דרושים » אבטחת מידע וסייבר » Senior Information Security Manager

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 4 שעות
Location: Tel Aviv-Yafo
Job Type: Full Time and Hybrid work
We are growing and are looking for a Senior Information Security Manager JD to join our mission to increase access to life-saving treatments.

The Role:

Lead and maintain all certification and compliance efforts, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, and CIS benchmarks

Serve as the primary point of contact for all security questions and concerns, internal and external

Own global security awareness strategy and programs, including annual employee training, ongoing awareness campaigns, and phishing simulations

Respond to customer and prospect security questionnaires while maintaining agreed turnaround times

Oversee SOC (Security Operations Center) operations, including log source coverage, detection rule creation and tuning, and SLA/KPI management

Build and manage the Third-Party Risk Management, Business Continuity, and Disaster Recovery programs

Run the vulnerability steering committee across corporate and production environments

Manage vendor risk and the security risk register

Monitor and manage the company's external digital footprint using third-party attack surface management tools

Act as incident commander for security incidents - analyze, escalate, coordinate response, and drive remediation

Help design and execute the annual security roadmap

Manage the company Trust Center

Lead the internal security policy lifecycle - creation, updates, approvals, and distribution

Audit onboarding and offboarding processes from a security perspective
Requirements:
5+ years of experience in information security, with meaningful time in GRC, security operations, or a hybrid role

Hands-on experience leading or supporting SOC 2, ISO 27001, HIPAA, and GDPR certifications and audits

Strong understanding of SOC operations, SIEM tooling, detection engineering concepts, and incident response

Experience building or running a Third-Party Risk Management program

Experience acting as incident commander or lead responder for security incidents

Familiarity with vulnerability management programs across cloud and corporate environments

Strong written and verbal communication skills in English, able to represent security to customers, auditors, and executives
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818572
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
our companys Harmony SASE is looking for an Information Security Manager to join its staff.
This is a unique opportunity for you to work in the #1 worldwide Cyber Security Company, gain expertise and experience leading the information security program for the best of SASE (Secure Access Service Edge).
Key Responsibilities
As Information Security Manager you will:
Governance, Risk & Compliance
Lead and manage the Product Security team
Build, operate, and continuously improve the Harmony SASE Information Security Management System (ISMS), aligning policies, standards, and controls with our company and industry best practices.
Own the Harmony SASE compliance roadmap - lead and maintain certifications and attestations including ISO/IEC 27001, SOC 2 Type II, GDPR, IRAP and C5
Lead enterprise risk assessments and the third-party / vendor risk program, ensuring risks are identified, prioritized, and treated.
Coordinate internal and external audits, manage evidence collection, and remediate findings to closure.
Product & Application Security
Develop and implement a comprehensive AI - Secure Software Development Lifecycle (AI S-SDLC) framework, embedding security into every phase of the SDLC and CI/CD pipelines.
Conduct threat modeling and secure architecture reviews for new and existing Harmony SASE features, partnering with R&D to mitigate vulnerabilities by design.
Operate the application security tooling stack - ASPM, SAST, DAST, SCA, AI Security Scanning and secret scanning - at scale, and partner with development teams to drive findings to remediation while maintaining developer productivity.
Champion secure coding practices and OWASP Top 10 awareness across R&D.
Operational Security & Incident Response
Lead security incident response for Harmony SASE - preparedness, detection, containment, eradication, recovery, and lessons-learned - covering both product and information security incidents.
Oversee identity and access governance, ensuring least-privilege, segregation of duties, and access reviews across production and corporate environments.
Design and operate security automation to enhance the efficiency and coverage of security operations.
Security Culture & Enablement
Foster a culture of security awareness and continuous improvement; deliver targeted training for engineers, operations, and broader staff.
Lead responses to customer security questionnaires, RFPs, and due-diligence requests, representing Harmony SASEs security posture to customers and partners.
Stay current on the evolving Threats Landscape, regulations, and technologies, and translate them into pragmatic improvements to the security program.
Requirements:
We are looking for you:
Bachelors degree in computer science, Information Security, or related field.
Minimum of 5 years of experience in information security or application/product security, with at least 2 year in a leadership role.
Proven experience building or operating an Information Security Management System (ISMS) and leading certifications such as ISO/IEC 27001 and SOC 2.
Working knowledge of GDPR, PCI-DSS, and NIST CSF / 800-53; familiarity with HIPAA, FedRAMP, DORA, Cyber Essentials, C5, IRAP, AI Security Frameworks and the Cloud Controls Matrix (CCM).
Hands-on experience with S-SDLC, threat modeling, and application security tooling such as ASPM, SAST, and DAST in complex, high-scale environments.
Strong understanding of risk management, third-party risk, identity and access governance, and incident response.
Excellent communication and leadership skills, with the ability and passion to drive change across R&D and the broader organization.
Reports to the Harmony SASE Head of Architecture (R&D Director) and partners closely with R&D, DevOps, IT, Legal, and the company Corporate Security organization.
Relevant certifications such as CISM (preferred), CISSP, CCSP, ISO 27001 Lead Auditor / Lead Implementer, CCSP or CSSLP are desirable.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785659
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Security Engineering Lead to join the Cyber Security organization, reporting to the Corporate Security Engineering Manager under the CISO.

This is a senior technical lead role focusing on engineering and execution without direct people management responsibilities. This role combines hands-on security engineering to deliver end-to-end protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will be responsible for implementing, managing, integrating and maintaining security systems across the organizations IT landscape. The role requires deep technical proficiency in multiple platforms and tools, combined with the ability to collaborate with Security, IT, Engineering, Product, GRC and other business units to reduce risks and embed strong security practices.

Your responsibilities will include:

Engineer, deploy, and continuously tune systems such as Identity & Access, Threat Detection & Response, Cloud & Network Security.
Define, enforce and maintain security policies & configurations across endpoints, email, SaaS, network, and cloud platforms.
Design and implement solutions to gain continuous visibility into systems and processes, sensitive data, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Monitor, triage, and investigate security alerts and risks, collaborating with Security, IT, Network teams on escalation and remediation.
Conduct risk assessments and identify gaps in security controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed security controls into systems, and workflows.
Maintain documentation, runbooks, and guidelines for operations, security posture management, and security practices.
Requirements:
6+ years of experience in IT security, with a strong focus on System, Network, Information, Cyber. With at least 3 years in a Security Engineering role.
Proven hands-on engineering experience with enterprise security platforms - including policy authoring, tuning, incident workflow configuration, and platform administration.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governance principles.
Experience working cross-functionally with Security, IT, Engineering, Product, and GRC teams.
Strong analytical mindset with the ability to communicate security risks clearly to technical and non-technical stakeholders.
Excellent written and verbal communication skills in English.
Proactive, detail-oriented, and ownership-driven.
Hand-on experience with multiple technologies such as: XDR (Extended Detection & Response), SWG (Secure Web Gateway), DLP (Data Leakage Prevention), Email Security, Network security (Firewalls, NAC, NDR), IGA (Identity Governance & Administration), CASB (Cloud Access Security Broker), PAM (Privileged Access Management), EPM (Endpoint Privilege Management), BAS (Breach & Attack Simulation), Vulnerability Scanners, SIEM (Security Information & Event Management), SOAR (Security Orchestration, Automation & Response), CTI (Cyber Threat Intelligence), Patch Management, TPRM (Third-Party Risk Management), EASM (External Attack Surface Management).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817717
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
18/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a Security Engineer with 1-2 years of experience to join our Internal Security team.
This role combines hands-on cloud and security operations with support for GRC and compliance activities.
You will be involved in securing our cloud, SaaS, and AI-driven systems, monitoring security events, and helping maintain our overall security posture. In parallel, you will support customer security questionnaires and compliance processes.

What You'll Do:
Monitor, triage, and investigate security alerts and incidents across cloud and security tools (EDR, CASB, ZTNA, SaaS security platforms, and identity providers), and support response and remediation activities
Assist in securing cloud environments (AWS/GCP/Azure), including IAM, access controls, network security, and CI/CD pipeline security
Work closely with DevOps and IT teams to implement and enforce security best practices across infrastructure, endpoints, and SaaS systems
Support vulnerability management processes, including scanning, prioritization, and remediation tracking
Support risk management processes by identifying, assessing, and tracking risks, including vulnerability management, remediation efforts, and control gaps
Support customer security questionnaires (RFPs/RFIs) with accurate technical responses
Assist in maintaining compliance with frameworks such as SOC 2 and ISO 27001, including preparing audit evidence and documentation
Requirements:
Who You Are?
1-2 years of experience in cybersecurity, cloud security, and security operations
Basic hands-on experience with cloud platforms (AWS, GCP, or Azure)
Understanding of core security concepts: IAM, networking, least privilege, and secure configurations
Experience or strong interest in collaborating with DevOps and IT teams, alongside a focus on AI security, data protection, and emerging technologies
Familiarity with security tools such as EDR, vulnerability scanners, or SaaS security solutions
Strong analytical and troubleshooting skills, with high attention to detail and the ability to manage multiple tasks
Good communication skills and ability to work cross-functionally
Willingness to learn and grow in both technical security and GRC domains
Nice to Have:
Experience with cloud security best practices and securing CI/CD pipelines and infrastructure-as-code (Terraform, etc.)
Familiarity with identity systems (Okta, Azure AD, etc.)
Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8787070
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 22 שעות
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Data Protection Lead to join the Cyber Security organization.

This role combines hands-on Data Leakage Prevention (DLP) engineering with Data Security Posture Management (DSPM) to deliver end-to-end data protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will own the data protection lifecycle from discovery and classification through policy enforcement and incident response. The role requires deep technical proficiency in DLP platforms and DSPM tooling, combined with the ability to collaborate with Security, IT, Engineering, Product, Privacy and GRC teams to reduce data exposure risks and embed strong data governance practices.

Your responsibilities will include:
Lead and own the organizations data protection domain, including strategy, standards, and hands-on technical implementation
Engineer, deploy, and continuously tune DLP policies across endpoints, email, SaaS, network proxies, and cloud platforms - covering both inline and API-based enforcement modes.
Design and implement DSPM solutions to gain continuous visibility into sensitive data posture, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Drive data discovery initiatives to identify and inventory sensitive data across databases, SaaS applications, endpoints, and cloud storage.
Define and implement data classification frameworks, labeling standards, and data handling policies integrated with DLP and DSPM controls.
Build and maintain DLP detection rules, regular expressions, fingerprinting, and machine learning-based classifiers to minimize false positives and maximize coverage.
Integrate DSPM findings into DLP enforcement workflows to create a closed-loop data protection architecture.
Define and enforce data access governance, including least-privilege principles and monitoring of sensitive data access patterns.
Monitor, triage, and investigate DLP alerts and DSPM-identified risks, collaborating with SOC and Security teams on escalation and remediation.
Conduct risk assessments and identify gaps in data protection controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to data security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed data security controls into CI/CD pipelines, systems, and workflows.
Maintain documentation, runbooks, and guidelines for DLP operations, DSPM posture management, and data security practices.
דרישות:
6+ years of experience in cyber security, with a strong focus on data security, data protection, or information security.
Proven hands-on engineering experience with enterprise DLP platforms - including policy authoring, rule tuning, incident workflow configuration, and platform administration (e.g., Microsoft Purview DLP, Symantec DLP, Forcepoint, or equivalent).
Hands-on experience deploying and operating DSPM tools (e.g., Cyera, Varonis, Rubrik Security Cloud, Normalyze, Securiti, or equivalent) to manage cloud data exposure and classification at scale.
Deep understanding of DLP enforcement mechanisms: endpoint DLP, network DLP, email DLP, and cloud/API-based DLP controls.
Strong experience with data discovery and classification across cloud environments (AWS, Azure, GCP), SaaS platforms, and on-premises systems.
Ability to write and optimize detection logic - regular expressions, data fingerprinting, document fingerprinting, and EDM (Exact Data Matching).
Experience integrating DLP and DSPM tools with SIEM, SOAR, and ticketing systems for alert routing and automated response.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governanc המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818177
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Job Type: Full Time
We are looking for an experienced and highly driven Deputy CISO to join Sunbit's Security leadership team, reporting directly to the CISO.
This is a unique opportunity to play a key leadership role in shaping and scaling the security program of a fast-growing fintech company. As Deputy CISO, you will serve as the CISO's trusted partner, helping drive the organization's security strategy while leading day-to-day execution across multiple security domains.
Yo will oversee both the Security Operations , Security Engineering and GRC organizations, managing team leads and security professionals across Israel and abroad. This role requires a strong combination of strategic thinking, technical depth, operational excellence, and people leadership.
The ideal candidate brings experience from large-scale, cloud-native environments and has successfully led security programs spanning Security Operations, Security Engineering, Compliance, Risk Management, and Security Architecture. You will work closely with Engineering, Infrastructure, IT, Product, Legal, Compliance, and executive leadership teams to continuously strengthen Sunbit's security posture while enabling business growth.
What You'll Do:
Drive execution of strategic security initiatives across the organization
Partner closely with the CISO to define and execute Sunbit's security strategy and roadmap
Translate business objectives into scalable security programs and controls
Act as a key stakeholder in security governance, risk management, and decision-making processes
Help shape the future of Security at Sunbit, including emerging domains such as AI Security and Security Automation
Requirements:
10+ years of experience in Information Security, Cybersecurity, or Security Engineering roles
5+ years of leadership experience managing security teams and managers
Proven experience leading security programs in large-scale, high-growth organizations
Strong background across multiple security domains, including Security Engineering, Security Operations, Cloud Security, Incident Response, Vulnerability Management, and Governance
Extensive experience securing cloud-native environments (AWS, GCP, Azure)
Deep understanding of security architecture, security controls, and modern security technologies
Experience working with regulatory frameworks, audits, compliance programs, and risk management processes
Demonstrated ability to lead cross-functional initiatives across Engineering, Infrastructure, Product, and Business teams
Strong communication and stakeholder management skills
Fluent English, with extensive experience working with global teams and international stakeholders
Nice to have :
Experience in fintech, financial services, or highly regulated environments
Experience leading AI Security initiatives or security automation programs
Hands-on experience with modern security platforms such as CrowdStrike, Wiz, Okta, SIEM, and Identity solutions
Relevant certifications such as CISSP, CISM, CCSP, CRISC, or equivalent
Experience building and scaling security organizations
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8773664
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a senior, hands-on individual-contributor role with end-to-end ownership of security risk assessments, the security risk register, remediation tracking, risk acceptance, and risk reporting. The successful candidate will work closely with engineering, cloud infrastructure, product, security, compliance, legal, and business teams to ensure that material risks are identified early, assessed consistently, and driven toward clear treatment decisions.

The role requires strong judgment, technical understanding, and the ability to influence stakeholders without relying on formal authority.

Your responsibilities will include

Risk Assessment

Lead security risk assessments for infrastructure, cloud environments, products, applications, business processes, and major technology changes.
Conduct risk assessments for new initiatives, systems, and significant changes, including supporting M&A-related risk assessment work alongside the due diligence team.
Evaluate the design and effectiveness of controls and identify residual risk following mitigation.
Identify emerging and systemic risks that may affect multiple services, regions, or business functions.
Risk Register & Tracking

Maintain the security risk register: log new risks, update status, track owners, and follow items through to remediation or formal risk acceptance.
Support the ongoing refinement of risk assessment and risk register processes, contributing improvements as the practice matures.
Coordinate with other GRC functions on findings and gap assessments that carry risk implications, and independently determine whether a given finding warrants a risk register entry.
Metrics & Reporting

Maintain and improve security risk assessment, scoring, prioritization, and acceptance processes.
Define and monitor meaningful Key Risk Indicators and risk trends.
Translate complex technical risks into clear business impact for senior leadership and governance forums.
Prepare risk reporting that supports security posture reviews, strategic decision-making, and Board-level reporting.
Support auditors, customers, and internal stakeholders on security risk management matters.
Cross-Functional Coordination

Work closely with other GRC functions to ensure risk assessments reflect current operating reality.
Partner with engineering and business stakeholders to embed risk thinking into day-to-day decisions, building trust through clear, practical communication rather than formal authority.
Build trusted relationships with risk and remediation owners while maintaining independent and objective judgment.
Requirements:
5-8 years of experience in security risk management, IT risk, GRC, or a closely related discipline.
Hands-on experience running risk assessments and maintaining a risk register, including driving items through to remediation or formal risk acceptance.
Solid understanding of risk scoring and prioritization approaches, and the judgment to apply them consistently and defensibly.
Ability to define and track meaningful risk metrics/KRIs for leadership reporting.
Strong organizational and analytical skills, with the ability to manage multiple concurrent risk items without losing accuracy or follow-through.
Strong communication and stakeholder management skills; comfortable working across security, compliance, engineering, and business teams.
Familiarity with cloud infrastructure and technology environments is an advantage.
Relevant certifications (e.g., CRISC, CISSP) are an advantage, not a requirement.
Bachelor's degree in information security, computer science, engineering, or a related field preferred; equivalent practical experience will be considered.
Excellent written and verbal communication skills in English.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817688
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 23 שעות
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Head of Security Reliability to establish and lead the Security Reliability pillar. Reporting directly to the CISO, this leader will be accountable for the ongoing effectiveness, resilience, and operational maturity of security products after implementation.

The role ensures that security platforms remain properly configured, maintained, integrated, monitored, adopted, and optimized to deliver measurable risk reduction. It also owns Third-Party Risk Management (TPRM) program and the security-review process for new products, services, and technologies introduced across the company.

This is a hands-on leadership position for someone who combines security expertise, operational discipline, vendor-management experience, and a strong product mindset. The role partners closely with Security, IT, Engineering, Product, Procurement, Legal, Privacy, Compliance, and business stakeholders.

Key responsibilities

Security product reliability and lifecycle ownership

Own security products and platforms after implementation, from operational handover through optimization, renewal, replacement, or retirement.
Ensure security tools are correctly configured, maintained, integrated, monitored, and aligned with Nebius's risk profile and technical environment.
Define ownership, service levels, operating procedures, support models, and escalation paths for every security platform.
Monitor platform availability, data quality, control coverage, integration health, licensing, capacity, and performance.
Establish disciplined processes for upgrades, configuration changes, testing, exception management, and end-of-life planning.
Continuously assess whether security products deliver their intended outcomes, and improve utilization, coverage, automation, and return on investment.
Reduce overlapping capabilities, configuration drift, operational gaps, and underused tooling across the security stack.
Manage vendor performance, technical escalations, product-roadmap discussions, renewals, and service reviews.
Ensure newly implemented security products transition into operations with clear documentation, ownership, monitoring, and success criteria.
Security configuration and control assurance

Define and maintain secure configuration baselines for security platforms.
Establish continuous control-health monitoring to identify disabled, degraded, misconfigured, or incomplete controls.
Validate that integrations and telemetry remain complete, accurate, and reliable as environment evolves.
Coordinate remediation of control gaps with Security, IT, Engineering, and platform owners.
Maintain evidence demonstrating the operational effectiveness of security controls for audits, certifications, and customer-assurance activities.
Requirements:
Significant cybersecurity experience, including leadership responsibility in security engineering, security operations, platform security, security architecture, or technology risk.
Proven experience owning security products in production, including configuration, maintenance, integration, optimization, and lifecycle management.
Strong understanding of enterprise and cloud security technologies, architectures, and operating models.
Experience establishing or managing a Third-Party Risk Management program.
Experience performing security architecture, technology, vendor, or product reviews.
Demonstrated ability to translate technical findings into clear business risks and actionable recommendations.
Experience managing teams, budgets, vendors, service providers, and cross-functional programs.
Strong knowledge of security control frameworks and risk-management principles.
Ability to operate effectively in a complex, fast-moving, and highly technical organization.
Excellent communication and stakeholder-management skills, including presenting risks and recommendations to senior leadership.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818125
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
04/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We're looking for a GRC Specialist to own and drive our compliance and authorization programs, with a strong emphasis on FedRAMP and NIST 800-53. This is a hands-on governance, risk, and compliance role for someone who can build and run a federal-grade compliance program from the ground up and manage it through continuous monitoring and reauthorization cycles.

U.S. citizenship is required for this role due to FedRAMP and federal customer requirements.

Key Responsibilities

Own the FedRAMP process end-to-end: System Security Plan (SSP) development and maintenance, POA&M tracking and remediation, control implementation statements, and continuous monitoring (ConMon) deliverables
Serve as primary point of contact for 3PAO assessments, coordinating testing, evidence collection, and finding resolution
Maintain compliance programs across SOC 2 Type II and ISO 27001
Respond to customers security questionnaires, and support sales enablement with SSPs, control narratives, and other security documentation
Partner with engineering, GTM, and leadership to ensure controls are implemented, evidenced, and operating effectively
Monitor changes to FedRAMP requirements, NIST guidance, and federal compliance obligations, and translate them into actionable program updates
Requirements:
U.S. citizenship (required for FedRAMP program access and federal customer engagements)
3-5 years of hands-on GRC experience, with direct, demonstrable work on NIST control implementation and assessment
Direct experience supporting or owning a FedRAMP authorization (Moderate or High baseline) - SSP authorship, POA&M management, or ConMon deliverables
Solid understanding of the FedRAMP process, including 3PAO coordination
Working knowledge of SOC 2 and ISO 27001 frameworks
Excellent written English - you will be authoring SSPs, policies, and customer- and agency-facing documentation
Strong cross-team communication skills and comfort working directly with auditors and assessors
Ability to work independently and manage multiple compliance workstreams in a fast-paced environment
Experience with GRC platforms (e.g., Vanta, Drata, Scytale, or similar)
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8768192
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
25/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are revolutionizing legal tech with an AI-powered Legal Intelligence Platform trusted by some of the world's fastest-growing companies including Wiz, Socure, and Fiverr.
We integrate seamlessly with Salesforce and other systems to help in-house legal teams accelerate negotiations, reduce risk, and unlock institutional knowledge through automated workflows.
We're solving complex problems at the intersection of AI and legal operations. Join us as we scale our impact globally.
About the Role
We're looking for a Head of Security to own security end-to-end at our company- from the architecture of our product to the systems our own team runs on.
We handle some of the most sensitive documents our customers have, and our buyers' security teams scrutinize us accordingly.
You'll be our first dedicated security hire and the sole internal authority on the subject: setting the standards our engineers build against, owning our compliance posture, and sitting across the table from customer CISOs to defend it.
This is a hands-on role with real strategic weight - if you want to build a security function from scratch at a company where security is a deal-maker, we want to hear from you.
What You'll Do
Design, architect, and implement security directly into our product and codebase
Own our internal security posture: corporate IT, access management, endpoint, and employee security practices
Lead customer-facing security engagements - pre-sales security reviews, CISO-level discussions, security questionnaires, and enterprise assessments - representing our company's posture to buyers who evaluate us seriously
Own our compliance program end-to-end, including audits, evidence, and vendor risk
Set security standards and best practices across R&D and product as the internal authority on the subject
Build the security review process for how we ship AI features - threat modeling around LLMs, agentic workflows, and customer data boundaries
Partner with DevOps and engineering on cloud security, secure architecture, and incident readiness
Grow the security function as we scale, from process to headcount.
Requirements:
Passion to own and deliver - you take full responsibility for security outcomes and drive initiatives from idea to production
Curiosity and adoption of AI tools - you actively use tools like Cursor or Claude Code and are excited about how AI is transforming both software development and the threat landscape
7+ years of hands-on security experience, with real depth in product or application security
Experience in customer-facing security roles, representing a company to client CISOs, IT directors, and security teams across enterprise and SMB
Strong command of cloud security (AWS/GCP/Azure), web application security, and secure architecture design
Hands-on experience running or building a compliance program (SOC 2, ISO 27001, or equivalent)
A builder's mindset - comfortable establishing process and structure where none exists
Ability to thrive in a fast-paced environment, balancing deep technical execution with high-level strategic and client conversations
Strong communication skills, effective in a fast-paced startup environment
Bonus Points
Experience securing LLM-powered applications, agentic systems, or AI infrastructure
Background working with legal, financial, or other high-stakes documentheavy domains
Hands-on coding ability in Python or TypeScript
Experience building a security function from scratch, especially as a founding or first security hire
Familiarity with Kubernetes, infrastructure-as-code, and cloud-native architectures.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796752
סגור
שירות זה פתוח ללקוחות VIP בלבד