Security Operations Engineer
B2Tech is looking for a mid-level Security Operations Engineer to strengthen day-to-day security monitoring, identity and endpoint protection, and cloud and network security controls across our hybrid AWS and on-prem environment. This is a hands-on operational role: you will triage alerts, harden configurations, and execute on remediation plans defined by the SecOps Team Lead, while building toward greater independent ownership of specific security domains. Key Responsibilities Monitoring & Incident Response • Manage and triage security alerts in Coralogix (SIEM), escalating and documenting incidents per established SOC/NOC escalation procedures • Investigate suspicious activity using Entra ID sign-in logs, SentinelOne EDR telemetry, and Cloudflare audit logs • Support incident investigations, including timeline reconstruction and evidence collection Identity & Endpoint Security • Administer and monitor Entra ID Conditional Access policies; investigate authentication anomalies and access issues • Manage SentinelOne EDR agent health, policy configuration, and device control across the fleet • Support Microsoft Intune compliance and configuration policies Cloud & Infrastructure Security • Manage AWS IAM permissions, cross-account access, and Secrets Manager configurations following least-privilege principles • Monitor AWS CloudTrail activity and support AWS Organizations / SCP governance • Assist in maintaining and reviewing Terraform-managed Cloudflare WAF rules and Zero Trust (WARP) access policies Network & Application Security • Monitor and tune Cloudflare WAF rules, rate limiting, and bot/challenge configurations • Support Zero Trust network access rollout and troubleshooting for end users Collaboration & Process • Work with SOC, NOC, and Tech Support teams on cross-functional escalations • Maintain accurate documentation of configurations, playbooks, and incident records • Participate in access reviews and support ongoing security posture improvement initiatives Required Qualifications • 3-5 years of experience in a security operations, SOC analyst, or IT security engineering role • Hands-on experience with at least one SIEM platform (e.g., Coralogix, Splunk, Microsoft Sentinel) • Working knowledge of identity and access management concepts (SSO, Conditional Access, MFA) • Experience with endpoint detection and response (EDR) tools • Familiarity with core AWS services and basic cloud security principles • Understanding of WAF, DNS, and network security fundamentals • Strong analytical and documentation skills; comfortable working independently on defined tasks Preferred Qualifications • Direct experience with Cloudflare (WAF, Zero Trust/WARP) • Exposure to Infrastructure-as-Code (Terraform) for security rule management • Experience with Microsoft Intune or other MDM/UEM platforms • Familiarity with GitHub Enterprise administration and RBAC • Relevant certifications (Security+, SC-200, AWS Security Specialty, or similar) WHAT WE OFFER: Annual Discretionary Performance Bonus 💵 Annual Salary Review 📈 Hybrid Model 🏠 Semi-flexible Working Hours 🕒 Keren Hishtalmut contribution from the start date 🎓 Recuperation Pay 🩺 ILS 1,000 Monthly Lunch Allowance via Cibus, with No Usage Restrictions 🍽️ Happy Hour 🍻 Exciting Career Paths 🎯 Personalized Learning and Development Programs 📖 Birthday Leave 🎂 Marriage Leave Vacation 💍 Service Awards Gifts 🏅 Variety of Employee Perks 🎁 HitechZone membership 🎫
מצאו את המשרה הבאה שלכם בלוח הדרושים של ישראל.
כל המשרות