Эта вакансия пока только на английском.

← Назад к вакансиям
P

SecOps Engineer

Papaya Global·Израиль·
В офисеПолная занятостьSecurity EngineeringEnterprise Software

Hands-on opportunity to strengthen security operations across cloud, endpoints, identities, and applications. The role covers detection engineering, alert investigation, threat hunting, digital forensics, incident response, threat intelligence, and response automation. Occasional on-call and after

Обязанности

  • Operate and improve SIEM, identity, endpoint, cloud, and application telemetry, including log onboarding, health monitoring, and coverage remediation.
  • Investigate alerts and threats through triage, host and artifact analysis, digital forensics, incident response, and threat hunting.
  • Lead incident response from detection through containment, recovery, and post-incident review.
  • Build and tune detection rules, SIEM queries, and dashboards for high-risk attack paths.
  • Convert threat intelligence into detections, hunts, and control improvements.
  • Automate response and enrichment workflows using scripting, AI tools, and SOAR platforms.
  • Report incident metrics, including root cause, impact, and remediation status.
  • Support security reviews of vendors, SaaS platforms, and internal applications.
  • Partner with engineering to validate security controls and improve threat detection and mitigation.
  • Monitor and respond to risks involving AI-enabled workflows, agentic tooling, and integrations.
  • Develop and evaluate AI-assisted investigation workflows for evidence correlation, root-cause analysis, timeline reconstruction, and case documentation.

Требования

  • At least 3 years of hands-on experience in security operations, incident response, detection engineering, or a similar cybersecurity role.
  • Practical experience with IT security, endpoint protection, identity security, and security operations.
  • Hands-on experience with SIEM alert triage, investigations, query development, dashboards, and detection tuning.
  • Practical cloud security experience with identity, logging, network, and workload security concepts.
  • Experience with incident response and DFIR workflows, including host and artifact analysis on Windows, Linux, and macOS.
  • Proficiency in Python, Bash, PowerShell, or similar scripting languages.
  • Familiarity with SOAR platforms, automated playbooks, alert enrichment, and response workflows.
  • Strong written and verbal communication skills for cross-functional collaboration.
  • Familiarity with AI tools and experience applying them to security investigations.
  • Willingness to participate in occasional after-hours response for material security incidents.

Будет плюсом

  • Experience building detection and incident-response capabilities in a growing or cloud-native organization.
  • Experience with threat hunting, malware analysis, host forensics, and adversary tactics, techniques, and procedures.
  • Experience with containerized or cloud-native architectures, identity providers, and modern endpoint security platforms.

Соответствие

Больше возможностей

Похожие вакансии

Новые вакансии в категории «Security Engineering».

Создайте профиль, чтобы увидеть оценку соответствия.

Создайте профиль, чтобы увидеть оценку соответствия.

Создайте профиль, чтобы увидеть оценку соответствия.

Создайте профиль, чтобы увидеть оценку соответствия.