Incident Response Team Lead
פורסם לפני 20 ימים · 0 מועמדים
התפקיד במילים פשוטות
התפקיד כולל הובלה וניהול של צוות תגובה לאירועי סייבר (IR) בחברה פיננסית במרכז הארץ. במסגרת התפקיד, המוביל יחקור אירועי אבטחת מידע מורכבים ברמת Tier 3 ויפתח יכולות זיהוי ותגובה באמצעות פלטפורמות EDR ו-SIEM. כמו כן, התפקיד דורש עבודה צמודה מול SOC חיצוני ובניית תהליכי הגנת סייבר מתקדמים.
- 3 years of experience investigating Tier 3 cybersecurity incidents
- Experience managing a technical cybersecurity team
- Experience writing and customizing detection rules in EDR platforms
- Experience working with SIEM platforms such as Microsoft Sentinel or Splunk and writing KQL or SPL queries
- Broad understanding of IT infrastructure, networking, Windows, Linux, and Active Directory / Microsoft Entra ID
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים לבעלי ניסיון של שלוש שנים לפחות בחקירת אירועי סייבר ברמת Tier 3 וניסיון קודם בניהול צוות אבטחת מידע טכנולוגי. הוא פחות יתאים למי שאין לו ניסיון בכתיבת חוקי זיהוי ב-EDR או עבודה עם שאילתות KQL/SPL במערכות SIEM.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןWe are recruiting an Incident Response Team Lead for a financial company located in central Israel.
Responsibilities:
• Lead and manage the Cyber Incident Response (IR) team
• Investigate complex cybersecurity incidents at the Tier 3 level
• Develop and enhance detection and response capabilities using EDR and SIEM platforms
• Work closely with an external SOC and coordinate incident response activities
• Build advanced cyber defense processes and address AI-driven cyber threats while providing technical leadership for the Incident Response domain
Requirements:
• 3 years of experience investigating Tier 3 cybersecurity incidents
• Experience managing a technical cybersecurity team
• Experience writing and customizing detection rules in EDR platforms
• Experience working with SIEM platforms such as Microsoft Sentinel or Splunk and writing KQL or SPL queries
• Broad understanding of IT infrastructure, networking, Windows, Linux, and Active Directory / Microsoft Entra ID
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 3 years of experience investigating Tier 3 cybersecurity incidents, Experience managing a technical cybersecurity team, Experience writing and customizing detection rules in EDR platforms, Experience working with SIEM platforms such as Microsoft Sentinel or Splunk and writing KQL or SPL queries, Broad understanding of IT infrastructure, networking, Windows, Linux, and Active Directory / Microsoft Entra ID