Incident Response Expert
פורסם לפני 24 ימים · 0 מועמדים
התפקיד במילים פשוטות
בתפקיד זה, תשתתף בחקירות פורנזיות ותגובה לאירועים, כולל התקפות מתוחכמות בקנה מידה גדול, ותבצע ניתוח לוגים ופורנזיקה מבוססת מארח ורשת. כמו כן, תשתתף בציד איומים, תזהה אינדיקטורים לפריצה (IOCs) ותפתח כלים ומתודולוגיות לשיפור ערימת הטכנולוגיה הקיימת. תשתף פעולה עם צוותי IT ואבטחה ותפיק דוחות מקיפים ומקצועיים.
- 3 years of relevant experience in DFIR or advanced cyber threat investigation
- Bright, curious, and determined team player
- technical maturity of an Expert investigator
- Problem solver, in-depth thinker with a growth mindset
- capable of maintaining composure under pressure during high-stakes crises
- Hands-on experience in data analysis (network traffic and log analysis) in relevant data analysis platforms, with an emphasis on Splunk (writing complex queries, building dashboards, and filtering datasets)
- Familiarity with cloud infrastructure investigation, specifically Microsoft 365 / Azure AD environments and AWS CloudTrail
- Relevant professional certifications such as GIAC (GCFA, GCFE, GNFA), CHFI, Splunk Power User, or Cloud Security certificates (SC-200 / AZ-500)
- Excellent communication and interpersonal skills
- Fluent English, including the ability to document and explain complex technical information in a concise, understandable manner
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים למומחה חקירות בעל לפחות 3 שנות ניסיון ב-DFIR או חקירות איומי סייבר מתקדמות, עם הבנה מעמיקה במחזור החיים של איומי אבטחה מתקדמים וביכולת לפתור בעיות תחת לחץ. הוא פחות מתאים למי שאין לו ניסיון קודם בתחום או למי שאינו בקיא בעקרונות רשת ובקרות אבטחה במערכות הפעלה שונות.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיון* Participate in forensic and incident response investigations, including large-scale sophisticated attacks, conduct log analysis, host and network-based forensics.
* Participate in threat hunting: proactively hunt for targeted attacks and new emerging threats in client’s networks; as well as security assessments and simulations.
* Identify indicators of compromise (IOCs) and tools, tactics, and procedures (TTPs) to help ascertain whether and how breaches have occurred.
* Utilize and develop tools and methodologies to improve the existing investigative and hunting technological stack.
* Collaborate with IT and Security teams during investigations.
* Generate and present a comprehensive and professional report of findings from investigations.
Requirements * At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry).
* Bright, curious, and determined team player, who strives for excellence and exhibits the technical maturity of an Expert investigator.
* Problem solver, in-depth thinker with a growth mindset, capable of maintaining composure under pressure during high-stakes crises.
* Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework).
* Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis.
* Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix), including host-based forensics and experience with analyzing OS artifacts (MFT, Registry, Event Logs, Volatile Memory).
* Fluency with one or more scripting languages (i.e., Python, PowerShell) for data parsing and automation.
Multidisciplinary Knowledge and Competencies (An Advantage):
* Hands-on experience in data analysis (network traffic and log analysis) in relevant data analysis platforms, with an emphasis on *Splunk* (writing complex queries, building dashboards, and filtering datasets).
* Familiarity with cloud infrastructure investigation, specifically *Microsoft 365 / Azure AD* environments and AWS CloudTrail.
* Relevant professional certifications such as GIAC (GCFA, GCFE, GNFA), CHFI, Splunk Power User, or Cloud Security certificates (SC-200 / AZ-500).
* Excellent communication and interpersonal skills. Fluent English, including the ability to document and explain complex technical information in a concise, understandable manner.
Location: Tel Aviv (Hybrid Model)
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- היברידי
- 3 years of relevant experience in DFIR or advanced cyber threat investigation, Bright, curious, and determined team player, technical maturity of an Expert investigator, Problem solver, in-depth thinker with a growth mindset, capable of maintaining composure under pressure during high-stakes crises