SOC Analyst - Cato Networks
- חברה: Cato Networks
- מיקום: תל אביב - יפו
- רמת ניסיון: סניור
- טכנולוגיות: SIEM platform, EDR, AI/LLM tools, Elastic, CrowdStrike Falcon
תיאור המשרה
3-5 years of hands-on experience in a SOC or cybersecurity operations role. Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic). Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon). Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes. Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls. Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert. High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure. Excellent communication skills and the ability to work effectively with distributed teams across time zones. Ability to work effectively on time-sensitive tasks, with a service-oriented approach toward internal stakeholders. Proficiency in written and verbal English is a must.
תחומי אחריות
Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats. Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs. Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items. Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps. SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness. Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically. Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output. Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines. Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology. Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones. Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents. Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates.
דרישות
3-5 years of hands-on experience in a SOC or cybersecurity operations role. Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic). Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon). Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes. Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls. Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert. High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure. Excellent communication skills and the ability to work effectively with distributed teams across time zones. Ability to work effectively on time-sensitive tasks, with a service-oriented approach toward internal stakeholders. Proficiency in written and verbal English is a must.
שאלות נפוצות על המשרה
איך מגישים מועמדות למשרת SOC Analyst בCato Networks?
אפשר להגיש מועמדות למשרה זו ישירות מעמוד זה ב-HiTakeJob, ללא עלות וללא צורך במנוי. ההגשה נשלחת למערכת הגיוס של Cato Networks, ומעקב על הסטטוס זמין באזור המועמדויות שלכם.
איפה המשרה ממוקמת?
המשרה ממוקמת בתל אביב - יפו.
מה נדרש למשרת SOC Analyst?
רמת ניסיון: סניור. טכנולוגיות מרכזיות: SIEM platform, EDR, AI/LLM tools, Elastic, CrowdStrike Falcon. תחום: אבטחת מידע וסייבר. הדרישות המלאות מופיעות בתיאור המשרה שלמעלה, כפי שפורסמו על ידי Cato Networks.
האם המשרה עדיין פעילה?
כן. המשרה פורסמה ב2 בספטמבר 2026 ומופיעה כפעילה במערכת הגיוס של Cato Networks. HiTakeJob בודק את המשרות מול המקור מדי יום, ומשרה שנסגרת מוסרת מהאתר.
אילו עוד משרות פתוחות בCato Networks?
כל המשרות הפתוחות של Cato Networks מרוכזות בעמוד החברה, יחד עם מידע על החברה וחוות דעת של עובדים.