Cyber Security Automation Engineer

אינטנסיטי גלובלPetah Tikvadrushimpublished 09/08/2026
Must-have:PythonAzureCloudSecurity
Machine translation — original language: Hebrew.Show original

A leading company in the industry and security sector is looking for a Cyber Security Automation Engineer for a role that combines Incident Response, SOC, and the development of automations for cyber incident response processes.

The role includes working on SIEM / SOAR systems, developing and maintaining automations and Playbooks for cyber incident response, integration between security systems, and improving incident and alert handling processes.

The role is particularly suitable for a candidate coming from the SOC / Incident Response worlds, who has accumulated experience in handling cyber incidents and alerts, and subsequently gained experience in developing response automations.

Responsibilities:

  • Handling and investigating cyber incidents and alerts at Tier 1–2 levels, with an advantage for Tier 3 level experience.
  • Performing Incident Response and investigating cyber incidents.
  • Development, maintenance, and improvement of Playbooks and automations in SOAR systems.
  • Developing automations using Python and scripts.
  • Performing integrations between security systems using APIs.
  • Working with SIEM / XDR / SOAR systems.
  • Automation of Enrichment, Containment, and Response processes.
  • Improving SOC workflows and reducing cyber incident response time.
  • Collaboration with SOC, Incident Response, and information security teams.
  • At least 2–4 years of experience* in Cyber Security / SOC / Incident Response.
  • Practical experience in handling and investigating cyber incidents and alerts.
  • Experience working as a SOC Analyst, at least at Tier 1–2 levels.
  • Experience in Incident Response (IR) – Mandatory.
  • At least one year of experience in developing automations for cyber incident response processes – Mandatory.
  • Experience working with SIEM / SOAR systems.
  • Experience in script/automation development in Python.
  • Experience working with APIs and integrations between security systems – Significant advantage.
  • Experience with one or more of the following technologies: Azure, Splunk, Palo Alto.
  • Very good English level.
  • Israeli citizenship – Mandatory.

Advantages

  • Experience with Cortex XSOAR / XSIAM / Cortex XDR.
  • Experience with Splunk / Microsoft Sentinel / QRadar.
  • Experience in Digital Forensics / DFIR.
  • Experience in Threat Hunting or Detection Engineering.
  • Experience in large Enterprise environments or security environments.
  • Experience in developing complex Playbooks in SOAR.
  • Familiarity with Cloud environments, with an emphasis on Azure.
  • Professional certifications in the cyber field – Advantage.