דרושים » אבטחת מידע וסייבר » חוקר /ת DFIR - Incident Response Malware Analysis

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 1 שעות
דרושים בדור טכנולוגיות מידע בע"מ
מיקום המשרה: תל אביב יפו
סוג משרה: משרה מלאה
חברתנו מגייסת חוקר/ת תגובה לאירועים (IR), זיהוי פלילי דיגיטלי ( Digital Forensics ) וניתוח נוזקות (Malware Analysis). התפקיד כולל:
- ניהול וטיפול באירועי סייבר מקצה לקצה: איתור, תחקור, בלימה, מיגור, שחזור והקשחת תשתיות.
-איסוף ראיות דיגיטליות, ביצוע ניתוח פורנזי וניתוח נוזקות (Malware Analysis).
-ביצוע Threat Hunting וחקירות מורכבות בסביבות Cloud ו-On-Premises.
-פיתוח סקריפטים ואוטומציות לטובת ייעול תהליכי התחקור והתגובה.
-כתיבת דוחות טכניים מפורטים, תיעוד מומחים והפקת לקחים.
דרישות:
-לפחות שנתיים ניסיון מעשי בתחומי ה-DFIR וניתוח נוזקות (MA).
-ניסיון מוכח בסביבות ענן (Cloud) ובסביבות מקומיות (On-Prem).
-שליטה חזקה בשפת Python וכתיבת סקריפטים.
-הבנה מעמיקה בפרוטוקולי תקשורת, ארכיטקטורת רשת ומערכות הפעלה Windows ו- Linux.
-ניסיון מעשי בעבודה עם כלי EDR, NDR, Firewalls וכלי Fast IR.
-היכרות ועבודה מעשית עם MITRE ATT CK והנחיות NIST IR.
-יכולת גבוהה בכתיבה וניסוח של דוחות טכניים.
-השכלה / הסמכות (חובה לפחות אחד מהבאים):
תואר ראשון במדעי המחשב או תחום מקביל.
הסמכות GIAC: GCFA / GNFA / GASF.
הסמכת EC-Council: CHFI.
הסמכות Offensive Security: OSCP / OSTH / OSIR / OSEP. המשרה מיועדת לנשים ולגברים כאחד.
 
הסתר
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8831589
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
לפני 21 שעות
דרושים בpeax talent
סוג משרה: מספר סוגים
לארגון ממשלתי גדול ומוביל טכנולוגית בתל אביב. דרוש/ה חוקר/ת סייבר!
עבודה במודל היברידי! 
מומחה/ית סייבר מוביל/ה לביצוע מחקר ופיתוח מתקדם בתחומי נוזקות, חולשות, פורנזיקה, הנדסה לאחור ומבדקי חדירות למערכות מורכבות.
התפקיד כולל פיתוח כלי מחקר מתקדמים וניתוח מערכות ופרוטוקולי תקשורת בסביבות מורכבות ובסקייל רחב ( Big Data ).
דרישות:
נדרש ניסיון של 7 שנים ומעלה!
ניסיון מוכח במחקר ופיתוח מתקדם בתחום סייבר, עם דגש על סביבת ענן.
ידע וניסיון בזיהוי, איתור ומתן התרעה על תקיפות סייבר בסביבות ענן מורכבות.
יכולת לפתח וליישם תפיסות חקירה מתקדמות, כולל מימוש שרשרת התקיפה והסקת מסקנות מחקרים.
ניסיון בגיבוש דוחות מחקר והעשרת מידע טכנולוגי לצוותי חקירות ולארגונים.
הבנה מעמיקה בפרוטוקולים, מערכות ענן וכלי מחקר טכנולוגיים מתקדמים. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8585336
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
לפני 23 שעות
דרושים בpeax talent
סוג משרה: מספר סוגים
לארגון ממשלתי גדול ומוביל טכנולוגית בתל אביב דרוש/ה חוקר/ת חולשות סייבר!
עבודה במודל היברידי!
השתלבות בצוות מחקר סייבר מתקדם, הכוללת מחקר חולשות אבטחה, ניתוח איומים, פיתוח כלי אוטומציה, ביצוע מבדקי חדירות ומתן המלצות להגנה על תשתיות קריטיות.
דרישות:
ניסיון של 5+ שנים בתחום מחקר חולשות, מחקר סייבר או Offensive Security.
ניסיון במחקר וניתוח חולשות אבטחה (CVE), כתיבת POC, פיתוח סקריפטים וכלי אוטומציה למחקר.
ניסיון בביצוע מבדקי חדירות אפליקטיביים, כתיבת דוחות מקצועיים ומתן המלצות לטיפול בממצאים.
היכרות עם מחקר איומים, מערכות הפעלה, רשתות, אבטחת מידע ופרוטוקולי תקשורת.
יכולת מחקר גבוהה, ראייה מערכתית, זיקה טכנולוגית וניסיון בפיתוח כלים בתחום הסייבר. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8791082
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
לפני 21 שעות
דרושים בpeax talent
מיקום המשרה: מספר מקומות
סוג משרה: מספר סוגים
לארגון ממשלתי גדול ומוביל טכנולוגית בתל אביב דרוש/ה חוקר/ת מודיעין איומי סייבר Threat Intelligence
עבודה במודל היברידי!
 מומחיות במערכות לביצוע חקירה בסביבת ענן, גיבוש תפיסת החקירה בענן, ביצוע מחקרים מודיעינים טכנלוגיים על תקיפות סייבר מתקדמות בסביבות הענן השונות לטובת איתור מזהים לביצוע חקירה, מימוש שרשרת התקיפה על סביבות הענן, מתן מענה מחקרי טכנולוגי מתקדם ומוביל להתמודדות בזיהוי, איתור גילוי ומתן התרעה לתקיפות סייבר בסביבות ענן שונות, העשרת המידע הטכנולוגי לצוותי החקירות בשטח לטובת איתור תקיפות אלו בפועל, גיבוש מקצועי של דוחות מחקר בנושא תקיפות סייבר בסביבות ענן לטובת יצירת התרעה לארגונים ספציפיים והמשק הישראלי בכלל, במסגרת העלאת יכולות החוסן לאתר ולהתמודד עם תקיפות סייבר בסביבות ענן
דרישות:
יסיון של 7 שנים ומעלה בביצוע מטלות המתוארות בתפקיד
בעל רקע וניסיון מחקרי בתחומי מחקר המשמשים לגילוי, זיהוי וטיפול באיומי סייבר בשניים או יותר מתוך התחומים הבאים:
מחקר פורנזי
מחקר רשתות
מחקר איומים ומערכיתקיפה
מחקר מודיעין סייבר
וכן ניסיון בחילוץ תובנות מחקריות ממידע מודיעיני-טכנולוגי
ביצוע מבדקי חדירות
טיפול ותגובה לאירועים
ניטור רשתות ורכיבים, ביצוע מחקרים
פיתוח כלים ומערכות בתחום הסייבר וכלים תומכי מחקר.
בעל ידע, Big Data מבוססי
נרחב ומתקדם במגוון מערכות ופרוטוקולים
הכרות טובה עם מע' מחשוב והפעלה, אבטחת מידע ותקשורת נתונים. בעלי ראיה מערכתית, זיקה טכנולוגית מובהקת ובפרט לתחום מדעי המחשב ומודעות שירות גבוהה
עצמאות ויכולת ייצוגית מול גורמים מקצועיים, היכרות עם הסקטור הציבורי והפרטי, יכולת למידה והבדלה בין עיקר וטפל, יחסי אנוש טובים, התאמה לתפקיד המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8791080
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
1 ימים
דרושים בליאקום מערכות Liacom
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה ועבודה היברידית
תחומי אחריות:
הובלת מחקר טכנולוגי מתקדם בתחומי הפעילות של היחידה
ביצוע והובלת מחקרים מבוססי ביג דאטה והפקת תובנות ממידע מודיעיני-טכנולוגי
מחקר מתקדם של מערכות, רשתות ופרוטוקולי תקשורת הרלוונטיים לפעילות בזירה הדיגיטלית.
בחינה שוטפת של טכנולוגיות, שיטות ויכולות מתקדמות והתאמתן לצורכי היחידה
הובלת פיתוח והטמעה של כלים ויכולות טכנולוגיות תומכי מחקר
גיבוש תפיסות ופתרונות טכנולוגיים להתמודדות עם אתגרים מורכבים ומשתנים
חיבור בין צרכים מבצעיים לבין יכולות טכנולוגיות ומחקריות, בשיתוף גורמי המוצר, הארכיטקטורה והData
מתן הכוונה מקצועית בסוגיות טכנולוגיות ומחקריות מורכבות
מעקב אחר מגמות והתפתחויות בתחומי דאטה וAI, סייבר וזירות דיגיטליות והערכת התאמתן לפעילות היחידה
דרישות:
ניסיון משמעותי ומוכח במחקר ו/או פיתוח טכנולוגי מתקדם בתחומי הסייבר והמידע
ניסיון מוכח בעבודה בשניים או יותר מהתחומים הרלוונטיים להגדרת חוקר סייבר רמה ד', כגון מחקר מתקדם של
ופיתוח כלים תומכי מחקר. Big Data, פרוטוקולי תקשורת, מחקר מודיעיני-טכנולוגי
ידע נרחב, מתקדם ומוכח במערכות ובפרוטוקולים.
ניסיון בהובלת מחקר טכנולוגי מורכב ובהפיכת תוצרי מחקר ליכולות טכנולוגיות ישימות.
ניסיון בחיבור בין צרכים מבצעיים או ארגוניים לבין פתרונות טכנולוגיים.
יכולת הובלה מקצועית בסביבה רב-תחומית הכוללת מחקר, מידע, data וטכנולוגיה
ניסיון בעבודה בסביבות טכנולוגיות מורכבות ורב-מערכתיות המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8825446
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
דרושים בMertens – Malam Team
סוג משרה: מספר סוגים
אנחנו מחפשים סוקר.ת PT חד.ה ויסודי.ת, עם יכולת מעשית לזהות חולשות, לנתח סיכונים ולהנגיש ממצאים מקצועיים לצוותי פיתוח וטכנולוגיה.
בתפקיד זה תבצע.י מבדקי חדירה 100% מהזמן במערכות Web ו-Mobile, בתשתיות, בסביבות AWS ו-Azure ובמערכות AI.
העבודה משלבת מתודולוגיות ותקנים מרכזיים ובהם OWASP, MITRE, NIST ו-PCI-DSS, לצד ביצוע סקרי סיכונים, בדיקות תאימות לרגולציה וכתיבת דוחות מקצועיים.
דרישות:
לפחות 3 שנות ניסיון בביצוע מבדקי חדירה למערכות ולאפליקציות Web ו-Mobile - חובה.
נכונות לעסוק בביצוע מבדקי חדירה לאורך 100% מהתפקיד - חובה.
ידע מעמיק במתודולוגיות תקיפה ובתקנים OWASP, MITRE ו-NIST - חובה.
הבנה בפרוטוקולי TCP/UDP, DNS, IP ו-HTTPS ובטכניקות תקיפת רשת - חובה.
היכרות עם AWS ו-Azure וניסיון בביצוע מבדקי חדירה בסביבות ענן - יתרון.
שליטה ב-PowerShell, ב-Bash, ב- JavaScript וב- Python, או ניסיון בעבודה בארגון פיננסי - יתרון.
זה הזמן להגיש קורות חיים דרך Mertens Malam Team, החברה הגדולה והמובילה במשק לגיוס טכנולוגי, ולבנות ולקדם איתנו את הקריירה הטכנולוגית שלכם. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8816760
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
דרושים בMertens – Malam Team
מיקום המשרה: מספר מקומות
סוג משרה: מספר סוגים
חברת Mertens - MalamTeam מגייסת חוקר.ת חולשות וסייבר לארגון גדול בתל אביב

תיאור משרה:
ביצוע מחקרי חולשות ואיומי סייבר, ניתוח CVE וPOC, פיתוח כלי מחקר ואוטומציה,
ביצוע מבדקי חדירות אפליקטיביים וכתיבת דוחות והמלצות לטיפול בממצאים.
עבודה שוטפת עם מקורות מודיעין טכנולוגיים ומחקר מגמות בתחום הסייבר.
דרישות:
ניסיון של 5 שנים לפחות במחקר סייבר, חולשות או פיתוח בתחום הסייבר.
ניסיון באחד או יותר מהתחומים: מחקר נוזקות, חולשות, פורנזיקה, Reverse Engineering, מחקר פרוטוקולים או Penetration Testing.
ניסיון בפיתוח כלי מחקר ואוטומציה או במחקרים מבוססי Big Data.
ידע מעמיק במערכות מחשוב, מערכות הפעלה, אבטחת מידע, תקשורת נתונים ומגוון פרוטוקולים.
ניסיון בפיתוח כלים ומערכות בתחום הסייבר וכלים תומכי מחקר.
ראייה מערכתית, זיקה טכנולוגית גבוהה ויכולת למידה עצמית. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8776720
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a hands-on role that balances deep technical work along with building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by.

Youre welcome to work in our offices in Tel Aviv, Israel.

Your responsibilities will include:

Build and lead global DFIR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders.
Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases.
Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction.
Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements.
Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR.
Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA).
Raise the teams technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness.
Requirements:
7+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise).
Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2).
Technical Expertise

Deep knowledge of Windows and Linux internals, with proven disk and memory forensics capability.
Strong cloud-native platform security: containers and Kubernetes, CI/CD, secrets management, cloud control planes, and IAM attack paths.
Fluency in attacker TTPs (MITRE ATT&CK, including the Cloud and Containers matrices), and hands-on experience with EDR, SIEM, and forensic tooling (e.g., Velociraptor, Volatility, X-Ways/EnCase).
Strong scripting and data-analysis skills (Python, PowerShell, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818167
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
26/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for a top-notch Threat Detection Researcher to join our team and spread the power. In this role, you will further develop the Runtime Sensor as part of our threat research team.
Responsibilities
Develop detections and tools to protect customers from cloud threats.
Investigate attacks on cloud environments and malware targeting cloud and AI workloads.
Hunt and analyze real-world attacks and emerging cloud and AI threats.
Collaborate closely with the R&D team to transform research insights into product features.
Work with customers in response to requests related to suspicious activity or potential incidents.
Create best practices and security policies based on research findings.
Deliver external-facing content (blog posts and talks at security conferences) based on security insights and novel research.
Requirements:
Minimum Qualifications
6+ years of experience in security or threat research in which you conducted deep research with actionable conclusions and impacts.
Intimate knowledge of OS internals (Windows/Linux/MacOS) and networking.
Familiarity with cloud services, Kubernetes, cloud environment architecture, and the major cloud providers (AWS, GCP, Azure).
Proficiency in Python for tool development and automation.
Experience delivering security detections in customer-facing product(s).
The ability to learn independently, to be self-driven and goal-oriented.
Preferred Qualifications
Knowledge of Go, Rust, or C/C++.
Hands-on experience with malware analysis/reverse engineering/vulnerability research.
Familiarity with notable threat actors and threat intelligence analysis.
IR/red-team/threat-hunting experience.
Experience leveraging AI to supercharge research and detection workflows.
Deep knowledge of modern threat classes (Supply Chain, CI/CD, or threats targeting AI infrastructure and agentic frameworks).
Excellent communication and teamwork skills.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8798644
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
17/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Hunt, investigate, and analyze advanced persistent threat (APT) activity across endpoints, servers, cloud, and network infrastructure. partner with our Threat Intelligence team to resolve complex intrusions in customer networks. You'll uncover stealthy adversary behavior, reconstruct attack chains, and build the tools and methods that make our hunting and forensics better. You'll also present original research at top-tier industry conferences and
Key Responsibilities
Hunt and investigate targeted intrusions, long-dwell compromises, and espionage- driven activity across enterprise, cloud, identity, and network environments.
Perform advanced forensics across operating systems, cloud, memory, and network telemetry; correlate signals to determine the scope of compromise.
Build innovative tooling, research systems, and hunting/investigation workflows; identify capability gaps and propose automations to close them.
Produce clear reports, forensic timelines, threat-actor assessments, and actionable detection and remediation guidance.
Support internal security, threat intelligence, detection engineering, and investigation teams with expert forensic findings and technical analysis.
Partner with the Threat Intelligence team to resolve complex intrusions in customer networks.
Represent the organization through conference talks, workshops, and original research.
Requirements:
Extensive hands-on APT hunting, intrusion investigation, and digital forensics.
Deep understanding of APT tradecraft - stealth, persistence, credential abuse, defense evasion, living-off-the-land, custom tooling, supply-chain compromise, and command-and-control.
Broad forensic expertise across operating systems, cloud platforms, network and edge infrastructure, and memory, using industry-standard forensic and hunting tools.
Telemetry analysis across security platforms (EDR, SIEM, network, and identity systems) and the ability to build detection and hunting logic.
Strong development skills in Python (and ideally another language such as Go, C/C++, or PowerShell) to build tooling, automations, and analysis pipelines.
Strong communication for technical and executive audiences, including conference-grade presentations.
Represents the organization publicly, delivering talks, workshops, and research at top-tier cybersecurity and forensics conferences.
Nice to Have
Malware analysis and reverse engineering.
Experience with enterprise EDR/XDR and SIEM platforms.
Container, SaaS, and hybrid-cloud investigation experience.
Threat-intel collaboration; published research or prior conference talks.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8785669
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד