Security Operations Engineer
- רעננה
- משרה קבועה
- משרה מלאה
- Lead the implementation and ongoing operations of the company-wide SIEM solution
- Build and tune detection rules, alerts, and incident workflows
- Monitor cloud (AWS, GCP) and SaaS environments for anomalies and threats
- Integrate logs from production systems, cloud platforms, SaaS tools, and on-prem infrastructure
- Respond to security incidents and perform forensic investigations
- Partner with Engineering, IT, and GRC to ensure logging and alerting coverage
- Continuously improve our detection capabilities and response processes
- Ensure monitoring meets compliance frameworks (SOC2, PCI-DSS, etc.)
- 4-7 years in cybersecurity, including 2+ years in a security monitoring, SecOps, or blue team role
- Experience deploying and managing SIEM platforms
- Hands-on knowledge of cloud infrastructure security in AWS and GCP
- Familiarity with SaaS security monitoring (Okta, Google Workspace, M365, Salesforce,etc.)
- Experience with scripting or automation (e.g., Python, Bash, Terraform, etc.)
- Strong understanding of incident response processes
- Ability to work independently and lead projects end-to-end
- Nice to have: Experience with SOAR platforms, MITRE ATT&CK, and threat intel feeds
- Work experience from high-tech companies
Mploy