עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
Founded in 2014, OP Innovate specializes in protecting global enterprises from the ever-evolving challenges of organizational cybersecurity. With a deep-rooted expertise in cyber research, penetration testing, digital forensics, incident response and training. Headquartered in Israel, OP Innovate stands at the forefront of the cybersecurity industry, collaborates with leading experts and leverages state-of-the-art knowledge to address critical cybersecurity concerns. This commitment enables both the company and its clients to stay ahead in an increasingly complex digital landscape.
We are looking for a DFIR Specialist to join our team. In this position, you will be leading high-severity Digital Forensics and Incident Response (DFIR) investigations and take part as a technical expert in efforts to develop cyber security solutions. You will be at the forefront of cyber security, investigating breaches to contain and eradicate threats, while also actively working on developing mechanisms that help decrease chances of those incidents from recurring.
Your work will directly impact the digital resilience of organizations across various sectors, shaping both their active defense and proactive security posture.
Requirements:
Lead end-to-end Incident Response (IR) engagements - from initial alert triage and containment to eradication and post-incident recovery
Performing deep-dive disk, memory, and network forensics across Windows, Linux, and macOS environments
Identify, analyze, and reverse-engineer threat actor tactics designed to evade, neutralize, or blind EDR/XDR agents (e.g., unhooking, direct syscalls, bring-your-own-vulnerable-driver/BYOVD attacks, process hollowing, and living-off-the-land techniques)
Perform meticulous post-incident analysis to verify complete eradication of attacker presence. Ensure operating systems are fully cleaned of hidden backdoors, persistence mechanisms (WMI subscriptions, scheduled tasks, registry modifications, custom services), and rootkits
Providing urgent response to confirmed security breaches requiring immediate action at the highest level of escalation
Cleanly collect and maintain a defensible chain of custody for digital evidence, ensuring strict compliance with legal, evidentiary, and regulatory standards
Produce detailed, high-quality technical reports and incident timelines for technical, management, and legal stakeholders
Skills and Experience:
4+ years of hands-on experience in DFIR, threat hunting, or a closely related security operations role
Deep familiarity with forensic/IR tools, such as Velociraptor, Thor/Asgard/Loki, Volatility, Redline, EDR/XDR platforms, Autopsy, Eric Zimmerman's Tools
Solid foundational understanding of operating system internals (Windows Registry, Linux syslogs, etc.) and network traffic analysis
A self-driven commitment to researching emerging adversary tactics, techniques, procedures and zero-day vulnerabilities, ensuring both defensive and offensive strategies stay ahead of modern threat actors
Proven ability to drive projects autonomously from start to finish, combined with a highly collaborative mindset that thrives when sharing knowledge and tackling incidents as a cohesive team
A strong commitment to high ethical standards and professional integrity when handling highly sensitive data, active breaches, and 0-day style vulnerabilities
Recognized industry credentials: DFIR: GCFA, GCFE, GNFA, GREM, or equivalent. Offensive: OSWE, OSCP, GWAPT, BSCP, eWPTX, or equivalent
Excellent spoken and written communication skills in both Hebrew and English
Advantages:
Cloud Incident Response (AWS, Azure or GCP)
Broader experience across additional research domains such as cloud security, red team and penetration testing
Ability to perform manual or automated source-code analysis (SAST) to identify vulnerabilities at the development level
Basic to intermediate capability in reverse engineering malicious binaries to extract host and network-based indicators during investigations
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
אונליין