Security Operations Engineer

B2TechOr Yehuda, Tel AvivOn-siteFull-timeMid level, 2–5 yearsListed 3 days ago

Apply now

About this role

B2Tech is looking for a mid-level Security Operations Engineer to strengthen day-to-day security monitoring, identity and endpoint protection, and cloud and network security controls across our hybrid AWS and on-prem environment.

This is a hands-on operational role: you will triage alerts, harden configurations, and execute on remediation plans defined by the SecOps Team Lead, while building toward greater independent ownership of specific security domains.

Key Responsibilities

Monitoring & Incident Response

• Manage and triage security alerts in Coralogix (SIEM), escalating and documenting incidents per established SOC/NOC escalation procedures

• Investigate suspicious activity using Entra ID sign-in logs, SentinelOne EDR telemetry, and Cloudflare audit logs

• Support incident investigations, including timeline reconstruction and evidence collection

Identity & Endpoint Security

• Administer and monitor Entra ID Conditional Access policies; investigate authentication anomalies and access issues

• Manage SentinelOne EDR agent health, policy configuration, and device control across the fleet

• Support Microsoft Intune compliance and configuration policies

Cloud & Infrastructure Security

• Manage AWS IAM permissions, cross-account access, and Secrets Manager configurations following least-privilege principles

• Monitor AWS CloudTrail activity and support AWS Organizations / SCP governance

• Assist in maintaining and reviewing Terraform-managed Cloudflare WAF rules and Zero Trust (WARP) access policies

Network & Application Security

• Monitor and tune Cloudflare WAF rules, rate limiting, and bot/challenge configurations

• Support Zero Trust network access rollout and troubleshooting for end users

Collaboration & Process

• Work with SOC, NOC, and Tech Support teams on cross-functional escalations

• Maintain accurate documentation of configurations, playbooks, and incident records

• Participate in access reviews and support ongoing security posture improvement initiatives

Required Qualifications

• 3-5 years of experience in a security operations, SOC analyst, or IT security engineering role

• Hands-on experience with at least one SIEM platform (e.g., Coralogix, Splunk, Microsoft Sentinel)

• Working knowledge of identity and access management concepts (SSO, Conditional Access, MFA)

• Experience with endpoint detection and response (EDR) tools

• Familiarity with core AWS services and basic cloud security principles

• Understanding of WAF, DNS, and network security fundamentals

• Strong analytical and documentation skills; comfortable working independently on defined tasks

Preferred Qualifications

• Direct experience with Cloudflare (WAF, Zero Trust/WARP)

• Exposure to Infrastructure-as-Code (Terraform) for security rule management

• Experience with Microsoft Intune or other MDM/UEM platforms

• Familiarity with GitHub Enterprise administration and RBAC

• Relevant certifications (Security+, SC-200, AWS Security Specialty, or similar)

WHAT WE OFFER:

- Annual Discretionary Performance Bonus 💵
- Annual Salary Review 📈
- Hybrid Model 🏠
- Semi-flexible Working Hours 🕒
- Keren Hishtalmut contribution from the start date 🎓
- Recuperation Pay 🩺
- ILS 1,000 Monthly Lunch Allowance via Cibus, with No Usage Restrictions 🍽️
- Happy Hour 🍻
- Exciting Career Paths 🎯
- Personalized Learning and Development Programs 📖
- Birthday Leave 🎂
- Marriage Leave Vacation 💍
- Service Awards Gifts 🏅
- Variety of Employee Perks 🎁
- HitechZone membership 🎫