Назад
Company hidden
60 минут назад

Senior Security Operations Engineer (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Israel
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Operations Engineer (Cybersecurity): Strengthening threat detection, incident response, vulnerability management, cloud security, and AI security operations with an accent on detection engineering, automation, telemetry, and risk-based remediation. Focus on investigating complex incidents, securing AI agents and integrations with auditable guardrails, and reducing manual effort across cloud, identity, endpoint, SaaS, and corporate environments.

Location: Tel Aviv, Israel; hybrid work model with up to three days per week in the office and the remaining days remotely.

Company

hirify.global is a cybersecurity company focused on protecting identity, cloud, corporate, and AI-enabled environments.

What you will do

  • Operate and improve SIEM, EDR, cloud, identity, email, and security monitoring capabilities.
  • Design detection rules, analytics, dashboards, alert routing, investigation playbooks, and incident response improvements.
  • Lead vulnerability, endpoint patching, CSPM/CWP, exposure, and cloud security triage through remediation and closure.
  • Build automation, integrations, workflows, telemetry coverage, metrics, runbooks, and reporting for SecOps operations.
  • Assess AI tools, agents, plugins, and MCP integrations; implement least-privilege guardrails, sandboxing, human approval, and runtime monitoring.
  • Partner with Cloud Security, Identity and IT, AppSec, Product Engineering, Platform Engineering, GRC, and service owners while mentoring analysts and engineers.

Requirements

  • 5+ years of hands-on experience in Security Operations, Security Engineering, Detection Engineering, Incident Response, or a related field.
  • Strong experience with SIEM operations, detection engineering, alert triage, investigations, and incident response.
  • Practical experience with vulnerability management, endpoint hardening and patching, CSPM/CWP, cloud security, or attack-surface analysis.
  • Experience with Azure, AWS, or comparable cloud environments, plus a strong understanding of identity, privileged activity, and cloud administration risks.
  • Understanding of AI security risks, including prompt injection, excessive agency, data leakage, tool misuse, and AI supply-chain risks.
  • Ability to analyze security data with KQL, SQL, or an equivalent language and automate with Python, PowerShell, JavaScript, or a comparable language.

Nice to have

  • Microsoft Sentinel, Microsoft Defender, Log Analytics, SOAR, MITRE ATT&CK, Sigma, YARA, threat hunting, or detection-testing experience.
  • Infrastructure-as-code, CI/CD, containers, Kubernetes security, or AI agent and LLM security experience.
  • Endpoint privilege management, privileged access workstations, application control, or attack-surface-reduction experience.
  • SOC 2, ISO 27001, NIST, FedRAMP, relevant certifications, or equivalent practical experience.

Culture & Benefits

  • Hybrid work from the Tel Aviv office, with up to three remote days per week.
  • Global cybersecurity team focused on curiosity, integrity, initiative, and continuous improvement.
  • Employee experience centered on purpose, professional growth, support, and work-life balance.
  • Opportunity to work directly with cross-functional engineering, IT, cloud, identity, AppSec, and GRC teams.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →