DFIR
Cyesec
הרצליה, מחוז תל אביב
The Role
This position involves leading and executing the full incident response lifecycle — from detection and containment through to recovery — across both cloud and on-premises environments. Day to day, practitioners conduct digital forensics investigations, perform proactive threat hunting, analyse adversary TTPs, and collaborate closely with red team, threat intelligence, and architecture colleagues.
Skills & Experience
Candidates should bring two to three years of hands-on DFIR experience, including forensic investigation of Windows and Linux systems, network forensics, and cloud platforms such as Azure or AWS. Proficiency with data analysis tools — Splunk, Elasticsearch, SQL, or VQL — alongside solid knowledge of threat hunting models, IoC extraction, and TTP mapping is expected.
Who It Suits
This role suits an analytically minded security professional who thrives in fast-paced, high-stakes environments and is comfortable engaging directly with senior client stakeholders and CISOs worldwide. Someone who enjoys bridging research and real-world incident work, and who communicates findings clearly in English, will find this a strong fit.





