דרושים » אבטחת מידע וסייבר » Incident Response Manager (IRM)

משרות על המפה
 
בדיקת קורות חיים
VIP
הפוך ללקוח VIP
רגע, משהו חסר!
נשאר לך להשלים רק עוד פרט אחד:
 
שירות זה פתוח ללקוחות VIP בלבד
AllJObs VIP
כל החברות >
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for an experienced Incident Response Manager (IRM) to lead incident response services for clients across EMEA. This is a senior management role within Incident Response department and an integral part of the companys global IR service delivery organization.
The role combines technical leadership, crisis management, client engagement, and cross-functional project leadership. Following a substantial and successful tenure in the position, the IRM will have opportunities for continued professional growth and advancement across a variety of roles within .
Main Responsibilities:
Lead incident response and threat-hunting engagements involving large-scale and sophisticated cyberattacks, with the objective of containing, mitigating, and defeating real-world threats.
Lead dynamic, cross-functional teams of cybersecurity researchers, forensic experts, and other specialists assembled according to the specific needs of each engagement. Team members do not report directly to the IRM outside the scope of the project.
Maintain clear, concise, and timely internal communication, providing regular updates to technical, financial, legal, business, and executive stakeholders within .
Lead client-facing communication throughout investigations and work closely with clients IT, security, legal, and executive teams, as well as relevant external stakeholders.
Serve as a trusted advisor to clients during high-pressure and business-critical situations.
Collaborate with global teams to ensure consistent, high-quality incident response delivery across regions.
Strengthen client relationships, identify relevant business opportunities, and support the introduction of additional services.
Contribute to broader strategic objectives through professional publications, thought leadership, marketing initiatives, and business development activities.
Design, develop, and continuously improve internal incident response methodologies, processes, and capabilities.
Requirements:
At least 5 years of experience leading teams through direct management, project-based leadership, matrix management, or a combination of these models.
Proven ability to lead diverse groups of specialists who do not report directly to the role, while maintaining alignment, accountability, and effective execution.
A decisive, intellectually sharp, and positive leader with a strong commitment to excellence.
Calm and thoughtful leadership style, with the ability to make sound decisions in highly dynamic and fast-paced environments.
Strong crisis-management capabilities, including the ability to objectively assess situations, manage complex stakeholder relationships, and continuously evaluate actions and priorities.
Exceptional written, verbal, and presentation skills in English, with the ability to explain complex technical matters clearly and confidently to both technical professionals and executive leadership. Additional languages are an advantage.
In-depth understanding of advanced cyber threats, attack vectors, adversary techniques, and exploitation methods.
Strong technical knowledge of network fundamentals, common internet protocols, operating systems, and security controls.
Familiarity with the tools and techniques used in security event analysis, incident response, digital forensics, malware analysis, and broader security operations.
Ability to work in a project-based model involving urgent and unplanned engagements, including availability outside regular working hours and on weekends when required.
Willingness to travel internationally as needed.
Previous experience in strategy or cybersecurity consulting is an advantage.
An academic degree in a technological or scientific discipline is an advantage.
This position is open to all candidates.
 
Hide
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8845796
סגור
שירות זה פתוח ללקוחות VIP בלבד
משרות דומות שיכולות לעניין אותך
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for highly capable Incident Response Expert. The Incident Response Expert role includes conducting in-depth forensic analysis, investigation and response to real-world cyber threats. A significant part of our investigations is performed onsite at the client location, in collaboration with the clients IT and security teams.
Main Responsibilities:
Participate in forensic and incident response investigations, including large scale sophisticated attacks, conduct log analysis, host and network-based forensics and malware analysis.
Participate in threat hunting: proactively hunt for targeted attacks and new emerging threats in clients networks; as well as security assessments and simulations.
Identify indicators of compromise (IOCs) and tools, tactics, and procedures (TTPs) to help ascertain whether and how breaches have occurred.
Utilize and develop tools and methodologies to improve Sygnias existing investigative and hunting technological stack.
Collaborate with IT and Security teams during investigations.
Generate and present a comprehensive and professional report of findings from investigations.
Requirements:
At least 3 years of a relevant experience (from military service and/or industry).
Bright, curious and determined team player, who strive for excellency.
Problem solver, in-depth thinker with growth mindset.
Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors and variant methods of exploration.
Deep technical understanding of network fundamentals and common Internet protocols.
Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix and MacOS), including host-based forensics and experience with analyzing OS artifacts.
Fluency with one or more scripting language (i.e. Python).
Multidisciplinary knowledge and competencies, such as:
Hands-on experience in data analysis (preferably network traffic or log analysis) in relevant data analysis and data science platforms (Jupyter, Splunk, pandas, SQL).
Familiarity with cloud infrastructure, web application and servers, android and iOS mobile platforms.
Experience with malware analysis and reverse engineering.
Familiarity with enterprise SIEM platforms (e.g. Splunk, QR.adar, ArcSight).
Excellent communication and interpersonal skills. Fluent English, including the ability to document and explain technical information in a concise, understandable manner.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8845787
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a hands-on role that balances deep technical work along with building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by.

Youre welcome to work in our offices in Tel Aviv, Israel.

Your responsibilities will include:

Build and lead global DFIR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders.
Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases.
Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction.
Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements.
Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR.
Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA).
Raise the teams technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness.
Requirements:
7+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise).
Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2).
Technical Expertise

Deep knowledge of Windows and Linux internals, with proven disk and memory forensics capability.
Strong cloud-native platform security: containers and Kubernetes, CI/CD, secrets management, cloud control planes, and IAM attack paths.
Fluency in attacker TTPs (MITRE ATT&CK, including the Cloud and Containers matrices), and hands-on experience with EDR, SIEM, and forensic tooling (e.g., Velociraptor, Volatility, X-Ways/EnCase).
Strong scripting and data-analysis skills (Python, PowerShell, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818167
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOCs local anchor - the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate.

Responsibilities

Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats.
Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs.
Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps.
SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness.
Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines.
Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology.
Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements:
3-5 years of hands-on experience in a SOC or cybersecurity operations role.
Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic).
Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon).
Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure.
Excellent communication skills and the ability to work effectively with distributed teams across time zones.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8820142
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
Location: Tel Aviv-Yafo
Job Type: Full Time
We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Cloud - and lead a small, growing team of analysts and engineers.

This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy.

What youll do
Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.

Architect and operate detection coverage across our cloud and bare-metal environments

Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks.

Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure

Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents.

Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.

Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.

Build and maintain Security Incident Response program: people, processes, tools.

Build tools, runbooks, and on-call processes that scale as the company grows.
Requirements:
6+ years in security operations, detection engineering, or incident response - with at least 1-2 years leading or mentoring a team.

Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).

Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.

Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).

Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.

Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.

Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase. Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818174
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
Were looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.
As a DFIR Analyst, you will be tasked with delivering rapid, expert breach response for global enterprises facing active cyber threats as part of Digital Forensics and Incident Response (DFIR) team, which operates 24x7x365 on a follow-the-sun model. Working under the direction of an investigation's Technical Lead and Engagement Manager, you will execute hands-on forensic analysis, threat hunting, and investigative work across live incidents spanning endpoint, network, and cloud environments, and incident types from ransomware and business email compromise to identity compromise, zero-day exploitation, APT activity, and cloud/SaaS breaches. This is a foundational technical role built on rigor, where every conclusion must be evidence-backed, every case well-documented, and every finding able to hold up to scrutiny.
Requirements:
A bachelor's or master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field, or equivalent practical self-study, plus 3 or more years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environment.
Comfort analyzing Windows environments and forensic artifacts, with a foundational understanding of forensic methodologies, evidence handling, acquisition techniques, and chain-of-custody procedures.
Experience with forensic tools such as X-Ways Forensics, Axiom, and FTK; with EDR/XDR platforms (SentinelOne preferred) and SIEMs; and working knowledge of network protocols and network-based forensic analysis.
Scripting and automation capabilities.
Strong verbal and written communication, with comfort documenting and presenting technical findings clearly and precisely.
Ability to perform technical investigations under pressure in high-stakes, time-sensitive situations, while maintaining composure.
An evident self-starter with intellectual curiosity and the ability to adapt to change.
Knowledge of Linux and macOS forensic analysis, exposure to cloud environments (AWS, Azure, GCP) and memory analysis, and foundational experience conducting malware analysis and understanding the reverse engineering process are preferred.
Familiarity with endpoint threat hunting, cyber threat intelligence platforms, the MITRE ATT&CK framework, and AI-assisted tools for streamlining triage, analysis, or reporting workflows is preferred.
Relevant industry certifications, such as GCFE, GCFA, GREM, CFCE, or EnCE, and interest in contributing to industry publications, research, or speaking engagements are preferred.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8835483
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
The role is responsible for anticipating relevant threats, challenging defenses, identifying exploitable weaknesses, hunting for adversary activity that may evade existing controls, and converting findings into measurable security improvements. 

This is a hands-on leadership position for someone who combines offensive-security depth, threat-led thinking, strong operational judgment, and the ability to influence product, engineering, infrastructure, and security stakeholders. 



Your responsibilities will include:

Pillar strategy and leadership 

Define the Proactive Security strategy, operating model, roadmap, priorities, budget, and success measures in alignment with business objectives and threat profile. 
Build, lead, and develop high-performing Red Team, Penetration Testing, Threat Hunting, and Threat Intelligence teams. 
Create a unified intelligence-led program in which threat intelligence informs testing and hunting, and findings continuously improve defensive controls. 
Prioritize work based on crown jewels, material attack paths, emerging threats, major technology changes, incidents, and business risk. 
Establish clear team charters, engagement models, escalation paths, quality standards, and career-development frameworks. 
Provide the CISO and senior leadership with clear visibility into adversary exposure, validated weaknesses, emerging threats, and remediation progress. 
Red Team and adversary emulation 

Lead realistic, intelligence-led adversary simulations across cloud, identity, applications, infrastructure, endpoints, networks, and operational processes. 
Design campaigns that evaluate prevention, detection, response, escalation, and recovery capabilities against relevant threat scenarios. 
Develop and maintain adversary-emulation plans mapped to relevant threat actors, tactics, techniques, and procedures. 
Ensure every engagement operates under documented authorization, rules of engagement, safety controls, deconfliction procedures, and evidence-handling requirements. 
Deliver concise technical and executive reporting that explains demonstrated impact, attack paths, root causes, and prioritized improvements. 
Requirements:
Extensive cybersecurity experience, including leadership responsibility in offensive security, penetration testing, threat hunting, threat intelligence, detection engineering, or incident response. 
Proven experience building or scaling multidisciplinary security teams and programs, including budgets, vendors, and external testing providers. 
Strong technical understanding of modern cloud environments, identity systems, applications, APIs, networks, endpoints, containers, and production infrastructure. 
Demonstrated experience planning and delivering red-team operations, penetration tests, or adversary-emulation exercises. 
Practical knowledge of threat-hunting methodology, telemetry, detection logic, and investigation workflows. 
Experience producing and operationalizing strategic, operational, and tactical threat intelligence. 
Strong understanding of adversary behavior and frameworks such as MITRE ATT&CK. 
Excellent communication and executive-presentation skills, with the ability to translate complex technical findings into clear business risks, decisions, and remediation actions. 
Sound judgment regarding authorization, operational safety, confidentiality, evidence handling, and responsible disclosure. 
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818134
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are seeking a deeply experienced Security Analyst - Tier 3 for its Security Operations Center (SOC). This role is a senior individual-contributor position, leading challenging investigations, setting the standards the SOC operates by. This role reports to the SOC Manager, under the Detection and Response function within the CISO Office.

Your responsibilities will include:

Lead complex, multi-stage, multi-domain investigations end to end, from scoping through deep technical analysis to a clear determination of impact and root cause.
Serve as the SOC's senior escalation point and the quality gate for investigations across the team.
Support the Incident Response team during confirmed incidents with continued telemetry investigation, scoping, and analytical depth.
Continuously sharpen how the SOC investigates, identifying gaps in methods, runbooks, and tooling through daily casework and turning them into concrete improvements.
Mentor Tier 1 and Tier 2 analysts through case reviews, coaching, and pairing during investigations.
Partner with Security Engineering, Platform Security, Threat Intelligence, SOC Automation, and additional teams to turn what the SOC learns into stronger detection and response across .
Participate in readiness activities - tabletops, post-incident reviews, and purple-team engagements.
Participate in the on-call rotation as the senior point of contact outside business hours.
Requirements:
Around 8-10 years of hands-on experience in security operations or incident response, with a track record of leading complex investigations.
Technical Expertise

Expert-level investigation capability across multiple domains: endpoint, identity, cloud, and network.
Solid understanding of cloud-native environments, including containers, Kubernetes.
Deep practical fluency with EDR, SIEM query languages, and log analysis.
Deep knowledge of Windows and Linux internals, applied to artifact and behavioral analysis.
Fluency in attacker TTPs (MITRE ATT&CK), including the Cloud and Containers matrices.
Strong scripting and data-analysis skills (Python, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
Advanced certifications such as GCIH, GCFA, GNFA, GCFE, or OSCP are an advantage.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8818085
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
3 ימים
Location: Tel Aviv-Yafo
Job Type: Full Time
We are seeking a highly skilled and experienced Head of Application Security to join our dynamic team. This role is pivotal in driving the security of our software development lifecycle and ensuring the robustness of our applications against potential threats. The ideal candidate will have a strong background in secure software development practices, including SSDLC implementation, and a deep understanding of security risks & tools. This position reports directly to an R&D VP.
Key Responsibilities
Lead the application security team, providing strategic direction and mentorship.
Develop and implement a comprehensive Secure Software Development Lifecycle (SSDLC) framework.
Oversee the integration of security practices into all phases of the software development lifecycle, including CI/CD guardrails.
Conduct risk assessments and threat modeling to identify and mitigate potential security vulnerabilities.
Collaborate with development teams to ensure secure coding practices and adherence to security standards, while maintaining developer productivity.
Implement and manage security automation tools and processes to enhance the efficiency of security operations.
Stay up-to-date on the latest security trends, vulnerabilities, and technologies to continuously improve our security posture.
Provide expert guidance on security architecture and design for new and existing applications.
Lead incident response efforts related to application security breaches and vulnerabilities.
Foster a culture of security awareness and continuous improvement within the organization.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 7 years of experience in application security, with at least 3 years in a leadership role.
Proven experience in implementing and managing SSDLC frameworks.
In-depth knowledge of security frameworks and methodologies.
Strong understanding of threat modeling methodologies, secure coding practices and common vulnerabilities (e.g., OWASP Top Ten).
Proficiency in programming languages such as Java, Python, C#, or similar.
Experience in implementing security tools and technologies such as ASPM, SAST, DAST in complex and high-scale environment.
Excellent communication and leadership skills, with the ability and passion to drive change across the organization.
Relevant certifications such as CISSP, CISM, or CSSLP are desirable.
Proven experience in a similar role at another leading software development company.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8840733
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
01/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
we are looking for a SecOps Detection & Response.
As a Security Operations Analyst, Detection & Response, you will help protect Aidocs cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of clinical AI platform.
Responsibilities:
Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.
Requirements:
2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8805569
סגור
שירות זה פתוח ללקוחות VIP בלבד
סגור
דיווח על תוכן לא הולם או מפלה
מה השם שלך?
תיאור
שליחה
סגור
v נשלח
תודה על שיתוף הפעולה
מודים לך שלקחת חלק בשיפור התוכן שלנו :)
10/09/2026
חברה חסויה
Location: Tel Aviv-Yafo
Job Type: Full Time
This is a senior, hands-on individual-contributor role with end-to-end ownership of security risk assessments, the security risk register, remediation tracking, risk acceptance, and risk reporting. The successful candidate will work closely with engineering, cloud infrastructure, product, security, compliance, legal, and business teams to ensure that material risks are identified early, assessed consistently, and driven toward clear treatment decisions.

The role requires strong judgment, technical understanding, and the ability to influence stakeholders without relying on formal authority.

Your responsibilities will include

Risk Assessment

Lead security risk assessments for infrastructure, cloud environments, products, applications, business processes, and major technology changes.
Conduct risk assessments for new initiatives, systems, and significant changes, including supporting M&A-related risk assessment work alongside the due diligence team.
Evaluate the design and effectiveness of controls and identify residual risk following mitigation.
Identify emerging and systemic risks that may affect multiple services, regions, or business functions.
Risk Register & Tracking

Maintain the security risk register: log new risks, update status, track owners, and follow items through to remediation or formal risk acceptance.
Support the ongoing refinement of risk assessment and risk register processes, contributing improvements as the practice matures.
Coordinate with other GRC functions on findings and gap assessments that carry risk implications, and independently determine whether a given finding warrants a risk register entry.
Metrics & Reporting

Maintain and improve security risk assessment, scoring, prioritization, and acceptance processes.
Define and monitor meaningful Key Risk Indicators and risk trends.
Translate complex technical risks into clear business impact for senior leadership and governance forums.
Prepare risk reporting that supports security posture reviews, strategic decision-making, and Board-level reporting.
Support auditors, customers, and internal stakeholders on security risk management matters.
Cross-Functional Coordination

Work closely with other GRC functions to ensure risk assessments reflect current operating reality.
Partner with engineering and business stakeholders to embed risk thinking into day-to-day decisions, building trust through clear, practical communication rather than formal authority.
Build trusted relationships with risk and remediation owners while maintaining independent and objective judgment.
Requirements:
5-8 years of experience in security risk management, IT risk, GRC, or a closely related discipline.
Hands-on experience running risk assessments and maintaining a risk register, including driving items through to remediation or formal risk acceptance.
Solid understanding of risk scoring and prioritization approaches, and the judgment to apply them consistently and defensibly.
Ability to define and track meaningful risk metrics/KRIs for leadership reporting.
Strong organizational and analytical skills, with the ability to manage multiple concurrent risk items without losing accuracy or follow-through.
Strong communication and stakeholder management skills; comfortable working across security, compliance, engineering, and business teams.
Familiarity with cloud infrastructure and technology environments is an advantage.
Relevant certifications (e.g., CRISC, CISSP) are an advantage, not a requirement.
Bachelor's degree in information security, computer science, engineering, or a related field preferred; equivalent practical experience will be considered.
Excellent written and verbal communication skills in English.
This position is open to all candidates.
 
Show more...
הגשת מועמדותהגש מועמדות
עדכון קורות החיים לפני שליחה
עדכון קורות החיים לפני שליחה
8817688
סגור
שירות זה פתוח ללקוחות VIP בלבד