Incident response researcher/ DFIR
פורסם 6 באוג׳ · 0 מועמדים
התפקיד במילים פשוטות
תפקיד זה כולל השתתפות בחקירות תגובה לאירועי סייבר ופורנזיקה ברשתות ומארחים, לצד ביצוע ציד איומים (Threat Hunting) יזום בארגונים. העבודה כוללת ניתוח לוגים, זיהוי אינדיקטורים של תקיפה (IOCs), פיתוח כלי חקירה והפקת דוחות מפורטים עבור הלקוחות.
- At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry)
- Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework)
- Familiarity with cloud infrastructure investigation, specifically Microsoft 365 / Azure AD environments
- Familiarity with AWS CloudTrail
- Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים לבעלי ניסיון של לפחות 3 שנים בתחום ה-DFIR או חקירת איומי סייבר מתקדמים, בעלי היכרות מעמיקה עם מערכות הפעלה, חקירת ענן (כגון M365/Azure AD) ורשתות. הוא פחות מתאים למי שחסר ניסיון טכני מעשי בחקירת אירועי סייבר או ניתוח ממצאים פורנזיים.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןWe are a leading, innovative and fast-growing cybersecurity company.
With extensive experience supporting organizations (in Israel and globally) during complex attacks, we are dedicated to being ready when challenges strike.
We are looking for DFIR professional to join our team.
Job Description
* Participate in forensic and incident response investigations, including large-scale sophisticated attacks, conduct log analysis, host and network-based forensics.
* Participate in threat hunting: proactively hunt for targeted attacks and new emerging threats in client’s networks; as well as security assessments and simulations.
* Identify indicators of compromise (IOCs) and tools, tactics, and procedures (TTPs) to help ascertain whether and how breaches have occurred.
* Utilize and develop tools and methodologies to improve the existing investigative and hunting technological stack.
* Collaborate with IT and Security teams during investigations.
* Generate and present a comprehensive and professional report of findings from investigations.
Main Requirements
* At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry).
* Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework).
* Familiarity with cloud infrastructure investigation, specifically **Microsoft 365 / Azure AD** environments and AWS CloudTrail.
* Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis.
* Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix), including host-based forensics and experience with analyzing OS artifacts (MFT, Registry, Event Logs, Volatile Memory).
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry), Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework), Familiarity with cloud infrastructure investigation, specifically Microsoft 365 / Azure AD environments, Familiarity with AWS CloudTrail, Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis