דרושים » אבטחת מידע וסייבר » Security Analyst - Tier 3

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are seeking a deeply experienced Security Analyst - Tier 3 for its Security Operations Center (SOC). This role is a senior individual-contributor position, leading challenging investigations, setting the standards the SOC operates by. This role reports to the SOC Manager, under the Detection and Response function within the CISO Office.

Your responsibilities will include:

Lead complex, multi-stage, multi-domain investigations end to end, from scoping through deep technical analysis to a clear determination of impact and root cause.
Serve as the SOC's senior escalation point and the quality gate for investigations across the team.
Support the Incident Response team during confirmed incidents with continued telemetry investigation, scoping, and analytical depth.
Continuously sharpen how the SOC investigates, identifying gaps in methods, runbooks, and tooling through daily casework and turning them into concrete improvements.
Mentor Tier 1 and Tier 2 analysts through case reviews, coaching, and pairing during investigations.
Partner with Security Engineering, Platform Security, Threat Intelligence, SOC Automation, and additional teams to turn what the SOC learns into stronger detection and response across .
Participate in readiness activities - tabletops, post-incident reviews, and purple-team engagements.
Participate in the on-call rotation as the senior point of contact outside business hours.
Requirements:
Around 8-10 years of hands-on experience in security operations or incident response, with a track record of leading complex investigations.
Technical Expertise

Expert-level investigation capability across multiple domains: endpoint, identity, cloud, and network.
Solid understanding of cloud-native environments, including containers, Kubernetes.
Deep practical fluency with EDR, SIEM query languages, and log analysis.
Deep knowledge of Windows and Linux internals, applied to artifact and behavioral analysis.
Fluency in attacker TTPs (MITRE ATT&CK), including the Cloud and Containers matrices.
Strong scripting and data-analysis skills (Python, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
Advanced certifications such as GCIH, GCFA, GNFA, GCFE, or OSCP are an advantage.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818085
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are seeking an experienced Security Analyst - Tier 2 for its Security Operations Center (SOC). This role is a hands-on position built for depth, serving as the investigative core of the SOC, focused on evidence and grounded conclusions. This role reports to the SOC Manager, under the Detection and Response function within the CISO Office.

You are welcome to work in our offices in Tel Aviv, Israel.

Key Responsibilities
Investigate escalated security alerts across endpoint, identity, cloud, email, and network layers.
Determine scope, impact, and root cause using EDR, SIEM, and supporting telemetry.
Escalate suspected incidents to the Incident Response team and complex investigations to Tier 3.
Provide structured feedback to relevant stakeholders on detection or prevention quality, false-positive patterns, and coverage gaps discovered during investigations.
Contribute to and refine SOC runbooks, triage guides, and investigation procedures.
Review Tier 1 escalations, coach on handoff quality, and act as the analytical reference during triage.
Document investigations to a standard that supports handoff, quality review, and lessons learned.
Participate in the on-call rotation, acting as the investigative point of contact outside business hours.
Requirements:
Around 5-7 years of hands-on security operations experience, with proven depth in alert investigation.
Experience taking investigations to a clear verdict, including confirmed incidents.
Technical Expertise

Strong working command of EDR platforms and SIEM-based investigation, including writing and adapting queries independently.
Solid understanding of attacker techniques, with the ability to map findings to MITRE ATT&CK in analysis and reporting.
Investigation capability across at least two of: endpoint, identity, cloud, email, or network domains.
Windows and Linux internals at the depth required for log and artifact analysis: processes, authentication flows, and persistence mechanisms.
Solid networking fundamentals: TCP/IP, DNS, HTTP/S, and the ability to interpret network telemetry.
Scripting ability (Python or similar) for analysis at scale, and familiarity with SOAR platforms.
Certifications such as BTL2, OSDA, or CDSA are an advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818090
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a hands-on role that balances deep technical work along with building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by.

Youre welcome to work in our offices in Tel Aviv, Israel.

Your responsibilities will include:

Build and lead global DFIR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders.
Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases.
Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction.
Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements.
Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR.
Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA).
Raise the teams technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness.
Requirements:
7+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise).
Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2).
Technical Expertise

Deep knowledge of Windows and Linux internals, with proven disk and memory forensics capability.
Strong cloud-native platform security: containers and Kubernetes, CI/CD, secrets management, cloud control planes, and IAM attack paths.
Fluency in attacker TTPs (MITRE ATT&CK, including the Cloud and Containers matrices), and hands-on experience with EDR, SIEM, and forensic tooling (e.g., Velociraptor, Volatility, X-Ways/EnCase).
Strong scripting and data-analysis skills (Python, PowerShell, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818167
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
05/08/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
As a SecOps Lead , you will own the core of the security operations function: detection, response, automation, and the processes that connect them. You will guide incident response from first alert through post-mortem, keeping efforts structured and stakeholders informed along the way. You will shape how the team detects, triages, and resolves, and communicate that work clearly to leadership, engineering, and customers.

This is a hands-on role with broad ownership. You should be comfortable writing a detection rule, coordinating a live incident, and walking stakeholders through a post-incident review.

Key Responsibilities

Lead Incident Response: Own the end-to-end incident response lifecycle across infrastructure and enterprise browser platform, driving investigations, coordinating responders, and ensuring timely resolution and post-incident improvements.
Own the IR Framework: Build, maintain, and continuously improve incident response processes, including runbooks, severity definitions, escalation paths, on-call procedures, and communication standards.
Drive Detection Engineering: Design, implement, and continuously improve high-fidelity detections across SIEM, EDR, cloud, and endpoint security platforms, closing visibility gaps and strengthening detection coverage.
Automate Security Operations: Build automation and AI-driven workflows that streamline triage, investigation, enrichment, and response, reducing manual effort and improving operational efficiency.
Threat Hunting & Research: Proactively hunt for threats, leverage threat intelligence, and identify emerging attack techniques relevant to modern enterprise environments.
Own Security Operations: Serve as the technical owner for Security Operations within Product Security, driving strategy, setting best practices, and continuously improving detection and response capabilities.
Partner Across Engineering: Collaborate closely with Engineering, IT, Infrastructure, and Compliance teams to embed security into new services, infrastructure changes, FedRAMP initiatives, and customer-facing security requirements.
Communicate During Incidents: Provide clear, timely communication throughout incident response, keeping technical teams, leadership, and stakeholders aligned on impact, progress, risks, and next steps.
Requirements:
5+ years of hands-on experience in Security Operations, Incident Response, or Detection Engineering.
Proven experience leading end-to-end incident response for high-severity security incidents in cloud or enterprise environments.
Strong understanding of detection engineering, threat hunting, and modern security operations, with hands-on experience using SIEM, EDR, and cloud security platforms.
Experience building and improving incident response processes, including runbooks, severity frameworks, escalation paths, and post-incident reviews.
Hands-on experience automating security operations using SOAR platforms and AI-powered workflows (Torq, Tines, or similar).
Solid understanding of AWS security fundamentals, including IAM, CloudTrail, and containerized environments (EKS is an advantage).
Strong knowledge of modern attack techniques, threat intelligence, detection methodologies, and investigation best practices.
Excellent written and verbal communication skills, with the ability to communicate effectively during incidents and present findings to both technical and non-technical stakeholders.
Experience collaborating across Engineering, Infrastructure, IT, and Compliance teams to improve security posture.
Experience mentoring engineers or leading cross-functional security initiatives is an advantage.
Familiarity with SOC2, FedRAMP, or other regulated compliance frameworks is a plus.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8769437
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an Incident Response Engineer to join the IR team. This technical role focuses on active investigation, threat mitigation, and the continuous improvement of the security organizations posture through detection engineering and automation development.
The successful candidate will be responsible for the full lifecycle of security incidents, from initial triage to recovery. Beyond reactive response, this role involves tuning SIEM correlation rules and developing SOAR workflows to increase operational efficiency.
What Youll Be Doing:
Incident Management: Execute the IR lifecycle (Triage, Containment, Eradication, Recovery) for complex security events.
Technical Investigation: Perform root cause analysis and forensic examination across Windows, Mac, and Linux environments.
Detection & Tuning: Collaborate with the IR team to create, test, and tune SIEM rules and dashboards to reduce false positives and improve visibility.
Automation Engineering: Build and refine SOAR playbooks and automated response actions to streamline repetitive investigation tasks.
Cloud Security: Monitor and mitigate cloud-native threats across Azure, AWS, and GCP environments.
Requirements:
Experience as a SecOps/IR Analyst or Engineer with a heavy focus on active investigation.
Deep understanding of the Incident Response lifecycle (Triage, Containment, Eradication, Recovery).
Hands-on experience handling and managing security alerts, performing root cause analysis, and leading investigations.
Experience working across cloud providers (Azure, AWS, GCP) to identify and mitigate cloud-native threats.
Strong knowledge of operating systems (Mac, Windows, Linux) and their respective artifacts.
Proficiency with Splunk or other SIEM platforms for log analysis and threat hunting.
Experience with XSOAR or other security automation tools from an end-user/analyst perspective.
Strong knowledge of security technologies, including EDR, Mail Relay, Vulnerability Scanning, Secure Access, and MDM.
Scripting experience with Python or Bash to assist in data parsing and investigation tasks.
Nice to Have:
Detection Engineering: Ability to build and improve SIEM rules, correlations, and dashboards.
Automation Development: Experience developing new SOAR workflows, automated actions, and response playbooks.
Technical Literacy: Familiarity with REST APIs and Regex for advanced querying and tool integration.
Container Security: Familiarity and experience with K8S (Kubernetes).
Consultative Skills: Ability to guide best practices in Cloud Security and SIEM operations.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8794710
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
Location: Tel Aviv-Yafo
Job Type: Full Time
We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Cloud - and lead a small, growing team of analysts and engineers.

This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy.

What youll do
Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.

Architect and operate detection coverage across our cloud and bare-metal environments

Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks.

Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure

Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents.

Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.

Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.

Build and maintain Security Incident Response program: people, processes, tools.

Build tools, runbooks, and on-call processes that scale as the company grows.
Requirements:
6+ years in security operations, detection engineering, or incident response - with at least 1-2 years leading or mentoring a team.

Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).

Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.

Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).

Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.

Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.

Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase. Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818174
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a Lead Detection Engineer.This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline.

Youre welcome to work in our offices in Tel Aviv, Israel

Your responsibilities will include:

Detection coverage strategy across endpoint, identity, cloud, and infrastructure - how it's measured, prioritized, and continuously improved.
Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic.
Architecture connecting detections to enrichment, triage, and automated response workflows.
Technical standards for how detections are designed, tested, documented, deployed, and retired.
Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops.
Design and build high-fidelity behavioral detections across SIEM and EDR platforms.
Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.
Validate detections through threat simulations and continuous detection testing.
Partner with SOC analysts to close the feedback loop between detections and real investigations.
Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership.
Make architectural decisions that scale as the team and organization grow.
Requirements:
Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role - with demonstrated depth, not just breadth.
Experience owning or leading detection engineering work as a senior technical contributor
Strong understanding of attacker tradecraft and adversary behavior.
Hands-on experience with at least one enterprise SIEM and EDR platform - Splunk, Microsoft Sentinel, CrowdStrike, or equivalent.
Cloud security depth across Azure, AWS, or GCP.
Strong query development skills in SPL, KQL, Sigma, or similar.
Strong scripting skills (python, powershell etc)
Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows.
Experience using MITRE ATT&CK to design, validate, and measure detection coverage  
Ability to make and defend technical decisions and establish standards others adopt.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818112
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
e are currently seeking a dynamic Incident Response Analyst to contribute to the success of our rapidly growing business.



As an Incident Response Analyst, you will:

Investigate and respond to workspace security incidents across email, browser security and perimeter security domains.
Handle investigation requests submitted by customers
Perform targeted phishing analysis and investigation of new attack campaigns
Conduct threat hunting based on attack patterns, behaviors, and indicators
Build and improve detections based on new attack types, tactics, companies and trends
Collaborate with development and research teams to provide incident-driven insights, and develop new detection engines for identifying previously unknown attacks
Write professional blog posts based on incident investigations and attack trends, contributing to the companys research-driven content and public visibility
Work in rotating shifts as part of a 24/7 operation (including nights, weekends, and holidays)
Requirements:
At least 3 years of experience in an Incident Response or Security Operation roles
Strong understanding of attack vectors, including Phishing, BEC, Email spoofing and impersonation techniques, Malware, ATO and more
Knowledge of email protocols and security concepts: SMTP, SPF/DKIM/DMARC, headers, authentication methods
Strong querying skills using SQL, SPL, KQL or AQL
Good knowledge with Static & Dynamic techniques
Familiarity with and understanding of code and scripting languages such as Python, JavaScript, Visual Basic, or similar - with the ability to read, interpret, and analyze potentially malicious scripts
Excellent written and verbal communication in English
Team player with a proactive, ownership-driven approach
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8797736
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/08/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
Required Security Operations & Automation
About Your Day-to-Day:
As a Security Operations & Automation, you'll be the hands-on architect of how we detect, investigates, and responds to threats - built around AI agents and deep tooling integrations, not manual triage. You'll own incident response across corporate systems, workstations, and identity, unify alerts from every source - including cloud-originated signals that need a response - into a single SOAR/XDR fabric, and deploy AI agents to handle first-line investigation and response.
You'll work closely with IT and the Cloud Security team - taking the lead on investigation, triage, and response while they own the underlying cloud and SDLC architecture - and turn complex security signals into structured, AI-assisted, largely autonomous outcomes - fighting fire with fire.
Responsibilities:
Architect and own our AI-driven detection and response stack, integrating SIEM, XDR, SOAR, EDR, and IAM into a single automated fabric rather than siloed tools.
Deploy and tune AI agents to handle first-line alert triage, enrichment, and investigation, with humans engaged only for true edge cases - manual L1 triage is the exception, not the default.
Build SOAR playbooks and integrations across the security and IT toolchain (endpoint, identity, ticketing, chat) so detection, enrichment, and remediation run automatically end to end - regardless of which system or platform an alert originates from.
Own the alert pipeline as a whole: unify signals from EDR, IAM, and other sources - including cloud and SaaS alerts surfaced by the Cloud Security team - into one triage and response workflow, so nothing falls through the cracks between tools.
Evaluate and integrate best-of-breed, AI-native security tools - SIEM, XDR, SOAR, EDR, email security, AI guardrails, ZTNA, and others - wiring each into the unified detection and response fabric rather than running them as siloed point solutions. Hands-on tool integration (APIs, connectors, log and telemetry ingestion) is a core skill for this role, not an occasional task.
Drive vulnerability and patch management across corporate systems and endpoints, automating prioritization and remediation workflows and coordinating with IT against strict SLAs.
Build and tune detection rules specific to our environment, treating detection as code and feeding AI-driven correlation across the XDR layer.
Maintain security dashboards (MTTD/MTTR, automation rate, % of alerts resolved without human touch) and report on how automation is cutting noise and response time.
דרישות:
5+ years of experience in security operations, SecOps, or security engineering roles.
Hands-on experience operating EDR/XDR. SOAR/XSOAR, SIEM platforms and cloud security services (IAM, CSPM, SSPM).
Experience building automations and playbooks using SOAR platforms or scripting (Python, Bash).
Strong incident response skills, including triaging alerts and conducting root cause analysis.
Hybrid position based in our Tel Aviv office.
Excellent written and verbal English skills
Personal Attributes & Mindset:
High ownership mentality: You take responsibility for the security stack and follow through on every alert.
Strong sense of structure: You can manage vulnerability SLAs and maintain precise security policies.
Comfortable with ambiguity: You can take a vague threat and turn it into a clear detection rule or automated playbook.
Collaborative by nature: You enjoy working as a partner to R&D to solve security challenges without slowing down development.
Curious and self-driven: You are motivated to stay ahead of emerging threats and continuously improve Port's defenses.
Nice to Have:
Relevant certifications: CompTIA Security+, GSEC, CySA+, or AWS Security Specialty.
Deep understanding of the SDLC and experience embedding security tools (SAST, SCA) into CI/CD pipelines.
Experience with CNAPP/CSPM or code security platforms.
Familiarity with compliance frameworks (SOC 2, ISO המשרה מיועדת לנשים ולגברים כאחד.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8775548
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
1 ימים
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking an experienced Security Engineering Lead to join the Cyber Security organization, reporting to the Corporate Security Engineering Manager under the CISO.

This is a senior technical lead role focusing on engineering and execution without direct people management responsibilities. This role combines hands-on security engineering to deliver end-to-end protection across corporate, cloud, and SaaS environments. You will not only define strategy and standards - you will build, configure, tune, and operate the technical controls that enforce them.

You will be responsible for implementing, managing, integrating and maintaining security systems across the organizations IT landscape. The role requires deep technical proficiency in multiple platforms and tools, combined with the ability to collaborate with Security, IT, Engineering, Product, GRC and other business units to reduce risks and embed strong security practices.

Your responsibilities will include:

Engineer, deploy, and continuously tune systems such as Identity & Access, Threat Detection & Response, Cloud & Network Security.
Define, enforce and maintain security policies & configurations across endpoints, email, SaaS, network, and cloud platforms.
Design and implement solutions to gain continuous visibility into systems and processes, sensitive data, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
Monitor, triage, and investigate security alerts and risks, collaborating with Security, IT, Network teams on escalation and remediation.
Conduct risk assessments and identify gaps in security controls across systems, pipelines, and business processes.
Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to security and privacy.
Collaborate with Engineering, IT, Product, and GRC teams to embed security controls into systems, and workflows.
Maintain documentation, runbooks, and guidelines for operations, security posture management, and security practices.
Requirements:
6+ years of experience in IT security, with a strong focus on System, Network, Information, Cyber. With at least 3 years in a Security Engineering role.
Proven hands-on engineering experience with enterprise security platforms - including policy authoring, tuning, incident workflow configuration, and platform administration.
Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
Strong understanding of identity and access management and data access governance principles.
Experience working cross-functionally with Security, IT, Engineering, Product, and GRC teams.
Strong analytical mindset with the ability to communicate security risks clearly to technical and non-technical stakeholders.
Excellent written and verbal communication skills in English.
Proactive, detail-oriented, and ownership-driven.
Hand-on experience with multiple technologies such as: XDR (Extended Detection & Response), SWG (Secure Web Gateway), DLP (Data Leakage Prevention), Email Security, Network security (Firewalls, NAC, NDR), IGA (Identity Governance & Administration), CASB (Cloud Access Security Broker), PAM (Privileged Access Management), EPM (Endpoint Privilege Management), BAS (Breach & Attack Simulation), Vulnerability Scanners, SIEM (Security Information & Event Management), SOAR (Security Orchestration, Automation & Response), CTI (Cyber Threat Intelligence), Patch Management, TPRM (Third-Party Risk Management), EASM (External Attack Surface Management).
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817717
סגור
שירות זה פתוח ללקוחות VIP בלבד