Security Operations Analyst, Detection and Response
Join a clinical AI company as a hands-on Security Operations Analyst protecting cloud environments, products, corporate systems, and sensitive healthcare data. The role focuses on SIEM investigations, incident response, detection improvement, and cross-functional security operations in a hybrid Tel
Responsibilities
- Investigate SIEM alerts across cloud, product, identity, endpoint, and SaaS environments
- Distinguish false positives from genuine threats and prioritize cases by risk and impact
- Escalate high-risk findings with clear summaries of impact and required actions
- Collect evidence, support containment, track remediation, and maintain investigation records
- Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality
- Collaborate with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders
Requirements
- At least 2 years of experience in security operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role
- Hands-on SIEM investigation experience, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation
- Experience analyzing telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments
- Familiarity with cloud-native technologies including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD
- Understanding of attack techniques such as credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfiguration
- Experience investigating identity and endpoint activity involving SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious users or devices
- Ability to use KQL, SPL, SQL, Python, Bash, or similar query and scripting languages
- Understanding of incident response workflows, evidence collection, remediation tracking, case management, and post-incident review
- Strong analytical judgment, documentation, communication, ownership, and ability to escalate risks appropriately
Nice to have
- Experience in healthcare, healthtech, medical devices, digital health, or regulated software
- Knowledge of HIPAA, GDPR, SOC 2, ISO 27001, NIST CSF, or similar frameworks
- Familiarity with MITRE ATT&CK, detection logic, attacker behavior, and investigation playbooks
- Experience with threat hunting, detection engineering, malware analysis, forensics, or advanced incident response
- Experience with SOAR, case management, threat intelligence, detection-as-code, or SOC automation
- Experience improving SOC metrics and collecting audit-ready evidence for sensitive data environments
Benefits
- Hybrid work from offices in Tel Aviv
- Daily breakfasts and lunches
- Stocked kitchen and meal card
- Employee gym, Pilates, yoga, and functional workout classes
- Compensation package and benefits
- Inclusive equal-opportunity workplace