SecOps Engineer
Papaya Global
שכר לא צויןHerzliya, Herzliya, Israel, מרחוקמידמשרה מלאה
משרה חיצונית, ההגשה באתר החברהאושר שהמשרה פתוחה לפני 11 שעות
Join Papaya Global’s cybersecurity team to defend the organization across cloud, endpoints, identities, and applications. You will investigate threats, improve security operations, and build detection and response capabilities.
מה תעשו
- Operate and improve SIEM and security telemetry, including log onboarding and coverage-gap remediation.
- Investigate alerts and threats through triage, DFIR, and threat hunting.
- Lead incident response from detection through recovery and post-incident review.
- Build and tune detection rules, SIEM queries, and dashboards; turn threat intelligence into detections and control improvements.
- Automate response and enrichment workflows using scripting, AI tools, or SOAR; report incident metrics.
- Support security reviews and monitoring for vendors, SaaS platforms, applications, and AI-enabled workflows.
דרישות
- 3+ years of hands-on experience in security operations, incident response, detection engineering, or a similar cybersecurity role.
- Practical experience with IT security, endpoint protection, identity security, and security operations.
- Hands-on experience with SIEM platforms, including alert investigation, query development, dashboards, and detection tuning.
- Understanding of cloud security and practical experience with at least one major cloud platform.
- Experience with incident response and DFIR, including host and artifact analysis on Windows, Linux, and macOS.
יתרון
- Experience building detections and incident-response capability in a growing or cloud-native organization.
- Experience with threat hunting, malware analysis, host forensics, and mapping activity to adversary tactics and techniques.
- Experience with containerized or cloud-native architectures, identity providers, and modern endpoint security platforms.
תנאי סף
- 3+ years of relevant hands-on cybersecurity experience
- Ability and willingness to participate in occasional after-hours incident response when required
- Proficiency in Python, Bash, PowerShell, or a similar scripting language
- Hands-on experience with SIEM platforms
SIEMIncident ResponseDFIRThreat HuntingCloud SecurityPythonBashPowerShell