IR Team Lead - Cyber Incident Response (Tier 3)
פורסם לפני 24 ימים · 0 מועמדים
התפקיד במילים פשוטות
בתפקיד זה, תוביל צוות תגובה לאירועי סייבר (Tier 3) ותנהל חקירות סייבר מורכבות, כולל פורנז'יקה דיגיטלית וציד איומים. תהיה אחראי על פיתוח ושיפור יכולות זיהוי EDR, ניהול ה-SOC החיצוני ושיתוף פעולה עם צוותי IT וסייבר.
- 3+ years of experience investigating Tier 3 cyber incidents
- Experience leading a technical team
- Hands-on experience creating and tuning EDR detection rules
- Experience working with an external SOC, including SLA management and quality assurance
- Experience with SIEM platforms (Microsoft Sentinel or Splunk) and writing KQL or SPL queries
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים למומחים בעלי ניסיון של 3+ שנים בחקירת אירועי סייבר ברמת Tier 3 וניסיון בהובלת צוות טכני. נדרש ניסיון מעשי ביצירה וכוונון של כללי זיהוי EDR ועבודה עם SOC חיצוני. פחות מתאים למי שאין לו ניסיון מוכח בהובלת צוות או בחקירות סייבר מתקדמות.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןJoin one of Israel's leading insurance companies as an IR Team Lead, leading the organization's Tier 3 Cyber Incident Response team. This is a strategic, hands-on role combining technical leadership, advanced cyber investigations, development of detection capabilities, and continuous innovation in Detection & Response.
What You'll Do
• Lead the Tier 3 IR team, manage priorities, and drive end-to-end cyber investigations, including Digital Forensics, Threat Hunting, and Incident Response.
• Develop and enhance EDR detection capabilities, improve playbooks, and translate Threat Intelligence and MITRE TTPs into effective detection controls.
• Manage the external SOC, lead Purple Team and Breach & Attack Simulation initiatives, evaluate new security technologies, and collaborate with IT, Infrastructure, Cloud, and Cyber teams.
Requirements
• 3+ years of experience investigating Tier 3 cyber incidents - Must
• Experience leading a technical team - Must
• Hands-on experience creating and tuning EDR detection rules - Must
• Experience working with an external SOC, including SLA management and quality assurance - Must
• Experience with SIEM platforms (Microsoft Sentinel or Splunk) and writing KQL or SPL queries - Must
• Strong understanding of AI technologies, the evolving cyber threat landscape, and Autonomous SOC concepts - Must
• Strong knowledge of IT infrastructure, Networking, Windows, Linux, Active Directory, and Microsoft Entra ID - Must
• Experience with MITRE ATT&CK, Red Team, Purple Team, Penetration Testing, or Breach & Attack Simulation - Significant Advantage
• Relevant certifications such as GCIH, GCFA, GCIA, OSCP, or CRTO - Significant Advantage
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 3+ years of experience investigating Tier 3 cyber incidents, Experience leading a technical team, Hands-on experience creating and tuning EDR detection rules, Experience working with an external SOC, including SLA management and quality assurance, Experience with SIEM platforms (Microsoft Sentinel or Splunk) and writing KQL or SPL queries