Skip to main content

Incident Response Team Lead

SQLink GroupRamat Gan, Tel Aviv District, IsraelNot specifiedFull-timeSeniority: Lead

Posted 20 days ago · 0 applicants

Salary not listed for this role

Saving, applying or scoring takes a few seconds to set up your free account.

Willbi insight

The role in plain words

This role involves leading and managing a Cyber Incident Response team for a financial company. The day-to-day responsibilities include investigating complex Tier 3 cybersecurity incidents, developing detection capabilities using EDR and SIEM platforms, and coordinating with an external SOC. Additionally, the person will build advanced cyber defense processes and address AI-driven threats.

Must-have
  • 3 years of experience investigating Tier 3 cybersecurity incidents
  • Experience managing a technical cybersecurity team
  • Experience writing and customizing detection rules in EDR platforms
  • Experience working with SIEM platforms such as Microsoft Sentinel or Splunk and writing KQL or SPL queries
  • Broad understanding of IT infrastructure, networking, Windows, Linux, and Active Directory / Microsoft Entra ID
Nice-to-have

    Extracted from the job description · kept up to date automatically

    Who this suits

    This role suits experienced cybersecurity professionals with at least three years of Tier 3 incident investigation experience and prior team management experience. It is less ideal for those without hands-on experience customizing EDR detection rules or working with SIEM platforms like Sentinel or Splunk.

    Full job description

    Original listing · kept for reference

    We are recruiting an Incident Response Team Lead for a financial company located in central Israel.

    Responsibilities:

    • Lead and manage the Cyber Incident Response (IR) team

    • Investigate complex cybersecurity incidents at the Tier 3 level

    • Develop and enhance detection and response capabilities using EDR and SIEM platforms

    • Work closely with an external SOC and coordinate incident response activities

    • Build advanced cyber defense processes and address AI-driven cyber threats while providing technical leadership for the Incident Response domain

    Requirements:

    • 3 years of experience investigating Tier 3 cybersecurity incidents

    • Experience managing a technical cybersecurity team

    • Experience writing and customizing detection rules in EDR platforms

    • Experience working with SIEM platforms such as Microsoft Sentinel or Splunk and writing KQL or SPL queries

    • Broad understanding of IT infrastructure, networking, Windows, Linux, and Active Directory / Microsoft Entra ID

    About SQLink Group
    Company profile · coming soon

    Employee reviews · coming soonMore roles at SQLink Group

    Questions about this role

    • This listing did not state a salary. We only show pay when the employer publishes it.
    SQLink Group
    Posted 20 days ago · 0 applicants
    See how you match