DFIR Expert (Lead)
UST
תל אביב -יפו, מחוז תל אביב
The Role
This position leads complex digital forensics investigations and incident response engagements, serving as the senior escalation point for confirmed breaches. Day-to-day responsibilities span forensic analysis across file systems, memory, and networks, alongside containment and recovery activities, tool development, client communications, and contributing to service growth.
Skills & Experience
Candidates need three or more years in DFIR, threat hunting, SOC, or information security, with deep knowledge of Windows and Linux internals, network protocols, and intrusion techniques. Proficiency with EDR and SIEM platforms is expected, as is experience conducting both static and dynamic malware analysis to identify actionable indicators of compromise.
Who It Suits
This role suits a technically accomplished security professional who is equally comfortable leading a response effort and working hands-on at a forensic level. Someone who builds automation to improve investigation speed, communicates clearly with clients under pressure, and takes genuine ownership of both the technical work and the broader service will thrive here.





