עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
Cyber Incident Response Team Lead (Tier 3)
Hybrid | Central Israel
A leading enterprise organization is looking for an experienced Cyber Incident Response Team Lead to join its cybersecurity division.
This is a hands-on leadership role focused on leading a Tier 3 Incident Response team responsible for cyber investigations, threat hunting, detection engineering, and incident response operations. (This is not a SOC Manager position.)
What You'll Do
- Lead and mentor a Tier 3 Incident Response team, driving technical excellence and operational priorities.
- Manage complex cyber incidents, digital forensics investigations, and proactive threat hunting activities.
- Design, develop, and optimize detection logic across EDR and SIEM platforms.
- Oversee the organization's external SOC service, ensuring investigation quality, SLA compliance, and continuous improvement.
- Build and improve detection playbooks, incident response workflows, and investigation methodologies.
- Evaluate emerging security technologies and lead technical POCs.
- Improve security visibility by ensuring effective logging and monitoring across enterprise environments.
- Translate threat intelligence and MITRE ATT&CK techniques into actionable detection content.
- Lead Purple Team initiatives and Breach & Attack Simulation exercises.
- Collaborate closely with Infrastructure, Cloud, IT, Cyber Intelligence, and business stakeholders.
Requirements
- 3+ years of hands-on experience in Tier 3 Incident Response.
- Previous experience leading or mentoring a technical cybersecurity team.
- Strong experience with EDR technologies and detection engineering.
- Experience working with SIEM platforms such as Microsoft Sentinel or Splunk, including KQL or SPL.
- Experience managing or collaborating with external SOC providers.
- Strong knowledge of Windows, Linux, Active Directory, Entra ID, networking, and enterprise infrastructure.
- Familiarity with AI-driven cyber threats and modern defensive techniques.
- Understanding of Autonomous SOC concepts.
Nice to Have
- Experience with MITRE ATT&CK framework and detection engineering.
- Background in Red Team, Purple Team, or Penetration Testing.
- Experience with Breach & Attack Simulation (BAS) platforms.
- Relevant certifications such as GCIH, GCFA, GCIA, OSCP, CRTO, or similar.
- Strong English communication skills.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.