Security Operations Manager
פורסם אתמול · 0 מועמדים
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןWe are looking for a hands-on Senior SecOps & Security Infrastructure Lead to take complete ownership of our technical security environment. In a rapidly growing R&D defense-tech ecosystem (~200 employees), you will build, architect, and operate end-to-end security across endpoints, identities, networks, and advanced infrastructure.
This is not a traditional SOC analyst, GRC, or tool-administration position. You will work alongside an external CISO (who guides high-level risk and strategy) to personally design, automate, and operate detection and response capabilities from the ground up.
What You’ll Do
• Security Architecture & Visibility: Establish full-spectrum asset visibility and security controls across workstations, cloud workloads, HPC, lab systems, and air-gapped environments.
• Identity & Access Security: Own IAM lifecycle, SSO/MFA, privileged access (PAM), admin controls, and offboarding workflows.
• Detection & Incident Response: Deploy and operate EDR/XDR, SIEM/logging, MDM, and vulnerability management. Personally investigate incidents and continuously build novel detection logic for modern attack behaviors.
• Data & Network Protection: Architect secure network segmentation and safeguard R&D data flow across endpoints, Google Workspace, removable media, and controlled transfer points.
• Automation & Agentic Workflows: Leverage Python, Bash/PowerShell, and AI/agentic tooling to automate evidence collection, log analysis, threat hunting, and alert enrichment.
• Resilience: Partner with IT/Infra teams to enhance ransomware resilience, backup immutability, and recovery workflows.
What You’ll Bring
• Experience: Senior background in Security Operations, Security Infrastructure, or Cyber Engineering with proven ownership of production R&D environments.
• Domain Mastery: Deep, practical expertise across both Linux and Windows ecosystems, spanning endpoints, identities, networking, and SIEM/EDR pipelines.
• Automation & Scripting: Strong hands-on coding skills in Python, PowerShell, or Bash using APIs to automate repetitive operations.
• Complex Infrastructure: Familiarity with high-performance computing (HPC), on-prem systems, defense/embedded labs, or air-gapped environments – Major Advantage.
• AI & Agentic Proficiency: Practical experience utilizing or building AI agents/workflows (e.g., tool-calling, MCP, LLM integrations) for automated threat hunting, log analysis, or incident enrichment.
• Mindset: Highly autonomous engineer with an attacker’s perspective, who proactively identifies security gaps and bridges architecture with execution without needing separate domain specialists.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.