דלג לתוכן הראשי

IR Team Lead - Cyber Incident Response (Tier 3)

Moveo Sourceרמת גן, מחוז תל אביב, ישראללא צויןFull-timeדרגה: ליד

פורסם לפני 24 ימים · 0 מועמדים

שכר לא צוין במשרה זו

שמירה, הגשה או בדיקת התאמה — כמה שניות להקמת חשבון חינם.

תובנת Willbi

התפקיד במילים פשוטות

בתפקיד זה, תוביל צוות תגובה לאירועי סייבר (Tier 3) ותנהל חקירות סייבר מורכבות, כולל פורנז'יקה דיגיטלית וציד איומים. תהיה אחראי על פיתוח ושיפור יכולות זיהוי EDR, ניהול ה-SOC החיצוני ושיתוף פעולה עם צוותי IT וסייבר.

חובה
  • 3+ years of experience investigating Tier 3 cyber incidents
  • Experience leading a technical team
  • Hands-on experience creating and tuning EDR detection rules
  • Experience working with an external SOC, including SLA management and quality assurance
  • Experience with SIEM platforms (Microsoft Sentinel or Splunk) and writing KQL or SPL queries
יתרון

    חולץ מתיאור המשרה · מתעדכן אוטומטית

    למי זה מתאים

    התפקיד מתאים למומחים בעלי ניסיון של 3+ שנים בחקירת אירועי סייבר ברמת Tier 3 וניסיון בהובלת צוות טכני. נדרש ניסיון מעשי ביצירה וכוונון של כללי זיהוי EDR ועבודה עם SOC חיצוני. פחות מתאים למי שאין לו ניסיון מוכח בהובלת צוות או בחקירות סייבר מתקדמות.

    תיאור המשרה המלא

    המשרה המקורית · נשמר לעיון

    Join one of Israel's leading insurance companies as an IR Team Lead, leading the organization's Tier 3 Cyber Incident Response team. This is a strategic, hands-on role combining technical leadership, advanced cyber investigations, development of detection capabilities, and continuous innovation in Detection & Response.

    What You'll Do

    • Lead the Tier 3 IR team, manage priorities, and drive end-to-end cyber investigations, including Digital Forensics, Threat Hunting, and Incident Response.

    • Develop and enhance EDR detection capabilities, improve playbooks, and translate Threat Intelligence and MITRE TTPs into effective detection controls.

    • Manage the external SOC, lead Purple Team and Breach & Attack Simulation initiatives, evaluate new security technologies, and collaborate with IT, Infrastructure, Cloud, and Cyber teams.

    Requirements

    • 3+ years of experience investigating Tier 3 cyber incidents - Must

    • Experience leading a technical team - Must

    • Hands-on experience creating and tuning EDR detection rules - Must

    • Experience working with an external SOC, including SLA management and quality assurance - Must

    • Experience with SIEM platforms (Microsoft Sentinel or Splunk) and writing KQL or SPL queries - Must

    • Strong understanding of AI technologies, the evolving cyber threat landscape, and Autonomous SOC concepts - Must

    • Strong knowledge of IT infrastructure, Networking, Windows, Linux, Active Directory, and Microsoft Entra ID - Must

    • Experience with MITRE ATT&CK, Red Team, Purple Team, Penetration Testing, or Breach & Attack Simulation - Significant Advantage

    • Relevant certifications such as GCIH, GCFA, GCIA, OSCP, or CRTO - Significant Advantage

    אודות Moveo Source
    פרופיל החברה · בקרוב

    ביקורות עובדים · בקרובעוד משרות ב-Moveo Source

    שאלות על המשרה

    • המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
    Moveo Source
    פורסם לפני 24 ימים · 0 מועמדים
    בדקו את ההתאמה