DFIR
Cye
Herzliya, Tel Aviv District
The Role
This position sits within an incident response team, handling the full lifecycle of cyber incidents on behalf of clients worldwide. Day to day work spans detection, containment, eradication and recovery, digital forensics investigations across Windows and Linux platforms, cloud environments, and proactive threat hunting to identify malicious activity before it escalates.
Skills & Experience
Candidates should bring two to three years of hands-on experience in incident response and digital forensics, including cloud platforms such as Azure and AWS. Proficiency with Splunk, Elasticsearch, SQL or VQL is expected, alongside a solid grounding in threat hunting models, TTP analysis, and IoC extraction and mapping.
Who It Suits
This role suits a technically driven investigator who thrives under pressure and enjoys working across both reactive incidents and proactive research. Someone comfortable engaging directly with senior client stakeholders, including CISOs, and collaborating closely with red team, cyber threat intelligence, and architecture colleagues will feel at home here.





