Skip to main content

Incident response researcher/ DFIR

UndisclosedCenter District, IsraelNot specifiedFull-timeSeniority: Not specified

Posted 27 days ago · 0 applicants

Salary not listed for this role

Saving, applying or scoring takes a few seconds to set up your free account.

Willbi insight

The role in plain words

Must-have
  • At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry)
  • Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework)
  • Familiarity with cloud infrastructure investigation, specifically Microsoft 365 / Azure AD environments and AWS CloudTrail
  • Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis
  • Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix), including host-based forensics and experience with analyzing OS artifacts (MFT, Registry, Event Logs, Volatile Memory)
Nice-to-have

    Extracted from the job description · kept up to date automatically

    Who this suits

    Full job description

    Original listing · kept for reference

    We are a leading, innovative and fast-growing cybersecurity consulting company.

    With extensive experience supporting organizations (in Israel and globally) during attacks, we are dedicated to being ready when challenges strike.

    We are looking for DFIR professional to join our team.

    Job Description

    * Participate in forensic and incident response investigations, including large-scale sophisticated attacks, conduct log analysis, host and network-based forensics.

    * Participate in threat hunting: proactively hunt for targeted attacks and new emerging threats in client’s networks; as well as security assessments and simulations.

    * Identify indicators of compromise (IOCs) and tools, tactics, and procedures (TTPs) to help ascertain whether and how breaches have occurred.

    * Utilize and develop tools and methodologies to improve the existing investigative and hunting technological stack.

    * Collaborate with IT and Security teams during investigations.

    * Generate and present a comprehensive and professional report of findings from investigations.

    Main Requirements

    * At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry).

    * Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework).

    * Familiarity with cloud infrastructure investigation, specifically **Microsoft 365 / Azure AD** environments and AWS CloudTrail.

    * Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis.

    * Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix), including host-based forensics and experience with analyzing OS artifacts (MFT, Registry, Event Logs, Volatile Memory).

    * Fluency with one or more scripting languages (i.e., Python, PowerShell) for data parsing and automation.

    * Problem solver, in-depth thinker with a growth mindset, capable of maintaining composure under pressure during high-stakes crises.

    About Undisclosed
    Company profile · coming soon

    Employee reviews · coming soonMore roles at Undisclosed

    Questions about this role

    • This listing did not state a salary. We only show pay when the employer publishes it.
    Undisclosed
    Posted 27 days ago · 0 applicants
    See how you match