דרושים » אבטחת מידע וסייבר » Cyber Risk Assessor-2640

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 2 שעות
חברה חסויה
Location: Merkaz
Planning, managing, and executing cyber assessments to ensure regulatory compliance and secure the network operations of entities under the organization's responsibility.
Key Responsibilities
Responsible for identifying and mitigating cyber risks through risk surveys, audits, and technological assessments.
1. Risk Identification and Mapping: Examining and mapping network architecture, assets, processes, and security control.
2. Technological Validations: Performing technical tests to verify the effectiveness of security controls.
3. Damage Potential: Analyzing the correlation between threats, vulnerabilities, and controls, and assessing their impact on the organization's overall exposure level.
4. Professional Opinion: Providing evidence-based recommendations.
Requirements:
1. Experience in Risk Surveys: Proven experience in end-to-end risk surveys (planning, evidence collection, findings analysis, and drafting professional opinions).
2. Hands-On: Practical experience in scanning tools, asset mapping, network configuration audits, and control validation.
3. Standards: Familiarity with methodologies and standards, including ISO 27001, 27005, 19011, NIST-CSF, and SCF.
כישורים נדרשים
Critical Analysis: Ability to analyze complex information, identify gaps, and derive evidence-based conclusions.
Interface Management: Ability to work with diverse stakeholders while maintaining professionalism and independence.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8835433
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
דרושים באלביט מערכות
Location: Haifa
Job Type: Full Time
Role Purpose
Lead Technology Governance, (TGRC) within the cybersecurity domain by implementing security policies, reducing risk, and ensuring compliance with international regulations and standards
Key Responsibilities
Develop and implement Cyber TGRC frameworks
Conduct risk assessments and define mitigating control
Establish and maintain policies, standards and procedures aligned to ISO 27001, NIST, CIS ETC
Manage compliance with GDPR, SOX, ITAR/EAR and other regulations
Plan and execute internal/external audits and lead corrective actions
Collaborate with IT/OT, Legal, Procurement and business stakeholders
Support incident response with regulatory reporting and governance requirements
Measure, monitor and report risk posture and KPIs to leadership
Requirements:
3+ years of proven experience in GRC/Information Security
Deep knowledge of standards/regulations: ISO 27001, NIST-CSF, CIS Controls, GDPR, S
Strong technical understanding across infrastructure, cloud, networking and OT protocols
Experience in project management, policy writing and control implementation
Excellent English (written and verbal)
Relevant certifications: CISM, CRISC, ISO 27001 Lead Implementer /Lead Auditor - advantage
Skills
Analytical thinking and risk management orientation
Strong communication and stakeholder engagement
Executive reporting and documentation capabilities
Proactive, accountable and independent working style
Role Benefits
Direct impact on organizational cyber resilience aligned to business objectives
Broad exposure to technologies, regulations and cross-functional collaboration
This position is open to all candidates.
 
Show more...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8801406
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/08/2026
חברה חסויה
Location: Herzliya
Job Type: Full Time and Hybrid work
we are looking for a security architect to join our team! 
The cyber architecture team is part of professional services delivery department and is dedicated to helping drive customers' cybersecurity maturity forward. as a security architect you would be conducting enterprise level organizations' white-box risk assessments, reviewing design issues or security controls configuration, and offering relevant mitigations to identified risks during penetration testing, executed by red teamers.  
Responsibilities:
Perform security maturity assessments, including reviews of organizational policies, standards, procedures, and governance practices, aligned with the NIST CSF 2.0 cybersecurity framework.
Review designed or deployed environments, identifying security flaws and recommending mitigations plans
Review Implementation of technical security controls, identify gaps and offer practical mitigations.
Escort, evaluate and improve our clients security posture by elevating their infrastructure resilience and implement best-practice organizational procedures
Escort mitigation plans and design practical implementations for security issues e.g., firewall policies review, segmentation & segregation recommendations, Microsoft AD-tier Model implementation etc.
Research and advocate for new security solutions and technologies
Requirements:
3+ years of hands-on experience with securing large organizational networks, including security controls, OS hardening, network devices security, etc.
Strong understanding of governance, risk management, and operational processes.
Familiarity with cybersecurity frameworks (NIST CSF, ISO 27001 concepts), risk assessment, mitigation planning, and third‑party risk management.
Significant experience in at least five subjects from the following list:
Vast knowledge and expertise in cyber-security IT systems and cloud infrastructure
Deep understanding of Microsoft IT on-prem and cloud infrastructure, e.g., Entra-id, Office365, AD, GPO, protocols.
Practical experience with cloud environments - AWS, Azure, GCP- A significant advantage
Practical experience in consulting services and risk assessment
Practical experience with security configuration and maturity assessment
Knowledge of security controls, e.g., AV, EDR/XDR, DLP, Device control, etc.
ZTNA design & deployment experience.
Experience with implementing security monitoring procedures & systems (SOC, SIEM, SOAR)
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8793449
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Herzliya
Job Type: Full Time and Hybrid work
we are looking for a GRC Security Specialist.
Cyber Security Governance protects the security of an organizations information systems and data by setting policies, monitoring compliance, and following defined procedures to identify, assess, and manage risks from external and internal threats. We are seeking a GRC Security Specialist to join our Cyber GRC Team . You will be joining a tight-knit and highly respected team of GRC experts who are central to security strategy. In this role, you will be at the heart of protecting our global financial platform, directly influencing the trust and safety of millions of users worldwide. As a GRC Security Specialist, you will be responsible for the following:
Glilot, Israel
Hybrid
Full-time
What you'll do:
Directly responsible for policies, procedures, and controls to assure compliance with applicable regulatory, legal, and audit requirements as well as good business practices.
Develop a Cyber security compliance strategy and approach and ensure compliance with contractual requirements and globally recognized standards and guidelines.
Identify regulatory, legislative, and industry-specific compliance requirements and define controls that can be used to meet those requirements.
Conduct and participate in periodic internal reviews or audits to ensure that compliance procedures are followed.
Oversee and evaluate compliance systems to ensure they function effectively.
Compile and present reports to management on compliance activities and progress.
Stay updated on industry developments, regulatory trends, and best practices to evaluate their potential impact on the organization.
Design and implement enhancements in compliance communication, monitoring, and enforcement mechanisms.
Develop and execute a compliance awareness program, including the creation and distribution of materials for all employees.
Partner with Legal and IT teams to manage data protection agreements and compliance initiatives.
Lead the development and execution of company-wide security awareness and training initiatives.
Assist in incident response planning and investigations when necessary.
Requirements:
3+ years of experience in GRC, information security, or compliance within SaaS, cloud, or enterprise IT environments.
Strong understanding of regulatory frameworks and security standards such as SOC 2, PCI-DSS, NIST, and cloud security frameworks.
Knowledge and experience in AI Governance, including AI risk management, ethical AI principles, and alignment with frameworks such as EU AI Act, NIST AI RMF, and ISO/IEC 42001.
Strong knowledge of SDLC methodology.
Strong knowledge of IT systems and security controls.
Experience conducting security risk assessments and working with auditors or regulatory bodies.
Strong project management skills with the ability to manage multiple compliance initiatives.
Experience working with IT teams and business stakeholders to enhance security measures.
Excellent communication and collaboration skills, with the ability to translate compliance requirements into actionable business processes.
Ability to effectively interface with technical staff and senior management.
Proficiency in English and Hebrew, both written and spoken, to effectively communicate with local and global teams and stakeholders.
Excellent teamwork and interpersonal communication abilities
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8834274
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Data Protection Lead to join the Cyber Security organization.

This role combines hands-on Data Leakage Prevention (DLP) engineering with Data Security Posture Management (DSPM) to deliver end-to-end data protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will own the data protection lifecycle from discovery and classification through policy enforcement and incident response. The role requires deep technical proficiency in DLP platforms and DSPM tooling, combined with the ability to collaborate with Security, IT, Engineering, Product, Privacy and GRC teams to reduce data exposure risks and embed strong data governance practices.

Your responsibilities will include:
Lead and own the organizations data protection domain, including strategy, standards, and hands-on technical implementation
Engineer, deploy, and continuously tune DLP policies across endpoints, email, SaaS, network proxies, and cloud platforms - covering both inline and API-based enforcement modes.
Design and implement DSPM solutions to gain continuous visibility into sensitive data posture, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Drive data discovery initiatives to identify and inventory sensitive data across databases, SaaS applications, endpoints, and cloud storage.
Define and implement data classification frameworks, labeling standards, and data handling policies integrated with DLP and DSPM controls.
Build and maintain DLP detection rules, regular expressions, fingerprinting, and machine learning-based classifiers to minimize false positives and maximize coverage.
Integrate DSPM findings into DLP enforcement workflows to create a closed-loop data protection architecture.
Define and enforce data access governance, including least-privilege principles and monitoring of sensitive data access patterns.
Monitor, triage, and investigate DLP alerts and DSPM-identified risks, collaborating with SOC and Security teams on escalation and remediation.
Conduct risk assessments and identify gaps in data protection controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to data security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed data security controls into CI/CD pipelines, systems, and workflows.
Maintain documentation, runbooks, and guidelines for DLP operations, DSPM posture management, and data security practices.
דרישות:
6+ years of experience in cyber security, with a strong focus on data security, data protection, or information security.
Proven hands-on engineering experience with enterprise DLP platforms - including policy authoring, rule tuning, incident workflow configuration, and platform administration (e.g., Microsoft Purview DLP, Symantec DLP, Forcepoint, or equivalent).
Hands-on experience deploying and operating DSPM tools (e.g., Cyera, Varonis, Rubrik Security Cloud, Normalyze, Securiti, or equivalent) to manage cloud data exposure and classification at scale.
Deep understanding of DLP enforcement mechanisms: endpoint DLP, network DLP, email DLP, and cloud/API-based DLP controls.
Strong experience with data discovery and classification across cloud environments (AWS, Azure, GCP), SaaS platforms, and on-premises systems.
Ability to write and optimize detection logic - regular expressions, data fingerprinting, document fingerprinting, and EDM (Exact Data Matching).
Experience integrating DLP and DSPM tools with SIEM, SOAR, and ticketing systems for alert routing and automated response.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governanc המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818177
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
28/08/2026
חברה חסויה
Location: Ramat Gan
Job Type: Full Time
As a Cybersecurity GRC Specialist at our innovative healthcare startup, you will own our information security program end to end. We are on a mission to bring the first Hybrid Drug to market: a groundbreaking therapeutic entity that integrates mobile apps with traditional medication. Operating at the intersection of digital health and pharma means security, privacy, and compliance are core to what we build - and you'll be the one making sure we get it right. If you're excited to shape and lead the security function of a growing company (rather than inherit one), read on

About the Role
This is a hands-on role with broad ownership. You'll act as our security lead, serving as the go-to person for all things governance, risk, and compliance - working directly with leadership, engineering, quality, and clinical teams. It's a great fit for someone with a few years of GRC experience who's ready to take on company-wide responsibility, not a traditional executive CISO position.

‍

Responsibilities
Governance & Security Program
Build, implement, and maintain our Information Security Management System (ISMS) in line with ISO 27001.
Develop and enforce security policies, standards, guidelines, and procedures across the company.
Foster a culture of security awareness through training and ongoing communication.
Risk Management
Identify, assess, and prioritize cyber risks across our products, infrastructure, and vendors.
Conduct Business Impact Analyses (BIA) to map critical business functions and potential disruptions.
Own the risk register and drive mitigation plans with relevant stakeholders.
‍
Compliance & Regulatory Alignment
Ensure compliance with healthcare and privacy regulations, including HIPAA and GDPR.
Support regulatory and quality processes relevant to medical device software (e.g., working alongside our QA/RA team on standards such as ISO 13485 and IEC 62304 where security intersects).
Manage security aspects of customer, partner, and vendor due diligence, including security questionnaires and audits.
Resilience & Incident Preparedness
Design and maintain Business Continuity (BCP) and Disaster Recovery (DRP) plans.
Define and test incident response procedures; lead response efforts when needed.
Run periodic tabletop exercises and recovery drills.
Security Operations & Engineering Collaboration
Work with engineering to embed security requirements into the development lifecycle of our mobile and cloud platforms.
Coordinate penetration tests, vulnerability assessments, and remediation follow-up.
Evaluate and manage security tooling appropriate to our size and needs.
Requirements:
2-4 years of hands-on experience in a GRC, information security, or IT security role - ideally in healthcare, medtech, or another regulated industry.

Knowledge
Practical experience implementing or maintaining ISO 27001-based ISMS (certification project experience is a strong plus).
Solid understanding of risk management methodologies, BIA, BCP, and DRP.
Familiarity with privacy and healthcare regulations such as GDPR and HIPAA.
Skills & Mindset
Strong ability to translate security and compliance requirements into practical, business-aligned actions.
Comfortable working independently and owning a domain across the whole company.
Excellent communication skills - you can explain risk to engineers, executives, and auditors alike.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8800876
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
30/08/2026
Location: Petah Tikva
Job Type: Full Time
We are looking for an Information Security and Cyber Specialist with hands-on experience in information security systems to join the company’s Information Security team. The role includes responsibility for the operation and management of security systems, the investigation of information security incidents, and advanced technological areas within the Information Security Department.

Responsibilities:

* Monitoring, operation, and maintenance of information security systems.
* Handling and analyzing information security incidents at the Tier 2 level.
* Conducting initial and advanced investigations of cyber incidents.
* Working with IT and DevOps teams and external vendors.
* Writing procedures and technical documentation.
* Assisting with regulatory controls, risk assessments, and audits.
* In-depth knowledge of Microsoft 365 and Azure Security systems.
* Experience in managing and implementing EDR/XDR and SIEM systems and endpoint protection solutions.
* In-depth understanding of networking and Windows and Linux operating systems.
* Experience working with firewalls, VPN, NAC, and network security solutions.
* Ability to work independently, learn quickly, and maintain a system-wide perspective.
Requirements:
Mandatory Requirements
* At least five years of experience in information security and cybersecurity.
* Experience working with Microsoft 365 Security and Defender.
* Experience with EDR/XDR or SIEM systems.
* Knowledge of networking, Active Directory, Windows Server, and Entra ID.
* Experience handling information security incidents.
* Strong self-learning capabilities and the ability to work independently.
Preferred Qualifications
* Experience in Azure and on-premises environments.
* Knowledge of PowerShell or Python.
* Experience working with information security standards and regulatory requirements.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8801753
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
The GRC Program Coordinator works across security risk management, strategic certification and regulatory programs, and other governance, risk, and compliance activities as they arise. This is a hands-on role that combines program execution with real GRC subject-matter knowledge: the person in this role is expected to understand security and compliance concepts well enough to contribute professional judgment, not only to coordinate schedules and trackers. The scope spans multiple concurrent programs and will grow to include new initiatives over time.

Your responsibilities will include

Program Execution

Support the planning, tracking, and execution of strategic certification and regulatory programs: milestones, owners, due dates, and status across multiple concurrent workstreams.
Coordinate evidence collection, documentation, and readiness activities in support of certification and audit cycles.
Support engagement with external assessors, auditors, and vendors, including scheduling, correspondence, and tracking of deliverables against agreed timelines.
Security Risk Support

Contribute to security risk assessment activities: help identify, assess, and document risks, and support the maintenance of the risk register.
Support risk mitigation and follow-up activities, including tracking corrective actions through to closure and helping confirm that remediation is effective, not just logged as complete.
Help prepare risk and program status materials for internal review.
General GRC Support

Take on additional governance, risk, and compliance activities as priorities evolve, applying sound judgment on how a given task fits existing frameworks and processes.
Maintain organized, audit-ready documentation across the programs and activities supported.
Identify opportunities to improve tracking, reporting, and process efficiency across the programs supported.
Requirements:
2-4 years of experience in information security, GRC, compliance, IT risk, or a closely related field.
Working knowledge of information security and compliance concepts (e.g., risk assessment, control frameworks, certification or audit cycles) sufficient to engage substantively with the work, not only to track it.
Strong organizational skills and comfort managing multiple concurrent workstreams with different cadences and stakeholders.
Clear written and verbal communication; able to synthesize status and findings accurately from multiple sources.
Proficiency with common tracking and documentation tools (e.g., Jira, Excel/spreadsheets); Confluence familiarity a plus.
Discretion with sensitive compliance and security information.
Genuine interest in growing into broader ownership of risk and program work over time.
Prior exposure to security certifications (e.g., ISO 27001, SOC 2), risk frameworks, or regulatory compliance programs is an advantage, not a requirement.
Bachelor's degree in information security, computer science, engineering, or a related field preferred; equivalent practical experience will be considered.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818150
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Head of Security Reliability to establish and lead the Security Reliability pillar. Reporting directly to the CISO, this leader will be accountable for the ongoing effectiveness, resilience, and operational maturity of security products after implementation.

The role ensures that security platforms remain properly configured, maintained, integrated, monitored, adopted, and optimized to deliver measurable risk reduction. It also owns Third-Party Risk Management (TPRM) program and the security-review process for new products, services, and technologies introduced across the company.

This is a hands-on leadership position for someone who combines security expertise, operational discipline, vendor-management experience, and a strong product mindset. The role partners closely with Security, IT, Engineering, Product, Procurement, Legal, Privacy, Compliance, and business stakeholders.

Key responsibilities

Security product reliability and lifecycle ownership

Own security products and platforms after implementation, from operational handover through optimization, renewal, replacement, or retirement.
Ensure security tools are correctly configured, maintained, integrated, monitored, and aligned with Nebius's risk profile and technical environment.
Define ownership, service levels, operating procedures, support models, and escalation paths for every security platform.
Monitor platform availability, data quality, control coverage, integration health, licensing, capacity, and performance.
Establish disciplined processes for upgrades, configuration changes, testing, exception management, and end-of-life planning.
Continuously assess whether security products deliver their intended outcomes, and improve utilization, coverage, automation, and return on investment.
Reduce overlapping capabilities, configuration drift, operational gaps, and underused tooling across the security stack.
Manage vendor performance, technical escalations, product-roadmap discussions, renewals, and service reviews.
Ensure newly implemented security products transition into operations with clear documentation, ownership, monitoring, and success criteria.
Security configuration and control assurance

Define and maintain secure configuration baselines for security platforms.
Establish continuous control-health monitoring to identify disabled, degraded, misconfigured, or incomplete controls.
Validate that integrations and telemetry remain complete, accurate, and reliable as environment evolves.
Coordinate remediation of control gaps with Security, IT, Engineering, and platform owners.
Maintain evidence demonstrating the operational effectiveness of security controls for audits, certifications, and customer-assurance activities.
Requirements:
Significant cybersecurity experience, including leadership responsibility in security engineering, security operations, platform security, security architecture, or technology risk.
Proven experience owning security products in production, including configuration, maintenance, integration, optimization, and lifecycle management.
Strong understanding of enterprise and cloud security technologies, architectures, and operating models.
Experience establishing or managing a Third-Party Risk Management program.
Experience performing security architecture, technology, vendor, or product reviews.
Demonstrated ability to translate technical findings into clear business risks and actionable recommendations.
Experience managing teams, budgets, vendors, service providers, and cross-functional programs.
Strong knowledge of security control frameworks and risk-management principles.
Ability to operate effectively in a complex, fast-moving, and highly technical organization.
Excellent communication and stakeholder-management skills, including presenting risks and recommendations to senior leadership.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818125
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/08/2026
Location: Herzliya
Job Type: Full Time and English Speakers
we are seeking a Cybersecurity Architect (GRC & Risk) to join our cybersecurity architecture team. In this role, you will lead security governance, risk, and control assessments, conduct third-party due diligence, support maturity assessments, and drive mitigation and architectural review processes. Youll work closely with CISOs, security leaders, engineering teams, and customers to develop risk-focused methodologies and improve security frameworks. This position is best suited for candidates with a technical GRC, risk, or security assessment background who excel in analysis, interpretation, and structuring of security information.
Responsibilites:
Lead customer third‑party security due diligence assessments.
Lead mitigation workshops to translate penetration test and assessment findings into prioritized remediation workplans.
Perform security maturity assessments, including reviews of organizational policies, standards, procedures, and governance practices, aligned with the NIST CSF 2.0 cybersecurity framework.
Develop and refine security methodologies, processes, and architectural guidance.
Maintain internal documentation and ensure alignment between frameworks, processes, and practical implementation.
Analyze technical findings and map them to governance, risk, and control gaps.
Produce clear, structured reports and executive‑ready summaries for technical and non‑technical audiences.
Requirements:
3-4 years in cybersecurity GRC, IT risk, compliance, audit/assurance, or related process‑oriented security roles.
Strong understanding of governance, risk management, and operational processes.
Familiarity with cybersecurity frameworks (NIST CSF, ISO 27001 concepts), risk assessment, mitigation planning, and third‑party risk management.
Basic conceptual understanding of cloud/SaaS shared responsibility models.
Ability to communicate technical issues in business‑aligned language.
Hands-on experience with security controls - an advantage.
Strong writing, communication, and facilitation skills.
Comfortable collaborating with internal stakeholders and external customers.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8793444
סגור
שירות זה פתוח ללקוחות VIP בלבד