Mploy - דרושים
Mploy - דרושים

דרושים DFIR Expert בתל אביב

 נכון לתאריך

 

15/12/2025

 תל אביב

 Code Blue Cyber

🚨 We're Hiring: Senior IR & DFIR Specialist

📍 Location: Tel Aviv, Israel | 🏢 Company: Code Blue Cyber

About Code Blue Cyber

At Code Blue Cyber, we help organizations prepare for, respond to, and recover from cyber crises. With deep operational experience and a proven track record managing high-impact incidents worldwide, we reduce downtime, minimize financial and regulatory impact, and protect reputations when it matters most. Headquartered in Tel Aviv and serving clients globally, we’re building the next generation of cyber crisis leadership.

Position Summary

We are seeking a highly seasoned Senior Incident Response (IR) and Digital Forensics (DFIR) Specialist to join our elite Incident Response team.

This is a senior technical specialist role focused on hands-on investigation and response to the most challenging cyber incidents. The ideal candidate possesses deep technical mastery, proven ability to execute complex DFIR tasks, and the capability to serve as a trusted technical advisor during high-stakes incidents (such as APTs and sophisticated ransomware attacks) within large enterprise environments.

Key Responsibilities

  • Full Incident Ownership: Take ownership in the core IR effort or an entire workstream, and conduct complex IR tasks during high-severity incidents (Ransomware, APTs, Data Breaches).
  • Advanced DFIR Execution: Perform in-depth, hands-on forensic investigations including large-scale sophisticated attacks, conduct log analysis, host and network-based forensics, and malware analysis.
  • Technical Leadership & Scoping: Technically lead small-scale proactive engagements, participate in ad-hoc scoping calls, and define investigation paths.
  • Client Communication & Reporting: Lead client communication on dedicated sessions and present reports. Generate and present a comprehensive and professional report of findings from investigations, compliant with international standards and Chain-of-Custody principles.
  • Threat Hunting & TTPs: Participate in threat hunting: proactively hunt for targeted attacks and new emerging threats in client’s networks, as well as security assessments and simulations. Identify indicators of compromise (IOCs) and tools, tactics, and procedures (TTPs) to help ascertain whether and how breaches have occurred.
  • Methodology and Tooling: Utilize and develop tools and methodologies to improve Code Blue's existing investigative and hunting technological stack.
  • Collaboration: Collaborate with IT and Security teams during investigations and work closely with Threat Intelligence and Detection Engineering teams.

Required Qualifications (Adjusted for 3 Years Experience)

  • 3+ years of hands-on DFIR and IR experience, specifically focusing on responding to high-impact cyber incidents.
  • Proven track record of contributing effectively to complex security incidents (e.g., sophisticated ransomware, data breaches) in mid-to-large-scale environments.
  • Deep technical understanding of the life cycle of advanced security threats, attack vectors, and various methods of exploration.
  • Solid technical knowledge and hands-on proficiency in:
  • Host-Based Forensics: Solid understanding of system and security controls on at least two operating systems (Windows, Linux, Unix, and macOS), including host-based forensics and experience with analyzing OS artifacts.
  • Network Fundamentals: Deep technical understanding of network fundamentals and common Internet protocols.
  • Data Analysis: Hands-on experience in data analysis (preferably network traffic or log analysis) in relevant data analysis and data science platforms (e.g., Splunk).
  • Tool Fluency: Familiarity with enterprise SIEM platforms (e.g., Splunk, QRadar, ArcSight) and proficiency with core forensic and IR tools (e.g., EnCase, Volatility, EDRs).
  • Scripting: Fluency with one or more scripting languages (i.e., Python) is a strong plus.
  • Problem-Solving Skills: Bright, curious, and determined team player, who strives for excellence, with a problem-solver and in-depth thinker mindset.
  • Communication: Excellent communication and interpersonal skills, including fluent English, with the ability to document and explain technical information in a concise, understandable manner.
  • Knowledge Assets: Familiarity with cloud infrastructure, web application and servers, and mobile platforms is an advantage.
  • Optional: Experience with malware analysis and reverse engineering is a strong advantage.

Preferred Certifications (A Strong Plus)

  • GCFA – GIAC Certified Forensic Analyst
  • GCIH – GIAC Certified Incident Handler
  • GREM – GIAC Reverse Engineering Malware
  • OSCP, OSCE, CISSP, or CISM

What We Offer

  • An opportunity to join a high-impact, experienced IR team focused on the world's most critical cyber incidents.
  • Work on challenging and diverse incidents with Enterprise clients worldwide.
  • Competitive compensation, benefits, and professional development support.
  • A mission-driven company with a culture of excellence and deep technical focus.

How to Apply

Send your resume and a short cover letter to: 📧 |** לפנייה למשרה יש להגיש מועמדות **| 💥 Make an impact where it matters most. Join Code Blue Cyber – where incident response becomes resilience.

משרות דומות שיכולות לעניין אותך

 נכון לתאריך

 

06/11/2025

 תל אביב

Sygnia is the foremost global cyber readiness and response team, applying creative approaches and battle-tested solutions to help organizations beat a...  

read more

 נכון לתאריך

 

15/11/2025

 תל אביב

CYE's DFIR team is responsible for responding to our clients' cyber incidents and crises.

Our group is expanding. If you see yourself in the fron...  

read more

 נכון לתאריך

 

20/11/2025

 תל אביב

**Job Description

**Join Fortinet, a cybersecurity pioneer with over two decades of excellence, as we continue to shape the future of cybersecuri...  

read more

 נכון לתאריך

 

11/12/2025

 תל אביב

The Position:

We are seeking a highly motivated and technically proficient Senior Security Researcher to join our security research division. Thi...  

read more

 נכון לתאריך

 

09/12/2025

 תל אביב

We’re looking for a Senior Cybersecurity Expert to join our team in Singapore and lead the design and delivery of impactful **cyber defense training p...  

read more

 נכון לתאריך

 

24/11/2025

 תל אביב

**About us:** PwC is one of the leading consulting firms in Israel and worldwide, providing professional services to first-tier clients. Our Forensics...  

read more

 נכון לתאריך

 

05/11/2025

 תל אביב

🔒 Senior Cyber Security Analyst – Leading Insurance Company 🚀

A leading insurance company is looking for a **Senior Cyber Security Analyst** to...  

קרא עוד

 נכון לתאריך

 

29/10/2025

 תל אביב

Come join the company that is reinventing cloud security and empowering businesses to thrive in the cloud. As the fastest-growing startup ever, Wiz is...  

read more

 נכון לתאריך

 

04/12/2025

 תל אביב

תחומי אחריות:

  • ניטור, ניתוח ותחקור אירועי סייבר בסביבות ענן ומערכות ארגוניות.
  • שיפור תהליכי אבטחה ואוטומציה של בקרות.

* עבודה שוטפת עם צוותי ...  

קרא עוד
הצג משרות דומות נוספות...

Mploy אצלכם בוואטסאפ

✨ רוצים להתעדכן בכל המשרות הכי שוות ישר לנייד?

הצטרפו לקבוצות הוואטסאפ שלנו וקבלו את כל ההצעות המתאימות – בלי לחפש, ובלי לפספס. מחכים לכם! 📱😊