1 день назад
SecOps Specialist (SIEM/SOAR)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SecOps Specialist (SIEM/SOAR): Developing and maintaining SIEM detections, SOAR playbooks, security-tool integrations, and incident-response documentation with an accent on security monitoring, log analysis, and detection engineering. Focus on investigating alerts across endpoint, cloud, identity, email, and network systems, automating response workflows, and improving cyber resilience.
Location: Jerusalem, Israel; hybrid workplace
Company
is hiring for its IT & Information Security function.
What you will do
- Develop, test, tune, and maintain SIEM detection rules, correlation logic, dashboards, and alert thresholds.
- Integrate security tools and services through APIs, webhooks, scripts, and automation platforms.
- Monitor, triage, and investigate alerts and telemetry from EDR, cloud, identity, email, network, and security platforms.
- Build and enhance SOAR playbooks for alert enrichment, investigation, case management, notifications, and approved containment actions.
- Validate log coverage, parsing, ingestion health, data quality, and retention across security-relevant systems.
- Collaborate with IT, cloud, infrastructure, identity, network, and engineering teams on incident containment and remediation.
Requirements
- 1–2 years of hands-on experience in Security Operations, SOC, Cyber Analysis, Incident Response, or Detection Engineering.
- Practical experience operating SIEM platforms, including log onboarding, parsing, detection-rule development, and alert tuning.
- Experience analyzing security telemetry from EDR, Windows and Linux systems, identity services, cloud environments, email-security tools, firewalls, DNS, proxy, VPN, and network devices.
- Strong understanding of common attack techniques, the cyber kill chain, and the MITRE ATT&CK framework.
- Excellent written and verbal communication skills for documentation and reporting in English.
- Proficiency in SIEM query languages such as KQL or SQL, plus scripting or automation with Python, PowerShell, Bash, REST APIs, JSON, or webhooks.
Nice to have
- Familiarity with SOAR platforms and automation workflows for alert enrichment, investigation, case management, and response.
Culture & Benefits
- Hybrid workplace in Jerusalem.
- Close collaboration with SOC, IT, cloud, infrastructure, and engineering teams.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →