← Back to jobs
A

Security Operations Analyst, Detection and Response

Aidoc·Israel·en
HybridFull-timeSecurity Solutions EngineeringMedical DevicesHealthcare Software

Join a clinical AI company as a hands-on Security Operations Analyst protecting cloud environments, products, corporate systems, and sensitive healthcare data. The role focuses on SIEM investigations, incident response, detection improvement, and cross-functional security operations in a hybrid Tel⁣

Responsibilities

  • Investigate SIEM alerts across cloud, product, identity, endpoint, and SaaS environments
  • Distinguish false positives from genuine threats and prioritize cases by risk and impact
  • Escalate high-risk findings with clear summaries of impact and required actions
  • Collect evidence, support containment, track remediation, and maintain investigation records
  • Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality
  • Collaborate with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders

Requirements

  • At least 2 years of experience in security operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role
  • Hands-on SIEM investigation experience, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation
  • Experience analyzing telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments
  • Familiarity with cloud-native technologies including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD
  • Understanding of attack techniques such as credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfiguration
  • Experience investigating identity and endpoint activity involving SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious users or devices
  • Ability to use KQL, SPL, SQL, Python, Bash, or similar query and scripting languages
  • Understanding of incident response workflows, evidence collection, remediation tracking, case management, and post-incident review
  • Strong analytical judgment, documentation, communication, ownership, and ability to escalate risks appropriately

Nice to have

  • Experience in healthcare, healthtech, medical devices, digital health, or regulated software
  • Knowledge of HIPAA, GDPR, SOC 2, ISO 27001, NIST CSF, or similar frameworks
  • Familiarity with MITRE ATT&CK, detection logic, attacker behavior, and investigation playbooks
  • Experience with threat hunting, detection engineering, malware analysis, forensics, or advanced incident response
  • Experience with SOAR, case management, threat intelligence, detection-as-code, or SOC automation
  • Experience improving SOC metrics and collecting audit-ready evidence for sensitive data environments

Benefits

  • Hybrid work from offices in Tel Aviv
  • Daily breakfasts and lunches
  • Stocked kitchen and meal card
  • Employee gym, Pilates, yoga, and functional workout classes
  • Compensation package and benefits
  • Inclusive equal-opportunity workplace

Relevance

More opportunities

Similar jobs

The newest open roles in Security Solutions Engineering.

Questions, answered

Frequently asked questions

Security Operations Analyst, Detection and Response | CVZilla