Skip to main content

Incident Response Expert

Code Blue CyberTel Aviv District, IsraelNot specifiedFull-timeSeniority: Not specified

Posted 24 days ago · 0 applicants

Salary not listed for this role

Saving, applying or scoring takes a few seconds to set up your free account.

Willbi insight

The role in plain words

Must-have
  • 3 years of relevant experience in DFIR or advanced cyber threat investigation
  • Bright, curious, and determined team player
  • technical maturity of an Expert investigator
  • Problem solver, in-depth thinker with a growth mindset
  • capable of maintaining composure under pressure during high-stakes crises
Nice-to-have
  • Hands-on experience in data analysis (network traffic and log analysis) in relevant data analysis platforms, with an emphasis on Splunk (writing complex queries, building dashboards, and filtering datasets)
  • Familiarity with cloud infrastructure investigation, specifically Microsoft 365 / Azure AD environments and AWS CloudTrail
  • Relevant professional certifications such as GIAC (GCFA, GCFE, GNFA), CHFI, Splunk Power User, or Cloud Security certificates (SC-200 / AZ-500)
  • Excellent communication and interpersonal skills
  • Fluent English, including the ability to document and explain complex technical information in a concise, understandable manner

Extracted from the job description · kept up to date automatically

Who this suits

Full job description

Original listing · kept for reference

* Participate in forensic and incident response investigations, including large-scale sophisticated attacks, conduct log analysis, host and network-based forensics.

* Participate in threat hunting: proactively hunt for targeted attacks and new emerging threats in client’s networks; as well as security assessments and simulations.

* Identify indicators of compromise (IOCs) and tools, tactics, and procedures (TTPs) to help ascertain whether and how breaches have occurred.

* Utilize and develop tools and methodologies to improve the existing investigative and hunting technological stack.

* Collaborate with IT and Security teams during investigations.

* Generate and present a comprehensive and professional report of findings from investigations.

Requirements * At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry).

* Bright, curious, and determined team player, who strives for excellence and exhibits the technical maturity of an Expert investigator.

* Problem solver, in-depth thinker with a growth mindset, capable of maintaining composure under pressure during high-stakes crises.

* Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework).

* Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis.

* Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix), including host-based forensics and experience with analyzing OS artifacts (MFT, Registry, Event Logs, Volatile Memory).

* Fluency with one or more scripting languages (i.e., Python, PowerShell) for data parsing and automation.

Multidisciplinary Knowledge and Competencies (An Advantage):

* Hands-on experience in data analysis (network traffic and log analysis) in relevant data analysis platforms, with an emphasis on *Splunk* (writing complex queries, building dashboards, and filtering datasets).

* Familiarity with cloud infrastructure investigation, specifically *Microsoft 365 / Azure AD* environments and AWS CloudTrail.

* Relevant professional certifications such as GIAC (GCFA, GCFE, GNFA), CHFI, Splunk Power User, or Cloud Security certificates (SC-200 / AZ-500).

* Excellent communication and interpersonal skills. Fluent English, including the ability to document and explain complex technical information in a concise, understandable manner.

Location: Tel Aviv (Hybrid Model)

About Code Blue Cyber
Company profile · coming soon

Employee reviews · coming soonMore roles at Code Blue Cyber

Questions about this role

  • This listing did not state a salary. We only show pay when the employer publishes it.
Code Blue Cyber
Posted 24 days ago · 0 applicants
See how you match