DFIR Expert
Herzliya, Israel
Applications have closed
CYE
CYE's optimized cyber risk management helps you gain visibility, quantify cyber risk, prioritize mitigation, and effectively communicate with stakeholders.
CYE's DFIR team is responsible for responding to our clients' cyber incidents and crises. Our group is expanding. If you see yourself in the front line of the cybersecurity domain as a data forensic and incident response (DFIR) talent, your place is with us. As a DFIR team member, you will participate in hands-on security research and investigations, helping our customers understand and mitigate cyber threats and attacks.
Responsibilities
- Perform incident response lifecycle and real-time activities, including detection and analysis, containment and eradication, and recovery
- Perform incident response in a cloud environment (Azure, AWS, etc.).
- Perform digital forensics investigations
- Research and analyze tactics, techniques, and procedures (TTPs) used by malicious actors
- Perform hunt-evil and find-evil activities for proactively detecting attacks
- Work closely with our in-house red team, CTI, and cyber architect teams
- Work closely with worldwide companies, CISOs, and technology experts
Qualifications
- 3 years of experience as a DFIR team member
- Experience with performing digital forensics in a cloud environment
- Experience with performing digital forensics of Windows-based and/or Linux-based platforms, network forensics, and analysis
- Thorough understanding of threat hunting models, as well as cyber threat intelligence, including TTP and IoCs extraction and mapping
- Experience with research and data analysis of large DBs via Splunk, Elasticsearch, SQL, or VQL
- Strong understanding of targeted attacks; able to create customized tactical remediation plans
- Good written and verbal English communication skills
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Tags: AWS Azure Cloud DFIR Elasticsearch Forensics Incident response Linux Red team SaaS Splunk SQL Threat intelligence TTPs Windows
Region:
Middle East
Country:
Israel
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsSenior Cloud Security Engineer jobsInformation System Security Officer jobsSenior Cybersecurity Engineer jobsInformation Security Specialist jobsInformation Security Manager jobsSenior Network Security Engineer jobsSecurity Consultant jobsCyber Security Specialist jobsIT Security Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Penetration Tester jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsSystems Engineer jobsChief Information Security Officer jobsSystems Administrator jobsStaff Security Engineer jobsInformation System Security Officer (ISSO) jobsPrincipal Security Engineer jobsThreat Intelligence Analyst jobsSenior Product Security Engineer jobsCloud Security Architect jobsInformation Systems Security Engineer jobs
GDPR jobsEncryption jobsPowerShell jobsDevSecOps jobsEDR jobsSaaS jobsIDS jobsSplunk jobsSDLC jobsRMF jobsIPS jobsTop Secret jobsSQL jobsIntrusion detection jobsBash jobsThreat detection jobsActive Directory jobsCompTIA jobsDoDD 8570 jobsITIL jobsOWASP jobsDocker jobsBanking jobsCRISC jobsUNIX jobs
Finance jobsTCP/IP jobsClearance Required jobsGIAC jobsCISO jobsIndustrial jobsTerraform jobsHIPAA jobsIT infrastructure jobsSOC 2 jobsSANS jobsJavaScript jobsVPN jobsOSCP jobsCCSP jobsMITRE ATT&CK jobsSOAR jobsJira jobsDNS jobsSOX jobsData Analytics jobsPolygraph jobsNIST 800-53 jobsGCIH jobsSecurity strategy jobs