Information Security Manager
פורסם לפני 30 ימים · 0 מועמדים
התפקיד במילים פשוטות
התפקיד כולל הובלה וחניכה של צוות תגובה לאירועים (Tier 3), תכנון, תעדוף וביצוע משימות. כמו כן, בנייה ושיפור יכולות זיהוי על ידי פיתוח ותחזוקה של כללי זיהוי EDR ובקרות אבטחה נוספות. העבודה כוללת גם ניהול ספק SOC חיצוני ושיפור מתמיד של תהליכי זיהוי ותגובה.
- 3+ years of hands-on Tier 3 Incident Response experience
- Proven experience leading a technical cybersecurity team
- Strong experience developing and tuning EDR detection rules
- Experience working with or managing an external SOC provider
- Hands-on experience with SIEM platforms (Microsoft Sentinel, Splunk) and KQL/SPL
- Experience with MITRE ATT&CK and translating TTPs into detection logic
- Red Team / Purple Team / Penetration Testing experience
- Experience with Breach & Attack Simulation platforms
- Relevant certifications such as GCIH, GCFA, GCIA, OSCP, CRTO, or equivalent
- Strong English communication skills
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים למועמדים עם 3+ שנות ניסיון מעשי בתגובה לאירועים (Tier 3) וניסיון מוכח בהובלת צוות אבטחת סייבר טכני. נדרש ניסיון חזק בפיתוח וכוונון כללי זיהוי EDR, וכן ניסיון בעבודה עם או ניהול ספק SOC חיצוני.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןIR Team Lead (Tier 3)
We're looking for an experienced Incident Response (IR) Team Lead to join a leading enterprise organization in Central Israel in a hybrid work model.
Please note: This is not a SOC Manager position. This role focuses on leading a Tier 3 Incident Response team responsible for cyber investigations, threat hunting, detection engineering, and response capabilities.
Responsibilities
• Lead and mentor the Tier 3 Incident Response team, including planning, prioritization, and execution.
• Build and enhance detection capabilities by developing and maintaining EDR detection rules and other security controls.
• Lead complex cyber investigations, including Incident Response, Digital Forensics, and Threat Hunting.
• Manage the organization's external SOC provider, including SLA, KPI, investigation quality, and service oversight.
• Drive continuous improvement of detection playbooks and response processes.
• Evaluate security technologies and lead POCs for new cyber defense capabilities.
• Ensure log readiness and visibility to support effective incident investigations.
• Monitor Threat Intelligence and translate MITRE ATT&CK TTPs into practical detection rules and security controls.
• Lead Purple Team exercises and Breach & Attack Simulation activities to validate and improve detection coverage.
• Work closely with Infrastructure, IT, Cloud, Cyber Intelligence, BCP, and executive stakeholders.
Requirements
• 3+ years of hands-on Tier 3 Incident Response experience.
• Proven experience leading a technical cybersecurity team.
• Strong experience developing and tuning EDR detection rules.
• Experience working with or managing an external SOC provider.
• Hands-on experience with SIEM platforms (Microsoft Sentinel, Splunk) and KQL/SPL.
• Strong understanding of Windows, Linux, Active Directory, Entra ID, networking, and enterprise IT infrastructure.
• Deep understanding of AI-related cyber threats and defensive approaches.
• Familiarity with Autonomous SOC concepts.
Advantage
• Experience with MITRE ATT&CK and translating TTPs into detection logic.
• Red Team / Purple Team / Penetration Testing experience.
• Experience with Breach & Attack Simulation platforms.
• Relevant certifications such as GCIH, GCFA, GCIA, OSCP, CRTO, or equivalent.
• Strong English communication skills.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- היברידי
- 3+ years of hands-on Tier 3 Incident Response experience, Proven experience leading a technical cybersecurity team, Strong experience developing and tuning EDR detection rules, Experience working with or managing an external SOC provider, Hands-on experience with SIEM platforms (Microsoft Sentinel, Splunk) and KQL/SPL