SOC / NOC Team Lead
- תל אביב
- משרה קבועה
- משרה מלאה
- Establish and enforce processes, procedures and workflows to detect, analyze, contain and eliminate incidents efficiently
- Prepare incident response plans and playbooks for different types of operational and Security incidents
- Communicate with stakeholders and resolve incidents both security and operational as part of incident response activities
- Identify root causes of incidents and recommend corrective actions to prevent future ones
- Optimize and configure security and observability tools to ensure comprehensive visibility and actionable insights across the entire environment.
- Define key performance indicators (KPIs) for your security and operations monitor metrics
- Prepare regular reports on SOC /NOC activities, incident trends and metrics for senior management and stakeholders
- Lead a team of NOC and SOC analysts operating 24/7, ensuring real-time monitoring of network/system health, application performance, and security events.
- Drive operational excellence in detecting, troubleshooting, and resolving infrastructure and connectivity issues (e.g., latency, packet loss, hardware failures, etc.).
- Implement and maintain incident response protocols and playbooks for network outages, service degradations, and cybersecurity incidents.
- Ensure coordination between IT, Infrastructure, Security, and DevOps during escalations and major incidents.
- Own and evolve our observability stack: monitoring tools (e.g., Prometheus, Grafana), SIEM platforms, log aggregation, alerting systems.
- Define KPIs for both network operations and security metrics (MTTR, SLA adherence, false positives, escalation rates).
- Deliver reports and dashboards on incident trends, operational stability, and threat landscapes to management.
- Lead post-incident reviews (PIRs), identifying root causes and preventive actions.
- Proven leadership experience in a SOC or related information security role
- 5+ years as a Security Operations Centre (SOC) analyst IR analyst or SOC Engineer
- Hands-on capabilities - research and leading incident response teams
- Deep understanding of network troubleshooting, TCP/IP stack, DNS, VPNs, routing, and connectivity issues.
- Strong working knowledge of Linux systems, including command-line tools and system logs.
- Strong analytical and problem-solving abilities, with keen attention to detail
- Experience in building a SOC team, including staffing, recruitment, supervision, development and evaluations
- Lead, mentor, and develop a high-performing security operations team, ensuring they have the necessary skills and resources
- Strong foundation in cybersecurity principles, practices, and technologies; threat intelligence/intrusion detection/prevention systems
- Continuous learning and adaptability; commitment and continuous learning and stay up to date with industry trends, emerging threats, security best practices
- Passion for continuous learning and process improvement.
- Experience with the following tools and technologies: Splunk, Sentinel, CrowdStrike, Grafana, AWS, Zabbix
Mploy