← Back to jobs
B

Cyber Defense Engineer

BeyondTrust·Tel Aviv, Israel·en
Not specifiedFull-timeSecurity OperationsCybersecurityEnterprise Software

Join a cyber defense operations team protecting enterprise infrastructure and customer-facing products. Monitor and investigate security events, respond to incidents, improve detection coverage, and use AI-assisted tools to support security workflows.

Responsibilities

  • Monitor and triage alerts across SIEM, EDR, and CSPM platforms for corporate and product environments.
  • Investigate security alerts, assess scope and severity, and escalate when needed.
  • Use AI-assisted tools for triage, enrichment, and investigation.
  • Track alerts through their lifecycle and document findings in ticketing and case management systems.
  • Participate in incident response from detection through remediation, including evidence collection, forensic analysis, root cause analysis, and stakeholder communication.
  • Investigate SIEM, endpoint, cloud, identity, and network data sources and execute incident response runbooks.
  • Maintain evidence handling and chain-of-custody procedures.
  • Prepare incident summaries and post-incident reports.
  • Design, implement, and tune SIEM and EDR detection rules; reduce false positives and address coverage gaps.
  • Translate threat intelligence into detection content and maintain coverage mapped to MITRE ATT&CK.
  • Validate detection logic through hypothesis-driven threat hunts.
  • Evaluate and improve AI and automation capabilities, including prompts, agent workflows, and LLM-based pipelines.
  • Partner with engineering teams on log ingestion, data quality, and tool integrations.
  • Maintain shift handoffs, operational notes, runbooks, playbooks, and standard procedures.
  • Participate in an on-call rotation, tabletop exercises, purple team activities, and post-incident reviews.
  • Track operational security metrics and identify improvements.

Requirements

  • At least 2 years of experience in a SOC, security operations, or incident response role.
  • Understanding of MITRE ATT&CK, network protocols, and endpoint behavior.
  • Experience with at least one SIEM platform and familiarity with search or detection queries.
  • Familiarity with EDR platforms and cloud environments; IaaS experience preferred.
  • Comfort using AI systems in security workflows.
  • Strong written communication skills for technical and non-technical audiences.

Nice to have

  • Experience leading complex incident response engagements.
  • Experience with identity and access management platforms and cloud security posture management tools.
  • Scripting or automation skills applied to security workflows.
  • Familiarity with SOAR or orchestration tools.
  • Experience with AI agent architectures, LLM-based automation, or prompt engineering for security.
  • Experience with threat intelligence programs or detection-as-code pipelines.
  • Knowledge of privileged access management and related threat actors.
  • Experience evaluating emerging technologies in production security environments.

Relevance

More opportunities

Similar jobs

The newest open roles in Security Operations.

Questions, answered

Frequently asked questions

Cyber Defense Engineer – Security Operations and Incident Response | CVZilla