IR Team Lead
Must-have:AI
Machine translation — original language: Hebrew.Show original
A leading financial corporation is looking for an IR Team Lead for a full-time position in Ramat Gan.
As part of the role:
- Management and leadership of the IR team and the work plan
- Leading complex cyber investigations (Tier 3)
- Forensics and Threat Hunting
- Development and improvement of detection and protection capabilities (EDR, SIEM, Playbooks)
- Management of external SOC activity, SLA, and quality control
- Leading Purple Team exercises
- Attack simulations (BAS) and innovation initiatives
- At least 3 years of experience in cyber incident investigation at Tier 3 level - Mandatory
- Experience in managing a technical team - Mandatory
- Experience working with EDR, SIEM (Sentinel / Splunk) and writing KQL / SPL queries - Mandatory
- Experience in managing or working with an external SOC - Mandatory
- Deep familiarity with AI worlds in terms of threats and defense - Mandatory
- Broad understanding of IT infrastructures, networks, Windows/Linux, and identities (AD / Entra ID) - Mandatory
- Experience in MITRE ATT&CK, Purple Team / Red Team / BAS or Pentest - Advantage
- Relevant certifications (GCIH, GCFA, GCIA, OSCP, CRTO, etc.) - Advantage
- High level of English