Эта вакансия пока только на английском.

← Назад к вакансиям
A

Security Operations Analyst, Detection and Response

Aidoc·Израиль·en
ГибридПолная занятостьSecurity Solutions EngineeringMedical DevicesHealthcare Software

Join a clinical AI company as a hands-on Security Operations Analyst protecting cloud environments, products, corporate systems, and sensitive healthcare data. The role focuses on SIEM investigations, incident response, detection improvement, and cross-functional security operations in a hybrid Tel⁣

Обязанности

  • Investigate SIEM alerts across cloud, product, identity, endpoint, and SaaS environments
  • Distinguish false positives from genuine threats and prioritize cases by risk and impact
  • Escalate high-risk findings with clear summaries of impact and required actions
  • Collect evidence, support containment, track remediation, and maintain investigation records
  • Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality
  • Collaborate with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders

Требования

  • At least 2 years of experience in security operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role
  • Hands-on SIEM investigation experience, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation
  • Experience analyzing telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments
  • Familiarity with cloud-native technologies including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD
  • Understanding of attack techniques such as credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfiguration
  • Experience investigating identity and endpoint activity involving SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious users or devices
  • Ability to use KQL, SPL, SQL, Python, Bash, or similar query and scripting languages
  • Understanding of incident response workflows, evidence collection, remediation tracking, case management, and post-incident review
  • Strong analytical judgment, documentation, communication, ownership, and ability to escalate risks appropriately

Будет плюсом

  • Experience in healthcare, healthtech, medical devices, digital health, or regulated software
  • Knowledge of HIPAA, GDPR, SOC 2, ISO 27001, NIST CSF, or similar frameworks
  • Familiarity with MITRE ATT&CK, detection logic, attacker behavior, and investigation playbooks
  • Experience with threat hunting, detection engineering, malware analysis, forensics, or advanced incident response
  • Experience with SOAR, case management, threat intelligence, detection-as-code, or SOC automation
  • Experience improving SOC metrics and collecting audit-ready evidence for sensitive data environments

Условия и преимущества

  • Hybrid work from offices in Tel Aviv
  • Daily breakfasts and lunches
  • Stocked kitchen and meal card
  • Employee gym, Pilates, yoga, and functional workout classes
  • Compensation package and benefits
  • Inclusive equal-opportunity workplace

Соответствие

Больше возможностей

Похожие вакансии

Новые вакансии в категории «Security Solutions Engineering».

Создайте профиль, чтобы увидеть оценку соответствия.

Создайте профиль, чтобы увидеть оценку соответствия.

Создайте профиль, чтобы увидеть оценку соответствия.

Создайте профиль, чтобы увидеть оценку соответствия.