רובוט
היי א אי
stars

תגידו שלום לתפקיד הבא שלכם

לראשונה בישראל:
המלצות מבוססות AI שישפרו
את הסיכוי שלך למצוא עבודה

SOC/SIEM

מסמך
מילות מפתח בקורות חיים
סימן שאלה
שאלות הכנה לראיון עבודה
עדכון משתמש
מבחני קבלה לתפקיד
שרת
שכר
משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP

חברות מובילות
כל החברות
לימודים
עומדים לרשותכם
מיין לפי: מיין לפי:
הכי חדש
הכי מתאים
הכי קרוב
טוען
סגור
לפי איזה ישוב תרצה שנמיין את התוצאות?
Geo Location Icon

משרות בלוח החם
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
1 ימים
דרושים בקבוצת אשטרום
סוג משרה: משרה מלאה
קבוצת אשטרום מגייסת מיישם.ת תקשורת ואבטחת מידע למטה הקבוצה
אחריות על תפעול, תחזוקה וניהול תשתיות התקשורת ואבטחת המידע בארגון, כולל טיפול בתקלות מורכבות, יישום מדיניות אבטחה והטמעת פתרונות תקשורת ואבטחה.
*משרה זמנית לחצי שעה עם אופציה*

תחומי אחריות:
-  ניהול ותחזוקת תשתיות תקשורת (LAN/WAN) ומוצרי אבטחת מידע
- ניטור, איתור ופתרון תקלות תקשורת ואבטחה
- יישום ועדכון מדיניות אבטחת מידע במערכות הארגוניות
- עבודה מול ספקים ויצרנים לצורך הטמעה, תחזוקה ושיפור מערכות התקשורת והאבטחה

מיקום המשרה- מגדלי LYFE בני ברק
דרישות:
מה חשוב שיהיה לך?
- ניסיון של 3-5 שנים לפחות בתחום התקשורת ואבטחת המידע
- שליטה בפרוטוקולי תקשורת: TCP/IP, DNS, HTTP/HTTPS, VPN
- ניסיון בעבודה עם ציוד תקשורת של Cisco ויצרנים מובילים נוספים
- ידע וניסיון בפרוטוקולי ניתוב וטכנולוגיות: OSPF, BGP, VLAN, STP, HSRP
- ניסיון מעשי בניהול ותפעול Firewalls של Palo Alto
- ניסיון בעבודה עם פתרונות אבטחה כגון IPS/IDS, WAF, NAC, Load Balancer ו-Mail Gateway
- ידע וניסיון בתחום Endpoint Security ופתרונות EDR/XDR המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8844857
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
דרושים בוואן פתרונות טכנולוגיים בע"מ
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה
- אחריות לטיפול מקצועי בחשד לאירועי סייבר
- פיקוח על הפעילות השוטפת של מרכז הניטור וניהול משימות של אנליסטים T1
- מעקב רציף על האירועים / חשד לאירועים
- ניהול משמרות ניטור
- הקצאה וניהול משימות במרכז הניטור
- הפעלת צוותים לניהול תגובה לאירועי סייבר
- ניהול ומעקב פערי ניטור מול הצוותים הרלוונטיים
דרישות:
לפחות שנה כאנליסט ב- SOC
לפחות שנה כמנהל צוות ב- SOC או כמנהל צוות תגובה
ניסיון בהגדרות חוקים במערכות ה- SIEM (יתרון ל-SPLUNK)
יכולת הובלה מקצועית
יכולת ראייה בוגרת
המשרה מיועדת לנשים ולגברים כאחד. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8165491
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בקומפאי טכנולוגיות בע"מ
לארגון מוביל דרוש/ה SOC Analyst עם אוריינטציה טכנולוגית לתפקיד Hands-on בצוות GRC, המשלב עולמות של סייבר, אוטומציה, אינטגרציות וחדשנות טכנולוגית.
התפקיד מתאים לאנליסט/ית SOC שמעוניין/ת להתפתח מעבר לעולמות הניטור והחקירה, ולהשתלב בעבודה טכנולוגית הכוללת פיתוח Scripts ואוטומציות, מיפוי ושיפור תהליכים, Troubleshooting וחיבור בין מערכות. במסגרת התפקיד עובדים מול צוותי סייבר, תשתיות, פיתוח, ענן, ביקורת ויחידות עסקיות בארגון.
דרישות:
- 2 שנות ניסיון ומעלה כ- SOC Analyst / Security Analyst / Cyber analyst או בתפקיד טכנולוגי דומה בעולמות הסייבר ואבטחת המידע- חובה
- ניסיון בכתיבת Scripts ואוטומציות באמצעות Python, PowerShell או שפות מקבילות- חובה
- יכולת להבין תהליך מורכב End-to-End, למפות אותו ולתרגם אותו לפתרון טכנולוגי- חובה
- היכרות עם עולמות GRC, לרבות ניהול סיכונים, בקרות, ציות ודרישות רגולטוריות- יתרון משמעותי
- היכרות עם ISO 27001, NIST ודרישות בתחומי פרטיות ורגולציה- יתרון משמעותי
* משרה זו פונה לנשים וגברים כאחד. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8831779
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בGtech
לחברה מובילה דרוש/ה אנליסט/ית סייבר מנוסה להצטרפות לתפקיד מרכזי בתחום אבטחת המידע והסייבר.

התפקיד כולל אחריות על פעילות הניטור, התחקור והתגובה לאירועי סייבר, עבודה שוטפת מול צוות SOC גלובלי, ניהול חולשות אבטחה והובלת תהליכים לשיפור מערך ההגנה הארגוני.

מה בתפקיד?
ניהול קשר שוטף מול צוות ה- SOC הגלובלי.
תחקור וטיפול באירועי אבטחת מידע וסייבר, כולל Root Cause Analysis.
עבודה עם מערכות SIEM, SOAR, EDR ו-XDR לצורך ניטור, חקירה ותגובה.
ניהול ותיעדוף ממצאי חולשות אבטחה ומעקב אחר תהליכי תיקון.
עבודה מול צוותי IT, תשתיות ופיתוח.
תחזוקה, שיפור וכיול של בקרות אבטחה וצמצום False Positives.
השתתפות בפרויקטים טכנולוגיים והטמעת בקרות אבטחה חדשות.
עבודה מול ממשקים טכנולוגיים ועסקיים בארץ ובחו"ל.
דרישות:
2/3 שנות ניסיון כאנליסט/ית סייבר או SOC Tier 2.
ניסיון בתחקור אירועי סייבר, ניתוח לוגים ותעבורת רשת.
ניסיון בעבודה עם כלי SIEM / SOAR / EDR / XDR.
ידע וניסיון בסביבות Windows, Linux, Active Directory ו-Entra ID.
הבנה טובה בתקשורת, רשתות ופרוטוקולים.
ניסיון בתהליכי Vulnerability Management.
אנגלית ברמה טובה מאוד - עבודה שוטפת מול צוותים גלובליים, כולל השתתפות בפגישות והצגת נושאים מקצועיים.
נכונות לזמינות בעת אירועי סייבר חריגים.

מה אנחנו מחפשים?
יכולת עבודה עצמאית והובלת משימות מקצה לקצה.
חשיבה אנליטית ויכולת תחקור גבוהה.
סדר, ארגון ויכולת מעקב אחר משימות ותהליכים.
יחסי אנוש מעולים ויכולת עבודה מול מגוון ממשקים.
יוזמה, אחריות אישית ורצון להתפתח מקצועית.

חשוב לדעת: מדובר במשרת בוקר, ללא משמרות וללא כוננויות קבועות, זמינות בשעות חריגות נדרשת רק במקרים חריגים של אירועי סייבר. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8841478
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בתבל מטרו בע"מ
חברת תבל מטרו, שמפעילה ומתחזקת את הקו האדום של הרכבת הקלה, מחפשת מפעיל/ת SOC מקצועי/ת להצטרף לצוות אבטחת המידע שלנו ולפעול במרכז הבקרה בזמן אמת.

התפקיד כולל:
ניטור ותחקור מתקדם של אירועי אבטחת מידע במתקן בזמן אמת.
זיהוי, ניתוח וביצוע בדיקות מתמידות של איומי אבטחת מידע חדשים.
תיאום ודיווח עם גורמים רלוונטיים בארגון בהתאם לממצאים.
תחקור אירועי אבטחת מידע ברמת Tier 1 וכתיבת דו"חות מקצועיים.
פיתוח וכתיבת נהלים והוראות עבודה בהתאם לסטנדרטים הארגוניים.
דרישות:
ניסיון בעולמות ה SOC של חצי שנה לפחות - חובה.
זיקה לעולמות ה IT / לימודי אבטחת מידע - חובה
פרואקטיביות בתחום אבטחת מידע - יתרון.
הבנה ברשת ופרוטוקולי תקשורת - יתרון.
הכרות עם מוצרי אבטחת מידע כדוגמת:
SIEM, IPS, EDR, FW (Firewall), AV(Antivirus),NAC יתרון.
נכונות לעבודה במשמרות במשרה חלקית (3 פעמים בשבוע), כוננויות ועבודה בשעות לא שגרתיות ע"פ הצורך. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8788601
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בBDO
מיקום המשרה: תל אביב יפו והרצליה
BDO מגייסת SOC Analyst
ההזדמנות להצטרף לצוות סייבר מקצועי ודינמי בתפקיד משמעותי
עם עבודה על טכנולוגיות מתקדמות מבית Microsoft
מיקום: מרכז, היברידי

מה נדרש לתפקיד:
ניסיון של לפחות שנתיים בעבודה ב- SOC
שליטה במערכות Microsoft Security בדגש על Sentinel
ניסיון בניתוח אירועי אבטחת מידע ותגובה לאירועים
אנגלית ברמה טובה
הסמכות Microsoft - יתרון משמעותי
סיווג ביטחוני בתוקף - יתרון
מתאים למועמדים שמחפשים סביבת עבודה טכנולוגית, מקצועית ומאתגרת עם אפשרות להתפתח ולהעמיק בעולם הסייבר.
דרישות:
מה נדרש לתפקיד:
ניסיון של לפחות שנתיים בעבודה ב- SOC
שליטה במערכות Microsoft Security בדגש על Sentinel
ניסיון בניתוח אירועי אבטחת מידע ותגובה לאירועים
אנגלית ברמה טובה
הסמכות Microsoft - יתרון משמעותי
סיווג ביטחוני בתוקף - יתרון
מתאים למועמדים שמחפשים סביבת עבודה טכנולוגית, מקצועית ומאתגרת עם אפשרות להתפתח ולהעמיק בעולם הסייבר. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8660140
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים בMertens – Malam Team
אנחנו מחפשים סוקר.ת PT חד.ה ויסודי.ת, עם יכולת מעשית לזהות חולשות, לנתח סיכונים ולהנגיש ממצאים מקצועיים לצוותי פיתוח וטכנולוגיה.
בתפקיד זה תבצע.י מבדקי חדירה 100% מהזמן במערכות Web ו-Mobile, בתשתיות, בסביבות AWS ו-Azure ובמערכות AI.
העבודה משלבת מתודולוגיות ותקנים מרכזיים ובהם OWASP, MITRE, NIST ו-PCI-DSS, לצד ביצוע סקרי סיכונים, בדיקות תאימות לרגולציה וכתיבת דוחות מקצועיים.
דרישות:
לפחות 3 שנות ניסיון בביצוע מבדקי חדירה למערכות ולאפליקציות Web ו-Mobile - חובה.
נכונות לעסוק בביצוע מבדקי חדירה לאורך 100% מהתפקיד - חובה.
ידע מעמיק במתודולוגיות תקיפה ובתקנים OWASP, MITRE ו-NIST - חובה.
הבנה בפרוטוקולי TCP/UDP, DNS, IP ו-HTTPS ובטכניקות תקיפת רשת - חובה.
היכרות עם AWS ו-Azure וניסיון בביצוע מבדקי חדירה בסביבות ענן - יתרון.
שליטה ב-PowerShell, ב-Bash, ב- JavaScript וב- Python, או ניסיון בעבודה בארגון פיננסי - יתרון.
זה הזמן להגיש קורות חיים דרך Mertens Malam Team, החברה הגדולה והמובילה במשק לגיוס טכנולוגי, ולבנות ולקדם איתנו את הקריירה הטכנולוגית שלכם. המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8816760
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
2 ימים
דרושים באלעד מערכות
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה ומשמרות
אם אתם חיים ונושמים סייבר ורוצים להיות בחזית הזיהוי והתגובה לאירועי אבטחת מידע - זו ההזדמנות שלכם להצטרף לצוות מקצועי ומשמעותי.

מה בתפקיד?
זיהוי, טיפול ותגובה לאירועי סייבר
ניטור מערכות SIEM וטכנולוגיות אבטחה מתקדמות
זיהוי חריגות בתעבורת רשת, מערכות ומערכות רפואיות
תחקור אירועי אבטחת מידע והצגת ממצאים
ניטור איומים באופן פרואקטיבי
עבודה מול צוותים שונים בארגון ותיעוד אירועים
דרישות:
קורס רלוונטי / תואר / ניסיון צבאי בתחום הסייבר - חובה
לפחות שנה ניסיון בעולמות SOC - חובה
היכרות עם SIEM, EDR, FW, Windows Event Logs - חובה
אנגלית ברמה גבוהה - חובה המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8801292
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
דרושים בקרול יועצים
Job Type: Full Time
Key Responsibilities:

Lead the managed security services operation, ensuring high-quality delivery, performance, and customer satisfaction.
Manage, mentor, and develop SOC and Security Engineering teams.
Build strong relationships with senior customer stakeholders and lead communications during critical incidents and escalations.
Define and continuously improve SLAs, KPIs, workflows, and service standards.
Drive improvements in detection engineering, incident response, and security automation.
Support customer onboarding, renewals, expansions, and technical presales activities.
Identify customer needs and operational insights and translate them into improvements across the organization.
Drive operational excellence and continuous improvement across service delivery.
Requirements:
Proven leadership experience in Managed Security Services, SOC Operations, Security Engineering, or a closely related field.
Experience managing technical teams and complex customer-facing security services.
Strong knowledge of incident response, detection, SIEM technologies, and cloud environments such as AWS and Azure.
Strong communication skills, with the ability to explain complex technical topics to both security professionals and business stakeholders.
Proven track record of improving service quality, operational processes, and team performance.
Strong customer orientation and ability to operate effectively in high-pressure environments.
This position is open to all candidates.
 
Show more...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8842108
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים במלם תים
מיקום המשרה: מספר מקומות
סוג משרה: משרה מלאה
לארגון טכנולוגי מוביל דרוש/ה SOC Engineer / SOC Analyst לתפקיד המשלב עבודת SOC לצד אחריות הנדסית בסביבת אבטחת מידע מתקדמת.
התפקיד כולל עבודה עם Splunk, כתיבת חוקי Detection, טיוב התראות, חיבור והטמעת מקורות לוגים חדשים ובדיקת תקינות האינטגרציות, לצד חקירת אירועי אבטחה, התראות ואסקלציות מעולמות הSOC והDLP.
התפקיד מתאים לאנשי/נשות סייבר בעלי אוריינטציה טכנולוגית גבוהה, חשיבה אנליטית, יכולת למידה מהירה ויוזמה לפתרון בעיות, המעוניינים להשתלב בסביבה דינמית ולהיות חלק מהתפתחות יכולות הסייבר והAI בארגון.

עבודה מתבצעת ביום ראשון במתכונת SOC Analyst בשעות 09:00-18:00 ובימים שני-חמישי במתכונת Engineering.
בנוסף, קיימת כוננות בכל יום החל מ18:00 עד 9:00 לבוקר למחרת ובימי שבת, במסגרתה העובד/ת משמש/ת כFirst Responder לאירועי אבטחה קריטיים.
משרדי החברה נמצאים בתל אביב בבניין שרונה.
דרישות:
- מעל שנתיים ניסיון בעולמות הSOC, SecOps, Incident Response או Security Engineering
- ניסיון מעשי בעבודה עם Splunk, ניסיון בכתיבת חוקי Detection וQueries ובטיוב התראות
- ניסיון בחקירת אירועי סייבר והתראות
- אנגלית ברמה גבוהה לקריאה והבנה
- ניסיון בעבודה עם מקורות לוגים ואינטגרציות לSIEM - יתרון משמעותי
-אוריינטציה לעולמות AI ויכולת להשתמש בכלי AI כחלק מעבודה טכנולוגית - יתרון המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8823791
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
 
משרה בלעדית
2 ימים
דרושים בקבוצת אשטרום
סוג משרה: משרה מלאה
קבוצת אשטרום מגייסת מנהל.ת סייבר והגנת פרטיות

תחומי אחריות:
- הגדרה ובקרה של יישום מדיניות אבטחת מידע בארגון
- ניהול מאגרי המידע מול הרשות
- ניהול סיכונים: הזדהות, הערכה וניהול של סיכוני אבטחת מידע הקשורים לפעילות הארגון
- תכנון ויישום של מדיניות אבטחת מידע, תהליכים וטכנולוגיות מתקדמות להגנה על מערכות המידע של הארגון
- ניהול תקיפות ואירועים: תכנון וניהול של פעולות תגובה לאירועי אבטחה ותקיפות מתמשכות, שיפור היכולת לזיהוי ולתגובה מהירה לאיומים חדשים
- יישום וניהול טכנולוגיות מול מוקד SOC : ניהול פתרונות טכנולוגיים כגון מערכות ניטור, מערכות הגנה מתקדמות וכלי תקשורת מוצפנים
- חינוך והכשרת צוות: הכשרה, הדרכה והפעלת צוותים לצורך התמודדות עם איומי אבטחת מידע ופתרון תקלות אבטחתיות
- עמידות והתמצאות במשמעות: בניית תהליכים ופוליסות למניעה, זיהוי ותגובה להפסקות בטחוניות, כולל תוכניות לשחזור ממצבי אסון (BCP)
דרישות:
מה חשוב שיהיה לך?
- ניסיון באבטחת מידע בענן
- ניסיון של מעל 5 שנים כמנהל סייבר והגנת פרטיות בארגון של מעל 1000 משתמשים
- השכלה בתחום הסייבר/אבטחת מידע המשרה מיועדת לנשים ולגברים כאחד.
 
עוד...
הגשת מועמדות
עדכון קורות החיים לפני שליחה
8847809
סגור
שירות זה פתוח ללקוחות VIP בלבד
לוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a MXDR Analyst to join the team of cybersecurity analysts monitoring services 24/7. The role includes development of detection analyses, triage of alerts, investigation of security incidents, proactive threat hunting and enhancement of sensors and overall visibility status.
The suitable candidate should be a team player with previous experience in SOC, SecOps or security monitoring, independent, and with a can-do attitude.
Responsibilities:
Working across all areas of Sygnias SOC, including continuous monitoring and analysis, threat hunting, security compliance, security event auditing and analysis, rule development and tuning, and forensics.
Solving security incidents in accordance with defined service level agreements and objectives.
Prioritizing and differentiating between potential incidents and false alarms.
Addressing clients enquiries via phone, email, and live chat.
Working side-by-side with customers, providing insightful incident reports.
Working closely with peers and higher-tier analysts to ensure that your analysis work meets quality standards.
Identifying opportunities for improvement and automation within the MXDR Operation Lead, and leading efforts to operationalize ideas.
Identifying and offering solutions to gaps in current capabilities, visibility, and security posture.
Correlating information from disparate sources to develop novel detection methods.
Requirements:
At least one year of experience in a SOC/MDR or Managed EDR service, including night and weekend shifts.
Strong analytical thinker, problem-solving mindset, and ability to succeed in a dynamic environment.
Independent, bright and positive analyst who strives for excellence.
Proficiency and experience with scripting (Python).
Strong capabilities in drafting cyber security reports for clients.
Basic understanding of the lifecycle of advanced security threats, attack vectors, and methods of exploitation.
Hands-on experience working with SIEM technologies. (e.g. Splunk, QRadar, ArcSight, Exabeam, etc.)
Familiarity with common data and log sources for monitoring, detection and analysis (e.g., Event Logs, firewall, EDR).
Strong technical understanding of network fundamentals, common internet protocols, and system and security controls.
Basic knowledge of host-based forensics and OS artifacts.
Familiarity with cloud infrastructure, web application and servers - an advantage.
Fluent English (written, spoken) - a must. Another language - an advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8845600
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: More than one
Job Type: Full Time
Technical Leadership: Provide authority guidance within the Splunk security domain, exhibiting deep expertise in SIEM, SOAR, and Observability integrations.

Strategic Advisory: Lead sophisticated, multi-functional security projects, acting as a trusted partner to CISO and IT leadership.

Solution Delivery: Lead the strategic planning, compose, and implementation of tailored Splunk security architectures to mitigate risk and maximize technology investments.

AI-Driven Security: Apply sophisticated AI and automation tools to optimize security operations, automate incident response, and improve detection efficacy.

Customer Management: Develop and maintain high-value relationships, ensuring technical alignment with customer security objectives.

Documentation Excellence: Define and implement documentation standards for sophisticated security deployments, ensuring transparency and structure for technical assets.

Authority Support: Build and apply advanced simulation environments; provide expert support for sophisticated security issues and platform challenges.

Mentorship & Growth: Build technical skills across the team, serving as a domain expert on Plan, Design, Implement, and Optimize (PDIO) methodologies.

Product Influence: Synthesize customer feedback to prioritize and advocate for Splunk product and service improvements.

Innovation: Apply expertise in security orchestration, automation, and AI Ops to deliver innovative, scalable customer outcomes.

Intellectual Capital: Lead the creation of digital assets, procedures, and standardized methodologies for Splunk security engagements.

multi-functional Partnership: Collaborate with Product Management to track security trends, influence service offers, and share actionable customer insights.
Requirements:
University degree plus equivalent experience (minimum 6-8 years)

Expert-level certification in Splunk (e.g., Splunk Certified Architect, Splunk Certified Consultant) or equivalent relevant security certification.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8837198
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
23/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Sr MSIAM SOC Engineer (Unit 42)
Job Summary
As a Senior SOC Engineer within Unit 42, you will drive the creation, validation, and optimization of custom detection rules and automated playbooks across our global customer base. Acting as a trusted advisor, you will collaborate closely with clients to maximize their security posture using Cortex XSIAM and Unit 42 expertise. This highly analytical role leverages your deep understanding of detection lifecycles, proactive automation, and threat intelligence to secure enterprise environments. You will architect end-to-end security lifecycles that seamlessly connect data ingestion with high-fidelity detection engineering.
Key Responsibilities:
Own the full lifecycle of custom detections and response automations, deploying them as high-fidelity Cortex XSIAM correlation rules and playbooks through a rigorous engineering process of development, testing, staging, and soft implementation.
Drive the continuous refinement of correlation rules to ensure strict standards for performance, accuracy, and operational relevance.
Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic.
Champion proactive automation by engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand.
Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.
Requirements:
Required Qualifications:
5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms in complex enterprise environments.
Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning.
Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback.
Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions.
Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests.
Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms.
Software development experience with a strong proficiency in Python for security automation and scripting.
Preferred Qualifications:
Previous hands-on experience utilizing and optimizing Cortex XSIAM.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830540
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
As a Senior SOC Engineer within Unit 42 at Palo Alto Networks, you will drive the creation, validation, and optimization of custom detection rules and automated playbooks across our global customer base. Acting as a trusted advisor, you will collaborate closely with clients to maximize their security posture using Cortex XSIAM and Unit 42 expertise. This highly analytical role leverages your deep understanding of detection lifecycles, proactive automation, and threat intelligence to secure enterprise environments. You will architect end-to-end security lifecycles that seamlessly connect data ingestion with high-fidelity detection engineering.
Key Responsibilities
Own the full lifecycle of custom detections and response automations, deploying them as high-fidelity Cortex XSIAM correlation rules and playbooks through a rigorous engineering process of development, testing, staging, and soft implementation.
Drive the continuous refinement of correlation rules to ensure strict standards for performance, accuracy, and operational relevance.
Translate Unit 42 threat intelligence research and emerging adversary TTPs into actionable, robust detection logic.
Champion proactive automation by engineering sophisticated playbooks to resolve emerging security challenges and optimize operational workflows ahead of demand.
Architect the end-to-end security lifecycle within Cortex XSIAM, seamlessly connecting data ingestion, high-fidelity detection engineering, and sophisticated response automation.
Requirements:
5+ years of hands-on experience in a Senior SOC, Detection Engineering, or Security Architecture role utilizing SIEMs, firewalls, EDR, sandboxes, and SOAR platforms in complex enterprise environments.
Proven mastery of the Detection Engineering lifecycle, including experience with rule testing frameworks, soft-deployment strategies, and continuous tuning.
Demonstrated experience reviewing and QA-ing detection logic written by others, with the ability to provide constructive optimization feedback.
Exceptional consultative and communication skills, with the confidence to guide enterprise customers through complex architectural and workflow decisions.
Proactive engineering mindset with a track record of designing complex automation playbooks (Cortex XSOAR or similar) based on anticipated threat vectors, not just reactive requests.
Strong background in incident response, threat hunting, and translating threat intelligence into actionable defense mechanisms.
Software development experience with a strong proficiency in Python for security automation and scripting.
Preferred Qualifications
Previous hands-on experience utilizing and optimizing Cortex XSIAM.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8830331
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We are looking for a skilled Security Automation Engineer to join our SOC Automation team and play a key role in building and scaling automation across Security Operations. This is a hands-on role - you will design, develop, and integrate automation solutions across SIEM, EDR, and other security platforms, contributing to our SOAR capabilities from the ground up.

You will work in a technologically rich environment, integrating with a wide range of security and infrastructure systems across the network - a unique opportunity to build automation at scale in a greenfield setting, with real influence over the architecture and tooling decisions.

We are especially interested in candidates who are curious about leveraging AI and intelligent agents to help evolve next-generation automation and response workflows - and who want to be a driving voice in how we apply those technologies.

Your responsibilities will include:

Automation development

Design and develop automation workflows for incident response and SOC operations
Identify and eliminate manual processes through scalable automation
Build reusable components and maintainable automation patterns
Engineering & integration

Develop integrations using REST APIs, webhooks, and event-driven architectures
Write high-quality, maintainable Python for automation and orchestration
Implement data parsing, enrichment, and transformation across multiple systems
SOAR & platform buildout

Lead or actively contribute to the evaluation, selection, and implementation of SOAR/automation platforms
Design the automation architecture and integration strategy for the team
Build automation capabilities in a greenfield environment - your decisions will shape the foundation
SOC collaboration

Work closely with SOC analysts and incident responders to translate operational needs into automation solutions
Improve end-to-end detection and response workflows through close partnership with the team
AI & innovation

Actively build and evaluate AI/LLM and agent-based workflows applied to security automation
Prototype AI-assisted enrichment, triage, and response solutions and drive them toward production
Requirements:
Minimum 3 years of hands-on experience with SOAR platforms (e.g., Torq, Cortex XSOAR, Splunk SOAR, or similar)
Strong hands-on experience with Python (or a comparable language)
Experience designing or implementing automation frameworks or workflows
Experience building integrations using REST APIs and web services
Experience working with security tools such as SIEM, EDR/XDR, or ticketing systems
Experience with at least one cloud platform (Azure, AWS, or GCP)
Solid understanding of incident response processes and SOC alert-handling workflows
Experience with at least one SIEM platform (Splunk,Sentinel,Qradar,Crowdstrike)
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817744
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות שנמחקו
ישנן -18 משרות במרכז אשר לא צויינה בעבורן עיר הצג אותן >