident response processes, including runbooks, severity definitions, escalation paths, on-call procedures, and communication standards.
Drive Detection Engineering: Design, implement, and continuously improve high-fidelity detections across SIEM, EDR, cloud, and endpoint security platforms, closing visibility gaps and strengthening detection coverage.
Automate Security Operations: Build automation and AI-driven workflows that streamline triage, investigation, enrichment, and response, reducing manual effort and improving operational efficiency.
Threat Hunting & Research: Proactively hunt for threats, leverage threat intelligence, and identify emerging attack techniques relevant to modern enterprise environments.
Own Security Operations: Serve as the technical owner for Security Operations within Product Security, driving strategy, setting best practices, and continuously improving detection and response capabilities.
Partner Across Engineering: Collaborate closely with Engineering, IT, Infrastructure, and Compliance teams to embed security into new services, infrastructure changes, FedRAMP initiatives, and customer-facing security requirements.
Communicate During Incidents: Provide clear, timely communication throughout incident response, keeping technical teams, leadership, and stakeholders aligned on impact, progress, risks, and next steps.
Requirements:
5+ years of hands-on experience in Security Operations, Incident Response, or Detection Engineering.
Proven experience leading end-to-end incident response for high-severity security incidents in cloud or enterprise environments.
Strong understanding of detection engineering, threat hunting, and modern security operations, with hands-on experience using SIEM, EDR, and cloud security platforms.
Experience building and improving incident response processes, including runbooks, severity frameworks, escalation paths, and post-incident reviews.
Hands-on experience automating security operations using SOAR platforms and AI-powered workflows (Torq, Tines, or similar).
Solid understanding of AWS security fundamentals, including IAM, CloudTrail, and containerized environments (EKS is an advantage).
Strong knowledge of modern attack techniques, threat intelligence, detection methodologies, and investigation best practices.
Excellent written and verbal communication skills, with the ability to communicate effectively during incidents and present findings to both technical and non-technical stakeholders.
Experience collaborating across Engineering, Infrastructure, IT, and Compliance teams to improve security posture.
Experience mentoring engineers or leading cross-functional security initiatives is an advantage.
Familiarity with SOC2, FedRAMP, or other regulated compliance frameworks is a plus.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769437
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Security Operations & Automation
About Your Day-to-Day:
As a Security Operations & Automation, you'll be the hands-on architect of how we detect, investigates, and responds to threats - built around AI agents and deep tooling integrations, not manual triage. You'll own incident response across corporate systems, workstations, and identity, unify alerts from every source - including cloud-originated signals that need a response - into a single SOAR/XDR fabric, and deploy AI agents to handle first-line investigation and response.
You'll work closely with IT and the Cloud Security team - taking the lead on investigation, triage, and response while they own the underlying cloud and SDLC architecture - and turn complex security signals into structured, AI-assisted, largely autonomous outcomes - fighting fire with fire.
Responsibilities:
Architect and own our AI-driven detection and response stack, integrating SIEM, XDR, SOAR, EDR, and IAM into a single automated fabric rather than siloed tools.
Deploy and tune AI agents to handle first-line alert triage, enrichment, and investigation, with humans engaged only for true edge cases - manual L1 triage is the exception, not the default.
Build SOAR playbooks and integrations across the security and IT toolchain (endpoint, identity, ticketing, chat) so detection, enrichment, and remediation run automatically end to end - regardless of which system or platform an alert originates from.
Own the alert pipeline as a whole: unify signals from EDR, IAM, and other sources - including cloud and SaaS alerts surfaced by the Cloud Security team - into one triage and response workflow, so nothing falls through the cracks between tools.
Evaluate and integrate best-of-breed, AI-native security tools - SIEM, XDR, SOAR, EDR, email security, AI guardrails, ZTNA, and others - wiring each into the unified detection and response fabric rather than running them as siloed point solutions. Hands-on tool integration (APIs, connectors, log and telemetry ingestion) is a core skill for this role, not an occasional task.
Drive vulnerability and patch management across corporate systems and endpoints, automating prioritization and remediation workflows and coordinating with IT against strict SLAs.
Build and tune detection rules specific to our environment, treating detection as code and feeding AI-driven correlation across the XDR layer.
Maintain security dashboards (MTTD/MTTR, automation rate, % of alerts resolved without human touch) and report on how automation is cutting noise and response time.
דרישות:
5+ years of experience in security operations, SecOps, or security engineering roles.
Hands-on experience operating EDR/XDR. SOAR/XSOAR, SIEM platforms and cloud security services (IAM, CSPM, SSPM).
Experience building automations and playbooks using SOAR platforms or scripting (Python, Bash).
Strong incident response skills, including triaging alerts and conducting root cause analysis.
Hybrid position based in our Tel Aviv office.
Excellent written and verbal English skills
Personal Attributes & Mindset:
High ownership mentality: You take responsibility for the security stack and follow through on every alert.
Strong sense of structure: You can manage vulnerability SLAs and maintain precise security policies.
Comfortable with ambiguity: You can take a vague threat and turn it into a clear detection rule or automated playbook.
Collaborative by nature: You enjoy working as a partner to R&D to solve security challenges without slowing down development.
Curious and self-driven: You are motivated to stay ahead of emerging threats and continuously improve Port's defenses.
Nice to Have:
Relevant certifications: CompTIA Security+, GSEC, CySA+, or AWS Security Specialty.
Deep understanding of the SDLC and experience embedding security tools (SAST, SCA) into CI/CD pipelines.
Experience with CNAPP/CSPM or code security platforms.
Familiarity with compliance frameworks (SOC 2, ISO המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8775548
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
13/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a SecOps Engineer to join our Security Operations team. In this role, you will help defend the organization end-to-end, from IT security to endpoint and cloud security - while performing third-party and internal security reviews, handling incident response, conducting threat hunting, and supporting GenAI security work.
Responsibilities:
Design, operate, and improve security infrastructure by maintaining core controls, hardening systems, and leading cloud security efforts to address misconfigurations, vulnerabilities, and identity risks.
Monitor, investigate, and remediate security alerts and threats by performing DFIR, analyzing attack vectors, proactively hunting adversary activity, and leading incident response.
Perform security reviews of third-party vendors, SaaS platforms, and internal applications, assessing architectures, data flows, integrations, and risk exposure.
Defend the organization end-to-end across endpoints, identities, applications, and cloud by operating and advancing SecOps controls (SIEM/EDR/CSPM), building automations, enforcing best practices, and partnering cross-functionally to drive security outcomes.
Requirements:
3+ years of hands-on experience in security operations, incident response, or a similar cybersecurity role.
Strong hands-on experience in IT security, endpoint protection, identity security, and general security operations.
Solid understanding of cloud platforms (GCP/AWS/Azure) and practical experience improving cloud security.
Experience with AI artifacts (Skills, MCP, Hooks etc.).
Strong knowledge of SIEM technologies (Splunk, etc.) and experience with incident response and DFIR workflows.
Proficiency with Python, Bash, or PowerShell for automation and scripting.
Familiarity with SOAR platforms and building automated playbooks.
Strong communication skills with the ability to collaborate across DevOps, IT, R&D, and business teams.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8781424
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Great IT and security work means nobody notices the bugs because you already squashed them. From cloud engineers to IT operations managers, our team combines technical expertise with a deep respect for what's at stake. So if you're proactive and precise under pressure, the Fiverr Cyber, IT and MIS team might be the right place for you. Join our Cloud Engineering department as a SecOps Engineer and play a critical role in safeguarding our complex, multi-cloud environment. You'll be essential in maintaining our incident response and security Service Level Agreements (SLAs), preventing team burnout, and ensuring our security posture remains robust in a dynamic, fast-paced setting.

What am I going to do?:

* Champion the monitoring and initial triage of security alerts, meticulously investigating potential threats to uphold our SLA targets.
* Own and execute essential daily SecOps tasks, ensuring seamless operations and preventing critical backlogs.
* Serve as a key security liaison for Cloud Engineering peers, facilitating project momentum without overburdening senior staff.
* Configure, fine-tune, and optimize a suite of security tools, maximizing visibility and effectiveness across our cloud infrastructure.
* Dive deep into security events and alerts, identifying vulnerabilities and prioritizing remediation actions with precision.
* Develop and implement automation for routine security operations, including vulnerability scanning, incident triage, and configuration management, to enhance efficiency.

Equal opportunities:
At Fiverr, we're not about checklists. If you don't meet 100% of the requirements for this role but still feel passionate about the position and think you have the right skills and qualifications to excel at it, we want to hear from you. At Fiverr, we prioritize diversity. We celebrate difference and embed it into every aspect of our workplace and product, as well as our community. Fiverr is proud and committed to providing equal opportunity employment to all individuals regardless of race, color, religion, sex, sexual orientation, citizenship, national origin, disability, Veteran status, or any other characteristic protected by law. In addition, Fiverr will provide accommodation to individuals with disabilities or a special need.
Requirements:
* You are a true Quality Executioner at heart, thriving on meticulous attention to detail and ensuring that every security operation is executed flawlessly to meet critical SLAs.
* You bring proven expertise in threat detection implementation and management, with hands-on experience in incident response, leveraging tools like Splunk and understanding ML models for anomaly detection.
* You possess strong proficiency with a range of security platforms including SIEM, CSPM, DSPM, EDR, vulnerability scanners, and cloud monitoring tools.
* You have a solid command of scripting languages such as Python and Bash, enabling you to automate complex security tasks.
* You have extensive, practical experience operating within complex multi-cloud environments, including AWS, Azure, and GCP.
* You are a natural collaborator and communicator, adept at working effectively with cross-functional teams to address security concerns proactively. Nice to have
* Experience with infrastructure vulnerability management and remediation strategies.
* Familiarity with DevSecOps principles and practices. Working with AI In this role, you'll leverage AI and automation tools to enhance our security operations. This includes utilizing AI-powered features within SIEM and cloud monitoring platforms for threat detection, and employing automation scripts for tasks like vulnerability scanning and incident triage. Your human expertise will be crucial for interpreting AI-driven insights, making critical decisions during incident response, and continuously refining these automated processes to stay ahead of emerging threats.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8726921
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
22/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Required SecOps Engineer
Great IT and security work means nobody notices the bugs because you already squashed them. From cloud engineers to IT operations managers, our team combines technical expertise with a deep respect for what's at stake. So if you're proactive and precise under pressure, the Cyber, IT and MIS team might be the right place for you.
Join our Cloud Engineering department as a SecOps Engineer and play a critical role in safeguarding our complex, multi-cloud environment. You'll be essential in maintaining our incident response and security Service Level Agreements (SLAs), preventing team burnout, and ensuring our security posture remains robust in a dynamic, fast-paced setting.
What am I going to do?
Champion the monitoring and initial triage of security alerts, meticulously investigating potential threats to uphold our SLA targets.
Own and execute essential daily SecOps tasks, ensuring seamless operations and preventing critical backlogs.
Serve as a key security liaison for Cloud Engineering peers, facilitating project momentum without overburdening senior staff.
Configure, fine-tune, and optimize a suite of security tools, maximizing visibility and effectiveness across our cloud infrastructure.
Dive deep into security events and alerts, identifying vulnerabilities and prioritizing remediation actions with precision.
Develop and implement automation for routine security operations, including vulnerability scanning, incident triage, and configuration management, to enhance efficiency.
Requirements:
You are a true Quality Executioner at heart, thriving on meticulous attention to detail and ensuring that every security operation is executed flawlessly to meet critical SLAs.
You bring proven expertise in threat detection implementation and management, with hands-on experience in incident response, leveraging tools like Splunk and understanding ML models for anomaly detection.
You possess strong proficiency with a range of security platforms including SIEM, CSPM, DSPM, EDR, vulnerability scanners, and cloud monitoring tools.
You have a solid command of scripting languages such as Python and Bash, enabling you to automate complex security tasks.
You have extensive, practical experience operating within complex multi-cloud environments, including AWS, Azure, and GCP.
You are a natural collaborator and communicator, adept at working effectively with cross-functional teams to address security concerns proactively.
Nice to have
Experience with infrastructure vulnerability management and remediation strategies.
Familiarity with DevSecOps principles and practices.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8749967
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
04/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Security Analyst to join our team and help customers strengthen their cloud security posture. In this role, you'll investigate security findings, analyze cloud environments, identify security risks, and provide customers with clear, actionable recommendations.
You'll work closely with Customer Success, Product, and R&D to improve our platform, enhance detection capabilities, and help shape the future of AI-driven cloud security.
If you're passionate about cybersecurity, enjoy solving complex security challenges, and want to make an impact in a fast-growing startup, we'd love to hear from you.

Responsibilities
Investigate security findings, customer environments, and cloud security risks.
Analyze Application Security, API Security, and Product Security vulnerabilities.
Review and tune security detections to improve accuracy and reduce false positives.
Stay up to date with emerging threats, attack techniques, and malware trends.
Respond to customer questions and provide clear, actionable security guidance.
Create concise investigation reports and security recommendations for customers.
Work closely with Customer Success and participate in customer calls when needed.
Collaborate with Product and R&D to improve platform capabilities, investigation workflows, and detection quality.
Requirements:
3+ years of hands-on experience in a SOC, Security Operations, Threat Hunting, Security Research, or a cybersecurity company.
Strong understanding of detection & response, vulnerability management, API Security, Identity Security, and cloud security concepts.
Experience investigating security alerts using SIEM, SOAR, and EDR solutions.
Strong knowledge of AWS, Azure, or GCP, including IAM, networking, logging, and cloud security best practices.
Good understanding of Application Security concepts, including OWASP Top 10, secure coding, SAST, DAST, and vulnerability management.
Familiarity with Linux and Kubernetes.
Excellent written communication skills with the ability to produce clear customer-facing reports.
Native English speaker.
Currently enrolled in a university program (or equivalent) in Cybersecurity, Computer Science, Information Security, or a related field, with at least one academic year remaining.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8768220
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for an experienced DevSecOps Engineer to join our DevOps core platform team and help strengthen the security of our cloud-native infrastructure and development pipelines.
You will work closely with our CISO, DevOps team, and developers to integrate security practices across the entire software development lifecycle (SDLC), helping ensure a secure, scalable, and resilient platform across cloud and on-prem environments.
The Responsibilities:
Integrate security practices into CI/CD pipelines and across the SDLC
Design and implement automated security solutions (vulnerability scanning, compliance checks, threat detection)
Build and maintain Infrastructure as Code (IaC) for secure, scalable cloud environments (Terraform, Ansible)
Automate security controls and operational processes across cloud and Kubernetes environments
Design, implement, and optimize CI/CD pipelines with a focus on security, reliability, and performance
Secure cloud and on-prem environments (IAM, network controls, encryption best practices)
Manage and harden Kubernetes workloads, including configuration, access control, and image security
Collaborate with DevOps, developers, and security teams to improve system reliability and overall security posture
Conduct security assessments, penetration testing, and compliance audits
Monitor threats, respond to incidents, and improve incident response processes
Promote DevSecOps culture by guiding teams on secure coding, infrastructure, and deployment practices
Enhance observability by integrating monitoring, logging, and SIEM solutions
Requirements:
5-8 years of experience in DevOps/Security, focusing on secure infrastructure and application security.
Expertise in cloud security (AWS, GCP, Azure) and Infrastructure as Code (IaC) tools like Terraform and Ansible.
Experience integrating security into CI/CD pipelines using tools like Jenkins, GitHub Actions, and ArgoCD.
Knowledge of container security, Kubernetes best practices, and image scanning.
Proficient with security practices (SAST, DAST, SCA, secret scanning) and compliance frameworks (e.g., CIS, NIST, ISO 27001, SOC2).
Strong scripting skills (Python, Bash) for automating security tasks.
Experience with zero-trust models, IAM, and secrets management.
Familiar with AWS security tools (GuardDuty, Inspector, Shield, CloudTrail) and monitoring/alerting solutions (Grafana, Prometheus, SIEM).
Strong troubleshooting skills in network security, encryption, and secure authentication.
Excellent communication and collaboration skills.
Advantages:
Experience securing endpoint products (agents, sensors, collectors).
Background in AI security (securing ML models, training pipelines, inference serving).
Hands-on experience with policy as code tools such as OPA (Open Policy Agent) or Kyverno.
Familiarity with compliance frameworks like ISO 27001, SOC 2, HIPAA, PCI-DSS, or FedRAMP.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785096
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a hands-on role that balances deep technical work alongwith building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by.

Youre welcome to work in our offices in Tel Aviv, Israel.

Your responsibilities will include:

Build and lead global IR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders.
Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases.
Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction.
Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements.
Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR.
Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA).
Raise the teams technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness.
Requirements:
We expect you to have:

Experience

8+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise).
Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8761463
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/07/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a skilled Security Automation Engineer to join our SOC Automation team and play a key role in building and scaling automation across Security Operations. This is a hands-on role - you will design, develop, and integrate automation solutions across SIEM, EDR, and other security platforms, contributing to our SOAR capabilities from the ground up.

You will work in a technologically rich environment, integrating with a wide range of security and infrastructure systems across the network - a unique opportunity to build automation at scale in a greenfield setting, with real influence over the architecture and tooling decisions.

We are especially interested in candidates who are curious about leveraging AI and intelligent agents to help evolve next-generation automation and response workflows - and who want to be a driving voice in how we apply those technologies.

Your responsibilities will include:

Automation development

Design and develop automation workflows for incident response and SOC operations
Identify and eliminate manual processes through scalable automation
Build reusable components and maintainable automation patterns
Engineering & integration

Develop integrations using REST APIs, webhooks, and event-driven architectures
Write high-quality, maintainable Python for automation and orchestration
Implement data parsing, enrichment, and transformation across multiple systems
SOAR & platform buildout

Lead or actively contribute to the evaluation, selection, and implementation of SOAR/automation platforms
Design the automation architecture and integration strategy for the team
Build automation capabilities in a greenfield environment - your decisions will shape the foundation
SOC collaboration

Work closely with SOC analysts and incident responders to translate operational needs into automation solutions
Improve end-to-end detection and response workflows through close partnership with the team
AI & innovation

Actively build and evaluate AI/LLM and agent-based workflows applied to security automation
Prototype AI-assisted enrichment, triage, and response solutions and drive them toward production
Requirements:
We expect you to have:

Minimum 3 years of hands-on experience with SOAR platforms (e.g., Torq, Cortex XSOAR, Splunk SOAR, or similar)
Strong hands-on experience with Python (or a comparable language)
Experience designing or implementing automation frameworks or workflows
Experience building integrations using REST APIs and web services
Experience working with security tools such as SIEM, EDR/XDR, or ticketing systems
Experience with at least one cloud platform (Azure, AWS, or GCP)
Solid understanding of incident response processes and SOC alert-handling workflows
Experience with at least one SIEM platform (Splunk,Sentinel,Qradar,Crowdstrike)
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8761403
סגור
שירות זה פתוח ללקוחות VIP בלבד