60 минут назад
Senior Security Operations Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Operations Engineer (Cybersecurity): Strengthening threat detection, incident response, vulnerability management, cloud security, and AI security operations with an accent on detection engineering, automation, telemetry, and risk-based remediation. Focus on investigating complex incidents, securing AI agents and integrations with auditable guardrails, and reducing manual effort across cloud, identity, endpoint, SaaS, and corporate environments.
Location: Tel Aviv, Israel; hybrid work model with up to three days per week in the office and the remaining days remotely.
Company
is a cybersecurity company focused on protecting identity, cloud, corporate, and AI-enabled environments.
What you will do
- Operate and improve SIEM, EDR, cloud, identity, email, and security monitoring capabilities.
- Design detection rules, analytics, dashboards, alert routing, investigation playbooks, and incident response improvements.
- Lead vulnerability, endpoint patching, CSPM/CWP, exposure, and cloud security triage through remediation and closure.
- Build automation, integrations, workflows, telemetry coverage, metrics, runbooks, and reporting for SecOps operations.
- Assess AI tools, agents, plugins, and MCP integrations; implement least-privilege guardrails, sandboxing, human approval, and runtime monitoring.
- Partner with Cloud Security, Identity and IT, AppSec, Product Engineering, Platform Engineering, GRC, and service owners while mentoring analysts and engineers.
Requirements
- 5+ years of hands-on experience in Security Operations, Security Engineering, Detection Engineering, Incident Response, or a related field.
- Strong experience with SIEM operations, detection engineering, alert triage, investigations, and incident response.
- Practical experience with vulnerability management, endpoint hardening and patching, CSPM/CWP, cloud security, or attack-surface analysis.
- Experience with Azure, AWS, or comparable cloud environments, plus a strong understanding of identity, privileged activity, and cloud administration risks.
- Understanding of AI security risks, including prompt injection, excessive agency, data leakage, tool misuse, and AI supply-chain risks.
- Ability to analyze security data with KQL, SQL, or an equivalent language and automate with Python, PowerShell, JavaScript, or a comparable language.
Nice to have
- Microsoft Sentinel, Microsoft Defender, Log Analytics, SOAR, MITRE ATT&CK, Sigma, YARA, threat hunting, or detection-testing experience.
- Infrastructure-as-code, CI/CD, containers, Kubernetes security, or AI agent and LLM security experience.
- Endpoint privilege management, privileged access workstations, application control, or attack-surface-reduction experience.
- SOC 2, ISO 27001, NIST, FedRAMP, relevant certifications, or equivalent practical experience.
Culture & Benefits
- Hybrid work from the Tel Aviv office, with up to three remote days per week.
- Global cybersecurity team focused on curiosity, integrity, initiative, and continuous improvement.
- Employee experience centered on purpose, professional growth, support, and work-life balance.
- Opportunity to work directly with cross-functional engineering, IT, cloud, identity, AppSec, and GRC teams.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Nebius
1 день назад
Security Analyst - Tier 3 (Cybersecurity)
6 дней назад
Incident Response Engineer (Cybersecurity)
Wiz
5 часов назад
AI Security Researcher (Cloud Security)
3 часа назад
Cloud Security Lead (Cybersecurity)
Nebius
6 дней назад
Vulnerability Lead (Cybersecurity)
Wiz
5 часов назад