דרושים » אבטחת מידע וסייבר » Director of Managed Security Services - SOC Security Operations

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
לפני 18 שעות
דרושים בקרול יועצים
Job Type: Full Time
Key Responsibilities:

Lead the managed security services operation, ensuring high-quality delivery, performance, and customer satisfaction.
Manage, mentor, and develop SOC and Security Engineering teams.
Build strong relationships with senior customer stakeholders and lead communications during critical incidents and escalations.
Define and continuously improve SLAs, KPIs, workflows, and service standards.
Drive improvements in detection engineering, incident response, and security automation.
Support customer onboarding, renewals, expansions, and technical presales activities.
Identify customer needs and operational insights and translate them into improvements across the organization.
Drive operational excellence and continuous improvement across service delivery.
Requirements:
Proven leadership experience in Managed Security Services, SOC Operations, Security Engineering, or a closely related field.
Experience managing technical teams and complex customer-facing security services.
Strong knowledge of incident response, detection, SIEM technologies, and cloud environments such as AWS and Azure.
Strong communication skills, with the ability to explain complex technical topics to both security professionals and business stakeholders.
Proven track record of improving service quality, operational processes, and team performance.
Strong customer orientation and ability to operate effectively in high-pressure environments.
This position is open to all candidates.
 
Hide
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8842108
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Job Type: Full Time
We are looking for an experienced and highly driven Head of Security to join our Security leadership team, reporting directly to the CISO.

This is a unique opportunity to play a key leadership role in shaping and scaling the security program of a fast-growing fintech company. As Head of Security, you will serve as the CISO's trusted partner, helping drive the organization's security strategy while leading day-to-day execution across multiple security domains.

Yo will oversee both the Security Operations , Security Engineering and GRC organizations, managing team leads and security professionals across Israel and abroad. This role requires a strong combination of strategic thinking, technical depth, operational excellence, and people leadership.

The ideal candidate brings experience from large-scale, cloud-native environments and has successfully led security programs spanning Security Operations, Security Engineering, Compliance, Risk Management, and Security Architecture. You will work closely with Engineering, Infrastructure, IT, Product, Legal, Compliance, and executive leadership teams to continuously strengthen our security posture while enabling business growth.

What You'll Do
Drive execution of strategic security initiatives across the organization.
Partner closely with the CISO to define and execute our security strategy and roadmap.
Translate business objectives into scalable security programs and controls.
Act as a key stakeholder in security governance, risk management, and decision-making processes.
Help shape the future of Security, including emerging domains such as AI Security and Security Automation.

Organizational Leadership & Business Partnership
Lead and mentor multiple security teams, including Security Operations and Security Engineering, through direct management of team leaders and global security personnel.
Build scalable operating models, KPIs, governance processes, and organizational structures that support Sunbit's rapid growth and global expansion.
Partner closely with Engineering, Infrastructure, Product, IT, Legal, Compliance, Privacy, Risk, and Business leaders to ensure security enables business objectives while managing risk appropriately.
Collaborate extensively with US-based stakeholders and cross-functional teams in a dynamic global environment.
Drive the adoption of AI, automation, and emerging technologies to improve security effectiveness, operational efficiency, and scalability.
Requirements:
What We're Looking For:
10+ years of experience in Information Security, Cybersecurity, or Security Engineering roles.
5+ years of leadership experience managing security teams and managers.
Proven experience leading security programs in large-scale, high-growth organizations.
Strong background across multiple security domains, including Security Engineering, Security Operations, Cloud Security, Incident Response, Vulnerability Management, and Governance.
Extensive experience securing cloud-native environments (AWS, GCP, Azure).
Deep understanding of security architecture, security controls, and modern security technologies.
Experience working with regulatory frameworks, audits, compliance programs, and risk management processes.
Demonstrated ability to lead cross-functional initiatives across Engineering, Infrastructure, Product, and Business teams.
Strong communication and stakeholder management skills.
Fluent English, with extensive experience working with global teams and international stakeholders.

Nice to have
Experience in fintech, financial services, or highly regulated environments.
Experience leading AI Security initiatives or security automation programs.
Hands-on experience with modern security platforms such as CrowdStrike, Wiz, Okta, SIEM, and Identity solutions.
Relevant certifications such as CISSP, CISM, CCSP, CRISC, or equivalent
Experience building and scaling security organizations.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8831058
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Head of Security Reliability to establish and lead the Security Reliability pillar. Reporting directly to the CISO, this leader will be accountable for the ongoing effectiveness, resilience, and operational maturity of security products after implementation.

The role ensures that security platforms remain properly configured, maintained, integrated, monitored, adopted, and optimized to deliver measurable risk reduction. It also owns Third-Party Risk Management (TPRM) program and the security-review process for new products, services, and technologies introduced across the company.

This is a hands-on leadership position for someone who combines security expertise, operational discipline, vendor-management experience, and a strong product mindset. The role partners closely with Security, IT, Engineering, Product, Procurement, Legal, Privacy, Compliance, and business stakeholders.

Key responsibilities

Security product reliability and lifecycle ownership

Own security products and platforms after implementation, from operational handover through optimization, renewal, replacement, or retirement.
Ensure security tools are correctly configured, maintained, integrated, monitored, and aligned with Nebius's risk profile and technical environment.
Define ownership, service levels, operating procedures, support models, and escalation paths for every security platform.
Monitor platform availability, data quality, control coverage, integration health, licensing, capacity, and performance.
Establish disciplined processes for upgrades, configuration changes, testing, exception management, and end-of-life planning.
Continuously assess whether security products deliver their intended outcomes, and improve utilization, coverage, automation, and return on investment.
Reduce overlapping capabilities, configuration drift, operational gaps, and underused tooling across the security stack.
Manage vendor performance, technical escalations, product-roadmap discussions, renewals, and service reviews.
Ensure newly implemented security products transition into operations with clear documentation, ownership, monitoring, and success criteria.
Security configuration and control assurance

Define and maintain secure configuration baselines for security platforms.
Establish continuous control-health monitoring to identify disabled, degraded, misconfigured, or incomplete controls.
Validate that integrations and telemetry remain complete, accurate, and reliable as environment evolves.
Coordinate remediation of control gaps with Security, IT, Engineering, and platform owners.
Maintain evidence demonstrating the operational effectiveness of security controls for audits, certifications, and customer-assurance activities.
Requirements:
Significant cybersecurity experience, including leadership responsibility in security engineering, security operations, platform security, security architecture, or technology risk.
Proven experience owning security products in production, including configuration, maintenance, integration, optimization, and lifecycle management.
Strong understanding of enterprise and cloud security technologies, architectures, and operating models.
Experience establishing or managing a Third-Party Risk Management program.
Experience performing security architecture, technology, vendor, or product reviews.
Demonstrated ability to translate technical findings into clear business risks and actionable recommendations.
Experience managing teams, budgets, vendors, service providers, and cross-functional programs.
Strong knowledge of security control frameworks and risk-management principles.
Ability to operate effectively in a complex, fast-moving, and highly technical organization.
Excellent communication and stakeholder-management skills, including presenting risks and recommendations to senior leadership.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818125
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Sr MSIAM SOC Engineer (Unit 42)
Job Summary
As a Senior SOC Engineer within Unit 42, you will drive the creation, validation, and optimization of custom detection rules and automated playbooks across our global customer base. Acting as a trusted advisor, you will collaborate closely with clients to maximize their security posture using Cortex XSIAM and Unit 42 expertise. This highly analytical role leverages your deep understanding of detection lifecycles, proactive automation, and threat intelligence to secure enterprise environments. You will architect end-to-end security lifecycles that seamlessly connect data ingestion with high-fidelity detection engineering.
Key Responsibilities:
Own the full lifecycle of custom detections and response automations, deploying them as high-fidelity Cortex XSIAM correlation rules and playbooks through a rigorous engineering process of development, testing, staging, and soft implementation.
Drive the continuous refinement of correlation rules to ensure strict standards for performance, accuracy, and operational relevance.
Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic.
Champion proactive automation by engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand.
Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.
Requirements:
Required Qualifications:
5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms in complex enterprise environments.
Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning.
Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback.
Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions.
Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests.
Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms.
Software development experience with a strong proficiency in Python for security automation and scripting.
Preferred Qualifications:
Previous hands-on experience utilizing and optimizing Cortex XSIAM.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830540
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a Senior SOC Engineer within Unit 42 at Palo Alto Networks, you will drive the creation, validation, and optimization of custom detection rules and automated playbooks across our global customer base. Acting as a trusted advisor, you will collaborate closely with clients to maximize their security posture using Cortex XSIAM and Unit 42 expertise. This highly analytical role leverages your deep understanding of detection lifecycles, proactive automation, and threat intelligence to secure enterprise environments. You will architect end-to-end security lifecycles that seamlessly connect data ingestion with high-fidelity detection engineering.
Key Responsibilities
Own the full lifecycle of custom detections and response automations, deploying them as high-fidelity Cortex XSIAM correlation rules and playbooks through a rigorous engineering process of development, testing, staging, and soft implementation.
Drive the continuous refinement of correlation rules to ensure strict standards for performance, accuracy, and operational relevance.
Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic.
Champion proactive automation by engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand.
Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.
Requirements:
5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms in complex enterprise environments.
Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning.
Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback.
Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions.
Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests.
Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms.
Software development experience with a strong proficiency in Python for security automation and scripting.
Preferred Qualifications
Previous hands-on experience utilizing and optimizing Cortex XSIAM.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830331
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time and Hybrid work
Were growing and looking to hire a Senior Security Operations Engineer who embodies our core values: People First, Customer Obsession, Strive for Excellence, and Integrity.
About the Company:
A global leader in cyber-physical systems (CPS) protection, dedicated to securing the critical infrastructure that keeps the world running. Were a fast-growing, award-winning team where innovation meets purpose-and we want you to help us define the future of cybersecurity.
About the Role:
In this role, you will be a key architect and operator of our modern security posture, focusing heavily on Cloud Access Security Broker (CASB/SSE) architecture, next-generation Endpoint Detection & Response (EDR), and securing the deployment and usage of Artificial Intelligence (AI) and Large Language Models (LLMs) across the enterprise.
As threats evolve, we are proactively embedding AI-driven defense mechanisms while managing the unique threat vectors introduced by enterprise AI adoption. If you thrive at the intersection of data protection, cloud edge security, and cutting-edge automation, this position offers an exceptional opportunity to impact our global defense strategy.
Responsibilities
As a Senior Security Operations Engineer, your responsibilities will include:
Engineering level oversight and support of the operational security environment including endpoint security, cloud/SaaS security, email security, AI security, and network security.
Design, implement, and maintain security solutions for on-premises and cloud environments (e.g., AWS, Azure, GCP).
Architect, configure, and maintain Security Service Edge (SSE), including CASB, Next-Gen SWG, and ZTNA. Establish data loss prevention (DLP) profiles, threat protection policies, and granular access controls across multi-cloud and SaaS environments.
Assist in responses to internal and external compliance audits, penetration tests and vulnerability assessments.
Provide recommendations regarding direction of systems and applications to help secure access, data and assets.
Research and analyze Security Operations Center (SOC) related cyber threats , alerts, and vulnerabilities and ensure our systems are properly protected.
Conduct research on emerging products, services, protocols, and standards relative to the information security arena.
Work with IT Security product vendors and service providers, to evaluate potential security offerings, including product evaluations, pilots and proof of concept installations
Ability to understand and troubleshoot cyber security issues, network configurations, system configurations and upgrades, user authentication, etc..
Ability to work well with other technology areas to deploy security technologies.
Customer service-oriented
Strong work ethic and sense of urgency
Develop and maintain security architecture diagrams, documentation, and standards.
Requirements:
Minimum 5 years experience with Cybersecurity Operations
BA/BS degree in MIS/Computer Science or related degree strongly preferred (or relevant experience)
Relevant Certifications are a plus (e.g. CISSP, CEH, etc).
Fluent in both English and Hebrew
Experience with endpoint security tools, network security tools related to deployment, management, support, and troubleshooting.
Knowledge of IT security regarding ID access, data protection, system\application monitoring, system and application access.
Working Knowledge of Windows, Mac OS, and Linux OS.
Experience with the rollout of new technologies and migrations.
Knowledge of AWS, GCP security and Azure security (deployment, configuration, monitoring, etc).
Strong knowledge in SSE, ZTNA, CASB, DLP, EDR
Experience with AI security policies and tools
Knowledge of security frameworks and standards.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8839311
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are seeking a deeply experienced Security Analyst - Tier 3 for its Security Operations Center (SOC). This role is a senior individual-contributor position, leading challenging investigations, setting the standards the SOC operates by. This role reports to the SOC Manager, under the Detection and Response function within the CISO Office.

Your responsibilities will include:

Lead complex, multi-stage, multi-domain investigations end to end, from scoping through deep technical analysis to a clear determination of impact and root cause.
Serve as the SOC's senior escalation point and the quality gate for investigations across the team.
Support the Incident Response team during confirmed incidents with continued telemetry investigation, scoping, and analytical depth.
Continuously sharpen how the SOC investigates, identifying gaps in methods, runbooks, and tooling through daily casework and turning them into concrete improvements.
Mentor Tier 1 and Tier 2 analysts through case reviews, coaching, and pairing during investigations.
Partner with Security Engineering, Platform Security, Threat Intelligence, SOC Automation, and additional teams to turn what the SOC learns into stronger detection and response across .
Participate in readiness activities - tabletops, post-incident reviews, and purple-team engagements.
Participate in the on-call rotation as the senior point of contact outside business hours.
Requirements:
Around 8-10 years of hands-on experience in security operations or incident response, with a track record of leading complex investigations.
Technical Expertise

Expert-level investigation capability across multiple domains: endpoint, identity, cloud, and network.
Solid understanding of cloud-native environments, including containers, Kubernetes.
Deep practical fluency with EDR, SIEM query languages, and log analysis.
Deep knowledge of Windows and Linux internals, applied to artifact and behavioral analysis.
Fluency in attacker TTPs (MITRE ATT&CK), including the Cloud and Containers matrices.
Strong scripting and data-analysis skills (Python, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
Advanced certifications such as GCIH, GCFA, GNFA, GCFE, or OSCP are an advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818085
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: More than one
Job Type: Full Time
Technical Leadership: Provide authority guidance within the Splunk security domain, exhibiting deep expertise in SIEM, SOAR, and Observability integrations.

Strategic Advisory: Lead sophisticated, multi-functional security projects, acting as a trusted partner to CISO and IT leadership.

Solution Delivery: Lead the strategic planning, compose, and implementation of tailored Splunk security architectures to mitigate risk and maximize technology investments.

AI-Driven Security: Apply sophisticated AI and automation tools to optimize security operations, automate incident response, and improve detection efficacy.

Customer Management: Develop and maintain high-value relationships, ensuring technical alignment with customer security objectives.

Documentation Excellence: Define and implement documentation standards for sophisticated security deployments, ensuring transparency and structure for technical assets.

Authority Support: Build and apply advanced simulation environments; provide expert support for sophisticated security issues and platform challenges.

Mentorship & Growth: Build technical skills across the team, serving as a domain expert on Plan, Design, Implement, and Optimize (PDIO) methodologies.

Product Influence: Synthesize customer feedback to prioritize and advocate for Splunk product and service improvements.

Innovation: Apply expertise in security orchestration, automation, and AI Ops to deliver innovative, scalable customer outcomes.

Intellectual Capital: Lead the creation of digital assets, procedures, and standardized methodologies for Splunk security engagements.

multi-functional Partnership: Collaborate with Product Management to track security trends, influence service offers, and share actionable customer insights.
Requirements:
University degree plus equivalent experience (minimum 6-8 years)

Expert-level certification in Splunk (e.g., Splunk Certified Architect, Splunk Certified Consultant) or equivalent relevant security certification.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8837198
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a skilled Security Automation Engineer to join our SOC Automation team and play a key role in building and scaling automation across Security Operations. This is a hands-on role - you will design, develop, and integrate automation solutions across SIEM, EDR, and other security platforms, contributing to our SOAR capabilities from the ground up.

You will work in a technologically rich environment, integrating with a wide range of security and infrastructure systems across the network - a unique opportunity to build automation at scale in a greenfield setting, with real influence over the architecture and tooling decisions.

We are especially interested in candidates who are curious about leveraging AI and intelligent agents to help evolve next-generation automation and response workflows - and who want to be a driving voice in how we apply those technologies.

Your responsibilities will include:

Automation development

Design and develop automation workflows for incident response and SOC operations
Identify and eliminate manual processes through scalable automation
Build reusable components and maintainable automation patterns
Engineering & integration

Develop integrations using REST APIs, webhooks, and event-driven architectures
Write high-quality, maintainable Python for automation and orchestration
Implement data parsing, enrichment, and transformation across multiple systems
SOAR & platform buildout

Lead or actively contribute to the evaluation, selection, and implementation of SOAR/automation platforms
Design the automation architecture and integration strategy for the team
Build automation capabilities in a greenfield environment - your decisions will shape the foundation
SOC collaboration

Work closely with SOC analysts and incident responders to translate operational needs into automation solutions
Improve end-to-end detection and response workflows through close partnership with the team
AI & innovation

Actively build and evaluate AI/LLM and agent-based workflows applied to security automation
Prototype AI-assisted enrichment, triage, and response solutions and drive them toward production
Requirements:
Minimum 3 years of hands-on experience with SOAR platforms (e.g., Torq, Cortex XSOAR, Splunk SOAR, or similar)
Strong hands-on experience with Python (or a comparable language)
Experience designing or implementing automation frameworks or workflows
Experience building integrations using REST APIs and web services
Experience working with security tools such as SIEM, EDR/XDR, or ticketing systems
Experience with at least one cloud platform (Azure, AWS, or GCP)
Solid understanding of incident response processes and SOC alert-handling workflows
Experience with at least one SIEM platform (Splunk,Sentinel,Qradar,Crowdstrike)
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817744
סגור
שירות זה פתוח ללקוחות VIP בלבד