Incident Response Practice Lead (Hands-on)
Up Security (Formerly Wake-up Cyber)
Tel Aviv District
The Role
This position leads complex cyber incidents from initial triage through containment, eradication, recovery, and post-incident review. Day-to-day responsibilities include digital forensics, threat hunting, compromise assessments, and building IR methodologies, playbooks, and service offerings while working directly with clients and executives under pressure.
Skills & Experience
Candidates should bring five to nine years in cybersecurity, including three to six years of hands-on DFIR or CSIRT experience. Practical knowledge of Windows, Active Directory, Entra ID, cloud environments, endpoints, and identity-based attack techniques is essential to performing the technical investigations this role demands.
Who It Suits
This role suits a senior incident response professional who combines deep technical capability with the ambition to build and eventually lead a growing practice. It appeals to someone comfortable owning an engagement end-to-end, shaping methodology from the ground up, and working across cloud, application, and identity security disciplines.





