דלג לתוכן הראשי

DFIR Specialist

OP Innovateראשון לציון, מחוז המרכז, ישראללא צויןFull-timeדרגה: בכיר/ה

פורסם אתמול · 0 מועמדים

שכר לא צוין במשרה זו

שמירה, הגשה או בדיקת התאמה. פתיחת חשבון חינם לוקחת כמה שניות.

תובנת Willbi

התפקיד במילים פשוטות

תפקיד זה כולל הובלת חקירות תגובה לאירועי סייבר (DFIR) וביצוע ניתוחי פורנזיקה מעמיקים במערכות הפעלה שונות, זיכרון ורשת. העבודה כוללת זיהוי טקטיקות תקיפה, הכלה ומיגור של איומים, לצד פיתוח פתרונות ואמצעים למניעת הישנות אירועים. בנוסף, יש צורך בכתיבת דוחות טכניים מפורטים ושמירה על ראיות דיגיטליות בהתאם לתקנים משפטיים.

חובה
  • 4+ years of hands-on experience in DFIR, threat hunting, or a closely related security operations role
  • Deep familiarity with forensic/IR tools (e.g., Velociraptor, Volatility, EDR/XDR platforms, Eric Zimmerman's Tools)
  • Performing deep-dive disk, memory, and network forensics across Windows, Linux, and macOS environments
  • Solid foundational understanding of operating system internals and network traffic analysis
  • Recognized industry credentials (e.g. GCFA, GCFE, GNFA, GREM, OSWE, OSCP, or equivalent)
יתרון
  • Cloud Incident Response (AWS, Azure or GCP)
  • Experience across cloud security, red team and penetration testing
  • Source-code analysis (SAST) to identify vulnerabilities
  • Reverse engineering malicious binaries

חולץ מתיאור המשרה · מתעדכן אוטומטית

למי זה מתאים

התפקיד מתאים למקצועני סייבר בעלי 4 שנות ניסיון מעשי לפחות בתחומי DFIR או ציד איומים, עם היכרות מעמיקה עם כלי פורנזיקה והסמכות מוכרות בתעשייה. הוא פחות מתאים למי שחסר ניסיון טכני מעשי בחקירת אירועי סייבר מורכבים או למי שאינו שולט באנגלית ועברית ברמה גבוהה.

תיאור המשרה המלא

המשרה המקורית · נשמר לעיון

Founded in 2014, OP Innovate specializes in protecting global enterprises from the ever-evolving challenges of organizational cybersecurity. With a deep-rooted expertise in cyber research, penetration testing, digital forensics, incident response and training. Headquartered in Israel, OP Innovate stands at the forefront of the cybersecurity industry, collaborates with leading experts and leverages state-of-the-art knowledge to address critical cybersecurity concerns. This commitment enables both the company and its clients to stay ahead in an increasingly complex digital landscape.

We are looking for a DFIR Specialist to join our team. In this position, you will be leading high-severity Digital Forensics and Incident Response (DFIR) investigations and take part as a technical expert in efforts to develop cyber security solutions. You will be at the forefront of cyber security, investigating breaches to contain and eradicate threats, while also actively working on developing mechanisms that help decrease chances of those incidents from reoccurring.

Your work will directly impact the digital resilience of organizations across various sectors, shaping both their active defense and proactive security posture.

Requirements

• Lead end-to-end Incident Response (IR) engagements - from initial alert triage and containment to eradication and post-incident recovery

• Performing deep-dive disk, memory, and network forensics across Windows, Linux, and macOS environments

• Identify, analyze, and reverse-engineer threat actor tactics designed to evade, neutralize, or blind EDR/XDR agents (e.g., unhooking, direct syscalls, bring-your-own-vulnerable-driver/BYOVD attacks, process hollowing, and living-off-the-land techniques)

• Perform meticulous post-incident analysis to verify complete eradication of attacker presence. Ensure operating systems are fully cleaned of hidden backdoors, persistence mechanisms (WMI subscriptions, scheduled tasks, registry modifications, custom services), and rootkits

• Providing urgent response to confirmed security breaches requiring immediate action at the highest level of escalation

• Cleanly collect and maintain a defensible chain of custody for digital evidence, ensuring strict compliance with legal, evidentiary, and regulatory standards

• Produce detailed, high-quality technical reports and incident timelines for technical, management, and legal stakeholders

Skills And Experience

• 4+ years of hands-on experience in DFIR, threat hunting, or a closely related security operations role

• Deep familiarity with forensic/IR tools, such as Velociraptor, Thor/Asgard/Loki, Volatility, Redline, EDR/XDR platforms, Autopsy, Eric Zimmerman's Tools

• Solid foundational understanding of operating system internals (Windows Registry, Linux syslogs, etc.) and network traffic analysis

• A self-driven commitment to researching emerging adversary tactics, techniques, procedures and zero-day vulnerabilities, ensuring both defensive and offensive strategies stay ahead of modern threat actors

• Proven ability to drive projects autonomously from start to finish, combined with a highly collaborative mindset that thrives when sharing knowledge and tackling incidents as a cohesive team

• A strong commitment to high ethical standards and professional integrity when handling highly sensitive data, active breaches, and 0-day style vulnerabilities

• Recognized industry credentials: DFIR: GCFA, GCFE, GNFA, GREM, or equivalent. Offensive: OSWE, OSCP, GWAPT, BSCP, eWPTX, or equivalent

• Excellent spoken and written communication skills in both Hebrew and English

Advantages

• Cloud Incident Response (AWS, Azure or GCP)

• Broader experience across additional research domains such as cloud security, red team and penetration testing

• Ability to perform manual or automated source-code analysis (SAST) to identify vulnerabilities at the development level

• Basic to intermediate capability in reverse engineering malicious binaries to extract host and network-based indicators during investigations

אודות OP Innovate
פרופיל החברה · בקרוב

ביקורות עובדים · בקרובעוד משרות ב-OP Innovate

שאלות על המשרה

  • המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
דומות וקשורות
OP Innovate
פורסם אתמול · 0 מועמדים
בדקו את ההתאמה