IR Team Lead - Cyber Incident Response (Tier 3)
פורסם לפני 5 ימים · 0 מועמדים
התפקיד במילים פשוטות
תפקיד זה כולל הובלת צוות תגובה לאירועי סייבר (Tier 3) בחברת ביטוח מובילה, תוך ניהול חקירות סייבר מקצה לקצה וביצוע ציד איומים ופורנזיקה דיגיטלית. העבודה משלבת ניהול טכני, פיתוח ושיפור יכולות זיהוי ב-EDR, עבודה מול SOC חיצוני והובלת יוזמות Purple Team.
- 3+ years of experience investigating Tier 3 cyber incidents
- Experience leading a technical team
- Hands-on experience creating and tuning EDR detection rules
- Experience working with an external SOC, including SLA management and quality assurance
- Experience with SIEM platforms (Microsoft Sentinel or Splunk) and writing KQL or SPL queries
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים לבעלי ניסיון של 3 שנים לפחות בחקירת אירועי סייבר ברמת Tier 3 וניסיון בהובלת צוות טכני. הוא פחות מתאים למי שאינו בעל רקע מעשי ביצירת חוקי גילוי ב-EDR ועבודה עם מערכות SIEM.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןJoin one of Israel's leading insurance companies as an IR Team Lead, leading the organization's Tier 3 Cyber Incident Response team. This is a strategic, hands-on role combining technical leadership, advanced cyber investigations, development of detection capabilities, and continuous innovation in Detection & Response.
What You'll Do
• Lead the Tier 3 IR team, manage priorities, and drive end-to-end cyber investigations, including Digital Forensics, Threat Hunting, and Incident Response.
• Develop and enhance EDR detection capabilities, improve playbooks, and translate Threat Intelligence and MITRE TTPs into effective detection controls.
• Manage the external SOC, lead Purple Team and Breach & Attack Simulation initiatives, evaluate new security technologies, and collaborate with IT, Infrastructure, Cloud, and Cyber teams.
Requirements
• 3+ years of experience investigating Tier 3 cyber incidents - Must
• Experience leading a technical team - Must
• Hands-on experience creating and tuning EDR detection rules - Must
• Experience working with an external SOC, including SLA management and quality assurance - Must
• Experience with SIEM platforms (Microsoft Sentinel or Splunk) and writing KQL or SPL queries - Must
• Strong understanding of AI technologies, the evolving cyber threat landscape, and Autonomous SOC concepts - Must
• Strong knowledge of IT infrastructure, Networking, Windows, Linux, Active Directory, and Microsoft Entra ID - Must
• Experience with MITRE ATT&CK, Red Team, Purple Team, Penetration Testing, or Breach & Attack Simulation - Significant Advantage
• Relevant certifications such as GCIH, GCFA, GCIA, OSCP, or CRTO - Significant Advantage
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 3+ years of experience investigating Tier 3 cyber incidents, Experience leading a technical team, Hands-on experience creating and tuning EDR detection rules, Experience working with an external SOC, including SLA management and quality assurance, Experience with SIEM platforms (Microsoft Sentinel or Splunk) and writing KQL or SPL queries