Incident Response Team Lead
Posted 20 days ago · 0 applicants
Saving, applying or scoring takes a few seconds to set up your free account.
The role in plain words
This role involves leading and managing a Cyber Incident Response team for a financial company. The day-to-day responsibilities include investigating complex Tier 3 cybersecurity incidents, developing detection capabilities using EDR and SIEM platforms, and coordinating with an external SOC. Additionally, the person will build advanced cyber defense processes and address AI-driven threats.
- 3 years of experience investigating Tier 3 cybersecurity incidents
- Experience managing a technical cybersecurity team
- Experience writing and customizing detection rules in EDR platforms
- Experience working with SIEM platforms such as Microsoft Sentinel or Splunk and writing KQL or SPL queries
- Broad understanding of IT infrastructure, networking, Windows, Linux, and Active Directory / Microsoft Entra ID
Extracted from the job description · kept up to date automatically
Who this suits
This role suits experienced cybersecurity professionals with at least three years of Tier 3 incident investigation experience and prior team management experience. It is less ideal for those without hands-on experience customizing EDR detection rules or working with SIEM platforms like Sentinel or Splunk.
Full job description
Original listing · kept for referenceWe are recruiting an Incident Response Team Lead for a financial company located in central Israel.
Responsibilities:
• Lead and manage the Cyber Incident Response (IR) team
• Investigate complex cybersecurity incidents at the Tier 3 level
• Develop and enhance detection and response capabilities using EDR and SIEM platforms
• Work closely with an external SOC and coordinate incident response activities
• Build advanced cyber defense processes and address AI-driven cyber threats while providing technical leadership for the Incident Response domain
Requirements:
• 3 years of experience investigating Tier 3 cybersecurity incidents
• Experience managing a technical cybersecurity team
• Experience writing and customizing detection rules in EDR platforms
• Experience working with SIEM platforms such as Microsoft Sentinel or Splunk and writing KQL or SPL queries
• Broad understanding of IT infrastructure, networking, Windows, Linux, and Active Directory / Microsoft Entra ID
Questions about this role
- This listing did not state a salary. We only show pay when the employer publishes it.
- 3 years of experience investigating Tier 3 cybersecurity incidents, Experience managing a technical cybersecurity team, Experience writing and customizing detection rules in EDR platforms, Experience working with SIEM platforms such as Microsoft Sentinel or Splunk and writing KQL or SPL queries, Broad understanding of IT infrastructure, networking, Windows, Linux, and Active Directory / Microsoft Entra ID