DFIR Expert (Lead)
UST
Tel Aviv-Yafo, Tel Aviv District
The Role
This position leads digital forensics investigations and incident response engagements, acting as the highest escalation point during confirmed breaches. Day-to-day work spans forensic analysis across file systems, memory, and networks, alongside threat containment, tool development, reporting, and collaboration with pre-sales and account teams to grow the DFIR service.
Skills & Experience
Candidates need three or more years in DFIR, threat hunting, SOC, or information security, with deep knowledge of Windows and Linux internals, network communications, and intrusion techniques. Hands-on experience with EDR and SIEM platforms, dynamic and static malware analysis, and the ability to build custom automation tools are all essential.
Who It Suits
This role suits a technically strong, self-driven professional who is comfortable leading teams and client communications under pressure. Someone who combines investigative rigour with a proactive mindset, enjoys building and improving services, and is ready to respond to high-severity incidents as part of an on-call escalation tier will thrive here.





