Incident Response Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Incident Response Engineer (Cybersecurity): Managing the full lifecycle of security incidents and enhancing threat detection capabilities with an accent on cloud-native environments and automation. Focus on building SOAR playbooks, tuning SIEM correlation rules, and performing deep-dive forensic investigations across multi-cloud and OS platforms.
Location: Tel Aviv, Israel (Onsite)
Company
is a leader in behavioral biometrics, utilizing machine learning to analyze digital behavior for fraud prevention and identity protection in the financial sector.
What you will do
- Execute the full IR lifecycle including triage, containment, eradication, and recovery for complex security events.
- Perform root cause analysis and forensic examinations across Windows, Mac, and Linux environments.
- Collaborate on creating and tuning SIEM rules and dashboards to improve visibility and reduce false positives.
- Develop and refine SOAR playbooks to automate repetitive investigation tasks and increase operational efficiency.
- Monitor and mitigate cloud-native threats across Azure, AWS, and GCP environments.
Requirements
- Proven experience as a SecOps or IR Analyst/Engineer with a focus on active investigation.
- Deep understanding of the Incident Response lifecycle.
- Hands-on experience managing security alerts and performing root cause analysis.
- Experience working across Azure, AWS, and GCP to mitigate cloud-native threats.
- Strong knowledge of Windows, Mac, and Linux operating systems and artifacts.
- Proficiency with SIEM platforms like Splunk and security automation tools like XSOAR.
- Scripting experience with Python or Bash for data parsing and investigation.
Nice to have
- Experience in detection engineering and building correlation rules.
- Ability to develop new SOAR workflows and automated response playbooks.
- Familiarity with REST APIs and Regex for advanced querying.
- Experience with container security and Kubernetes.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →