דרושים » אבטחת מידע וסייבר » Technical GRC Lead - Information Security Consultant

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 16 שעות
דרושים בעידור מחשבים בע"מ
Additional Benefits More than one
We are looking for an experienced Technical GRC Lead to drive information security consulting engagements for our customers across a variety of domains.
someone who can lead governance, risk, and compliance programs end-to-end while staying hands-on enough to log into a client's cloud console, pull evidence themselves, and verify a control actually works rather than taking a screenshot on faith.
You'll own security project management, risk management, and ISO/compliance leadership for clients and you'll use AI and automation as your default way of working, not a side project, to make GRC processes faster and more scalable than a traditional consulting engagement.
Serve as CISO -as-a-Service for a portfolio of clients across a variety of industries - owning security
strategy, risk appetite, and executive/board-level reporting for each, and acting as the senior securitecurity voice
Requirements:
Experience Certifications
- 5+ years of experience in GRC, Information Security, or a related governance, risk, or compliance role.
- Certified in at least one of: CISM, CISSP, CRISC, CISA.
- Cloud security certification (AWS, Azure, or GCP) is a plus, or equivalent hands-on experience.
- DPO Certification is advantag
This position is open to all candidates.
 
Hide
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8829694
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/08/2026
חברה חסויה
Location: Ramat Gan
Job Type: Full Time
As a Cybersecurity GRC Specialist at our innovative healthcare startup, you will own our information security program end to end. We are on a mission to bring the first Hybrid Drug to market: a groundbreaking therapeutic entity that integrates mobile apps with traditional medication. Operating at the intersection of digital health and pharma means security, privacy, and compliance are core to what we build - and you'll be the one making sure we get it right. If you're excited to shape and lead the security function of a growing company (rather than inherit one), read on

About the Role
This is a hands-on role with broad ownership. You'll act as our security lead, serving as the go-to person for all things governance, risk, and compliance - working directly with leadership, engineering, quality, and clinical teams. It's a great fit for someone with a few years of GRC experience who's ready to take on company-wide responsibility, not a traditional executive CISO position.



Responsibilities
Governance & Security Program
Build, implement, and maintain our Information Security Management System (ISMS) in line with ISO 27001.
Develop and enforce security policies, standards, guidelines, and procedures across the company.
Foster a culture of security awareness through training and ongoing communication.
Risk Management
Identify, assess, and prioritize cyber risks across our products, infrastructure, and vendors.
Conduct Business Impact Analyses (BIA) to map critical business functions and potential disruptions.
Own the risk register and drive mitigation plans with relevant stakeholders.

Compliance & Regulatory Alignment
Ensure compliance with healthcare and privacy regulations, including HIPAA and GDPR.
Support regulatory and quality processes relevant to medical device software (e.g., working alongside our QA/RA team on standards such as ISO 13485 and IEC 62304 where security intersects).
Manage security aspects of customer, partner, and vendor due diligence, including security questionnaires and audits.
Resilience & Incident Preparedness
Design and maintain Business Continuity (BCP) and Disaster Recovery (DRP) plans.
Define and test incident response procedures; lead response efforts when needed.
Run periodic tabletop exercises and recovery drills.
Security Operations & Engineering Collaboration
Work with engineering to embed security requirements into the development lifecycle of our mobile and cloud platforms.
Coordinate penetration tests, vulnerability assessments, and remediation follow-up.
Evaluate and manage security tooling appropriate to our size and needs.
Requirements:
2-4 years of hands-on experience in a GRC, information security, or IT security role - ideally in healthcare, medtech, or another regulated industry.

Knowledge
Practical experience implementing or maintaining ISO 27001-based ISMS (certification project experience is a strong plus).
Solid understanding of risk management methodologies, BIA, BCP, and DRP.
Familiarity with privacy and healthcare regulations such as GDPR and HIPAA.
Skills & Mindset
Strong ability to translate security and compliance requirements into practical, business-aligned actions.
Comfortable working independently and owning a domain across the whole company.
Excellent communication skills - you can explain risk to engineers, executives, and auditors alike.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8800876
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a senior, hands-on individual-contributor role with end-to-end ownership of security risk assessments, the security risk register, remediation tracking, risk acceptance, and risk reporting. The successful candidate will work closely with engineering, cloud infrastructure, product, security, compliance, legal, and business teams to ensure that material risks are identified early, assessed consistently, and driven toward clear treatment decisions.

The role requires strong judgment, technical understanding, and the ability to influence stakeholders without relying on formal authority.

Your responsibilities will include

Risk Assessment

Lead security risk assessments for infrastructure, cloud environments, products, applications, business processes, and major technology changes.
Conduct risk assessments for new initiatives, systems, and significant changes, including supporting M&A-related risk assessment work alongside the due diligence team.
Evaluate the design and effectiveness of controls and identify residual risk following mitigation.
Identify emerging and systemic risks that may affect multiple services, regions, or business functions.
Risk Register & Tracking

Maintain the security risk register: log new risks, update status, track owners, and follow items through to remediation or formal risk acceptance.
Support the ongoing refinement of risk assessment and risk register processes, contributing improvements as the practice matures.
Coordinate with other GRC functions on findings and gap assessments that carry risk implications, and independently determine whether a given finding warrants a risk register entry.
Metrics & Reporting

Maintain and improve security risk assessment, scoring, prioritization, and acceptance processes.
Define and monitor meaningful Key Risk Indicators and risk trends.
Translate complex technical risks into clear business impact for senior leadership and governance forums.
Prepare risk reporting that supports security posture reviews, strategic decision-making, and Board-level reporting.
Support auditors, customers, and internal stakeholders on security risk management matters.
Cross-Functional Coordination

Work closely with other GRC functions to ensure risk assessments reflect current operating reality.
Partner with engineering and business stakeholders to embed risk thinking into day-to-day decisions, building trust through clear, practical communication rather than formal authority.
Build trusted relationships with risk and remediation owners while maintaining independent and objective judgment.
Requirements:
5-8 years of experience in security risk management, IT risk, GRC, or a closely related discipline.
Hands-on experience running risk assessments and maintaining a risk register, including driving items through to remediation or formal risk acceptance.
Solid understanding of risk scoring and prioritization approaches, and the judgment to apply them consistently and defensibly.
Ability to define and track meaningful risk metrics/KRIs for leadership reporting.
Strong organizational and analytical skills, with the ability to manage multiple concurrent risk items without losing accuracy or follow-through.
Strong communication and stakeholder management skills; comfortable working across security, compliance, engineering, and business teams.
Familiarity with cloud infrastructure and technology environments is an advantage.
Relevant certifications (e.g., CRISC, CISSP) are an advantage, not a requirement.
Bachelor's degree in information security, computer science, engineering, or a related field preferred; equivalent practical experience will be considered.
Excellent written and verbal communication skills in English.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817688
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time and Hybrid work
We are growing and are looking for a Senior Information Security Manager JD to join our mission to increase access to life-saving treatments.

The Role:

Lead and maintain all certification and compliance efforts, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, and CIS benchmarks

Serve as the primary point of contact for all security questions and concerns, internal and external

Own global security awareness strategy and programs, including annual employee training, ongoing awareness campaigns, and phishing simulations

Respond to customer and prospect security questionnaires while maintaining agreed turnaround times

Oversee SOC (Security Operations Center) operations, including log source coverage, detection rule creation and tuning, and SLA/KPI management

Build and manage the Third-Party Risk Management, Business Continuity, and Disaster Recovery programs

Run the vulnerability steering committee across corporate and production environments

Manage vendor risk and the security risk register

Monitor and manage the company's external digital footprint using third-party attack surface management tools

Act as incident commander for security incidents - analyze, escalate, coordinate response, and drive remediation

Help design and execute the annual security roadmap

Manage the company Trust Center

Lead the internal security policy lifecycle - creation, updates, approvals, and distribution

Audit onboarding and offboarding processes from a security perspective
Requirements:
5+ years of experience in information security, with meaningful time in GRC, security operations, or a hybrid role

Hands-on experience leading or supporting SOC 2, ISO 27001, HIPAA, and GDPR certifications and audits

Strong understanding of SOC operations, SIEM tooling, detection engineering concepts, and incident response

Experience building or running a Third-Party Risk Management program

Experience acting as incident commander or lead responder for security incidents

Familiarity with vulnerability management programs across cloud and corporate environments

Strong written and verbal communication skills in English, able to represent security to customers, auditors, and executives
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818572
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
The GRC Program Coordinator works across security risk management, strategic certification and regulatory programs, and other governance, risk, and compliance activities as they arise. This is a hands-on role that combines program execution with real GRC subject-matter knowledge: the person in this role is expected to understand security and compliance concepts well enough to contribute professional judgment, not only to coordinate schedules and trackers. The scope spans multiple concurrent programs and will grow to include new initiatives over time.

Your responsibilities will include

Program Execution

Support the planning, tracking, and execution of strategic certification and regulatory programs: milestones, owners, due dates, and status across multiple concurrent workstreams.
Coordinate evidence collection, documentation, and readiness activities in support of certification and audit cycles.
Support engagement with external assessors, auditors, and vendors, including scheduling, correspondence, and tracking of deliverables against agreed timelines.
Security Risk Support

Contribute to security risk assessment activities: help identify, assess, and document risks, and support the maintenance of the risk register.
Support risk mitigation and follow-up activities, including tracking corrective actions through to closure and helping confirm that remediation is effective, not just logged as complete.
Help prepare risk and program status materials for internal review.
General GRC Support

Take on additional governance, risk, and compliance activities as priorities evolve, applying sound judgment on how a given task fits existing frameworks and processes.
Maintain organized, audit-ready documentation across the programs and activities supported.
Identify opportunities to improve tracking, reporting, and process efficiency across the programs supported.
Requirements:
2-4 years of experience in information security, GRC, compliance, IT risk, or a closely related field.
Working knowledge of information security and compliance concepts (e.g., risk assessment, control frameworks, certification or audit cycles) sufficient to engage substantively with the work, not only to track it.
Strong organizational skills and comfort managing multiple concurrent workstreams with different cadences and stakeholders.
Clear written and verbal communication; able to synthesize status and findings accurately from multiple sources.
Proficiency with common tracking and documentation tools (e.g., Jira, Excel/spreadsheets); Confluence familiarity a plus.
Discretion with sensitive compliance and security information.
Genuine interest in growing into broader ownership of risk and program work over time.
Prior exposure to security certifications (e.g., ISO 27001, SOC 2), risk frameworks, or regulatory compliance programs is an advantage, not a requirement.
Bachelor's degree in information security, computer science, engineering, or a related field preferred; equivalent practical experience will be considered.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818150
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
our companys Harmony SASE is looking for an Information Security Manager to join its staff.
This is a unique opportunity for you to work in the #1 worldwide Cyber Security Company, gain expertise and experience leading the information security program for the best of SASE (Secure Access Service Edge).
Key Responsibilities
As Information Security Manager you will:
Governance, Risk & Compliance
Lead and manage the Product Security team
Build, operate, and continuously improve the Harmony SASE Information Security Management System (ISMS), aligning policies, standards, and controls with our company and industry best practices.
Own the Harmony SASE compliance roadmap - lead and maintain certifications and attestations including ISO/IEC 27001, SOC 2 Type II, GDPR, IRAP and C5
Lead enterprise risk assessments and the third-party / vendor risk program, ensuring risks are identified, prioritized, and treated.
Coordinate internal and external audits, manage evidence collection, and remediate findings to closure.
Product & Application Security
Develop and implement a comprehensive AI - Secure Software Development Lifecycle (AI S-SDLC) framework, embedding security into every phase of the SDLC and CI/CD pipelines.
Conduct threat modeling and secure architecture reviews for new and existing Harmony SASE features, partnering with R&D to mitigate vulnerabilities by design.
Operate the application security tooling stack - ASPM, SAST, DAST, SCA, AI Security Scanning and secret scanning - at scale, and partner with development teams to drive findings to remediation while maintaining developer productivity.
Champion secure coding practices and OWASP Top 10 awareness across R&D.
Operational Security & Incident Response
Lead security incident response for Harmony SASE - preparedness, detection, containment, eradication, recovery, and lessons-learned - covering both product and information security incidents.
Oversee identity and access governance, ensuring least-privilege, segregation of duties, and access reviews across production and corporate environments.
Design and operate security automation to enhance the efficiency and coverage of security operations.
Security Culture & Enablement
Foster a culture of security awareness and continuous improvement; deliver targeted training for engineers, operations, and broader staff.
Lead responses to customer security questionnaires, RFPs, and due-diligence requests, representing Harmony SASEs security posture to customers and partners.
Stay current on the evolving Threats Landscape, regulations, and technologies, and translate them into pragmatic improvements to the security program.
Requirements:
We are looking for you:
Bachelors degree in computer science, Information Security, or related field.
Minimum of 5 years of experience in information security or application/product security, with at least 2 year in a leadership role.
Proven experience building or operating an Information Security Management System (ISMS) and leading certifications such as ISO/IEC 27001 and SOC 2.
Working knowledge of GDPR, PCI-DSS, and NIST CSF / 800-53; familiarity with HIPAA, FedRAMP, DORA, Cyber Essentials, C5, IRAP, AI Security Frameworks and the Cloud Controls Matrix (CCM).
Hands-on experience with S-SDLC, threat modeling, and application security tooling such as ASPM, SAST, and DAST in complex, high-scale environments.
Strong understanding of risk management, third-party risk, identity and access governance, and incident response.
Excellent communication and leadership skills, with the ability and passion to drive change across R&D and the broader organization.
Reports to the Harmony SASE Head of Architecture (R&D Director) and partners closely with R&D, DevOps, IT, Legal, and the company Corporate Security organization.
Relevant certifications such as CISM (preferred), CISSP, CCSP, ISO 27001 Lead Auditor / Lead Implementer, CCSP or CSSLP are desirable.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785659
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
06/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a highly skilled, technical, and multidisciplinary Deputy CISO to join our Bank's Information Security team. Reporting directly to the CISO, this key position serves as a right-hand lead in shaping technological strategy, managing risk, and implementing security policy. The role operates as a Senior Individual Contributor (IC) requiring high independence and real-world hands-on capabilities, and a strong 'all hands on deck' mindset.
Responsibilities
Strategic & Tech Partnership: Collaborate with the CISO and CIO to design security architecture, implement advanced solutions, and lead end-to-end tech projects.
Cloud Security & DevSecOps: Guide development teams, define secure cloud architectures, and enforce SSDF.
Hands-on Execution: Evaluate and deploy security technologies, analyze cyber/infrastructure incidents, and write/review code and scripts.
GRC & Banking Compliance: Lead GRC end-to-end, manage external pen-testing vendors, handle third-party/supply chain risk, ensure compliance with Bank of Israel regulations, and support audits.
Requirements:
5-10 years of experience in InfoSec and technology as a senior independent function.
Strong cloud security expertise (AWS preferred; Azure/GCP accepted).
Hands-on development background or deep technical understanding of CI/CD, containers, Microservices, and API Security.
Hands-on proficiency at the code, network, and infrastructure levels.
Excellent interpersonal skills and broad business vision, and strong collaborative abilities.
Advantages
Certifications: CISSP, CISM, CISA, CCSP, or AWS/Cloud Security certifications.
Experience with financial platforms or core banking systems.
Real-time Incident Response (IR) experience.
Deep acquaintance with banking GRC and Bank of Israel guidelines.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8810825
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
31/08/2026
חברה חסויה
Location: Tel Aviv-Yafo and Netanya
Job Type: Full Time
We are seeking a GRC Specialist (Governance, Risk, and Compliance) to join our growing GRC Team. This is a fantastic opportunity to be part of a growing team and support the company as it grows and matures. If you're a team player, self-driven, creative thinker, passionate about cybersecurity, and capable of blending a process-oriented mindset with a tech-oriented outlook, we are looking for you!

As a GRC specialist you will...
Maintain internal and external trust platforms, supporting ongoing customer due diligence activities including audits, questionnaires, and reviewing security contractual requirements.
Provide training and guidance to sales teams on compliance-related matters and develop tools and resources to enable the Sales Team to efficiently respond to compliance inquiries from prospective and existing customers.
Collaborate with cross-functional teams to support and enhance the overall GRC program.
Ensure company policies, procedures, and controls are aligned with regulatory requirements and industry standards.
Proactively gather customer feedback and stay abreast of industry trends to adapt and mature the GRC program accordingly.
Implement improvements and updates to the program, based on regulatory changes and customer requirements.
Participate in risk assessment and risk management processes.
Requirements:
Minimum 1-2 years as a cyber security / GRC specialist, expert, or consultant
Strong knowledge and hands-on experience with ISO 27001 and SOC 2 Type II
Familiarity with additional security frameworks as well as privacy regulations and standards (NIST, CSA, CAIQ, SIG, GDPR, CCPA, ISO 27701) is an advantage.
An excellent ability to communicate verbally and in writing
Ability to work on multiple projects simultaneously
Project management skills
Self-driven and fast learner with a can-do approach
Passionate about the team and responsibilities
Experience with auditing cloud environments
Experience in working with regulators and auditors
Experience in working with GRC tools
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8804094
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
02/09/2026
Location: Herzliya
Job Type: Full Time
About our company As a global semiconductor leader, our company  builds the hardware trust foundations powering modern computing - from trusted platform module (TPM) chips safeguarding millions of personal computers to complex root-of-trust architectures across cloud platforms and servers. Security is Embedded into the core of everything we design. As the global regulatory and threat landscape evolves, ensuring our products meet rigorous, gold-standard cybersecurity compliance and certifications is central to our mission and customer trust. About the Role We are looking for a highly motivated Security Certifications & Compliance Engineer to join our team and play a key role in ensuring our products meet the highest security, compliance, and certification standards. This position combines technical security expertise, compliance activities, product security governance, and collaboration with development teams to support industry-leading security products.
What You'll Do Certifications: Lead and support security certification activities, including Common Criteria (CC), FIPS 140-3, CSPN, OCP SAFE, and additional certification programs. Compliance & Frameworks: Support compliance initiatives related to the Cyber Resilience Act (CRA), Secure Development Lifecycle (SDL), NIST SSDF, and customer cybersecurity requirements. Cross-Functional Teamwork: Work closely with engineering teams, management, customers, certification bodies, and security experts across the organization. External Collaboration: Work closely with external laboratories and certification authorities throughout certification processes. Security Readiness: Review development processes, project documentation, and deliverables to ensure compliance and security readiness. Risk & Threat Assessment: Participate in threat modeling, risk assessments, security reviews, and secure development activities. Audits & Standards: Prepare for and support internal audits, external audits, and customer security assessments. Development Security system (DSS): Maintain, improve, and drive periodic activities for the Corporate Development Security system, including supporting security infrastructure, defining asset classifications, and driving employee awareness initiatives. Documentation: Prepare, review, and maintain certification documentation, including Security Targets, Security Policies, certification reports, and lifecycle evidence.
Requirements:
Education: B.Sc. in Computer Engineering, Electrical Engineering, Computer Science, Information Security, or a related field. Experience: 5+ years of experience in at least one the following: Cybersecurity, Product Security, Secure Development, Security Compliance, Information Security, Security Certifications, or Security Audits Domain Expertise: Background in the semiconductor industry. Core Technical Knowledge: Strong understanding of some of these areas: o Cryptography fundamentals o Secure Development Lifecycle (SDL) o Vulnerability management processes o Threat Modeling and Risk Assessment o Hardware and Embedded Security o Firmware and Software Security o Security Testing and Penetration Testing concepts
Advantages
* Experience with Common Criteria (CC), FIPS 140-3 or other security certifications.
* Familiarity with TPM technologies, Root of Trust architectures, Secure Boot and Post-Quantum Cryptography
* Knowledge of Cyber Resilience Act (CRA) and NIST frameworks
* Experience working with certification laboratories and regulatory bodies.
If you are passionate about silicon security and want to lead compliance for industry-defining hardware, send your CV to join our team.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8806462
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Data Protection Lead to join the Cyber Security organization.

This role combines hands-on Data Leakage Prevention (DLP) engineering with Data Security Posture Management (DSPM) to deliver end-to-end data protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will own the data protection lifecycle from discovery and classification through policy enforcement and incident response. The role requires deep technical proficiency in DLP platforms and DSPM tooling, combined with the ability to collaborate with Security, IT, Engineering, Product, Privacy and GRC teams to reduce data exposure risks and embed strong data governance practices.

Your responsibilities will include:
Lead and own the organizations data protection domain, including strategy, standards, and hands-on technical implementation
Engineer, deploy, and continuously tune DLP policies across endpoints, email, SaaS, network proxies, and cloud platforms - covering both inline and API-based enforcement modes.
Design and implement DSPM solutions to gain continuous visibility into sensitive data posture, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Drive data discovery initiatives to identify and inventory sensitive data across databases, SaaS applications, endpoints, and cloud storage.
Define and implement data classification frameworks, labeling standards, and data handling policies integrated with DLP and DSPM controls.
Build and maintain DLP detection rules, regular expressions, fingerprinting, and machine learning-based classifiers to minimize false positives and maximize coverage.
Integrate DSPM findings into DLP enforcement workflows to create a closed-loop data protection architecture.
Define and enforce data access governance, including least-privilege principles and monitoring of sensitive data access patterns.
Monitor, triage, and investigate DLP alerts and DSPM-identified risks, collaborating with SOC and Security teams on escalation and remediation.
Conduct risk assessments and identify gaps in data protection controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to data security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed data security controls into CI/CD pipelines, systems, and workflows.
Maintain documentation, runbooks, and guidelines for DLP operations, DSPM posture management, and data security practices.
דרישות:
6+ years of experience in cyber security, with a strong focus on data security, data protection, or information security.
Proven hands-on engineering experience with enterprise DLP platforms - including policy authoring, rule tuning, incident workflow configuration, and platform administration (e.g., Microsoft Purview DLP, Symantec DLP, Forcepoint, or equivalent).
Hands-on experience deploying and operating DSPM tools (e.g., Cyera, Varonis, Rubrik Security Cloud, Normalyze, Securiti, or equivalent) to manage cloud data exposure and classification at scale.
Deep understanding of DLP enforcement mechanisms: endpoint DLP, network DLP, email DLP, and cloud/API-based DLP controls.
Strong experience with data discovery and classification across cloud environments (AWS, Azure, GCP), SaaS platforms, and on-premises systems.
Ability to write and optimize detection logic - regular expressions, data fingerprinting, document fingerprinting, and EDM (Exact Data Matching).
Experience integrating DLP and DSPM tools with SIEM, SOAR, and ticketing systems for alert routing and automated response.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governanc המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818177
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
25/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are revolutionizing legal tech with an AI-powered Legal Intelligence Platform trusted by some of the world's fastest-growing companies including Wiz, Socure, and Fiverr.
We integrate seamlessly with Salesforce and other systems to help in-house legal teams accelerate negotiations, reduce risk, and unlock institutional knowledge through automated workflows.
We're solving complex problems at the intersection of AI and legal operations. Join us as we scale our impact globally.
About the Role
We're looking for a Head of Security to own security end-to-end at our company- from the architecture of our product to the systems our own team runs on.
We handle some of the most sensitive documents our customers have, and our buyers' security teams scrutinize us accordingly.
You'll be our first dedicated security hire and the sole internal authority on the subject: setting the standards our engineers build against, owning our compliance posture, and sitting across the table from customer CISOs to defend it.
This is a hands-on role with real strategic weight - if you want to build a security function from scratch at a company where security is a deal-maker, we want to hear from you.
What You'll Do
Design, architect, and implement security directly into our product and codebase
Own our internal security posture: corporate IT, access management, endpoint, and employee security practices
Lead customer-facing security engagements - pre-sales security reviews, CISO-level discussions, security questionnaires, and enterprise assessments - representing our company's posture to buyers who evaluate us seriously
Own our compliance program end-to-end, including audits, evidence, and vendor risk
Set security standards and best practices across R&D and product as the internal authority on the subject
Build the security review process for how we ship AI features - threat modeling around LLMs, agentic workflows, and customer data boundaries
Partner with DevOps and engineering on cloud security, secure architecture, and incident readiness
Grow the security function as we scale, from process to headcount.
Requirements:
Passion to own and deliver - you take full responsibility for security outcomes and drive initiatives from idea to production
Curiosity and adoption of AI tools - you actively use tools like Cursor or Claude Code and are excited about how AI is transforming both software development and the threat landscape
7+ years of hands-on security experience, with real depth in product or application security
Experience in customer-facing security roles, representing a company to client CISOs, IT directors, and security teams across enterprise and SMB
Strong command of cloud security (AWS/GCP/Azure), web application security, and secure architecture design
Hands-on experience running or building a compliance program (SOC 2, ISO 27001, or equivalent)
A builder's mindset - comfortable establishing process and structure where none exists
Ability to thrive in a fast-paced environment, balancing deep technical execution with high-level strategic and client conversations
Strong communication skills, effective in a fast-paced startup environment
Bonus Points
Experience securing LLM-powered applications, agentic systems, or AI infrastructure
Background working with legal, financial, or other high-stakes documentheavy domains
Hands-on coding ability in Python or TypeScript
Experience building a security function from scratch, especially as a founding or first security hire
Familiarity with Kubernetes, infrastructure-as-code, and cloud-native architectures.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8796752
סגור
שירות זה פתוח ללקוחות VIP בלבד