Digital Forensics and Incident Response Analyst-2584
Shabak - Israeli Security Agency - Career
Center District
The Role
This position sits within a cyber defence function, focusing on investigating security incidents and performing in-depth forensic analysis across endpoints, servers, network infrastructure, and cloud environments including AWS, Azure, and GCP. The analyst determines how compromises occurred, scopes their impact, and supports containment and remediation efforts.
Skills & Experience
Candidates need at least three years in incident response or digital forensics, with hands-on use of tools such as Volatility, FTK, Autopsy, X-Ways, and log2timeline. Strong knowledge of Windows and Linux internals, SIEM platforms like Splunk or ELK, and scripting in Python, PowerShell, or C# is required.
Who It Suits
This role suits an analytically minded forensics professional who is comfortable working across diverse operating systems and cloud platforms simultaneously. Someone who combines technical depth in memory, registry, and file system artefacts with practical scripting ability and a methodical approach to incident investigation will thrive here.





