B2Tech

Security Operations Engineer

B2Tech Or Yehuda, Tel-Aviv District, Israel

Entertainment · 201-500 employees

7 h ago
Mid (2-5 yrs) Full-time Israel
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Security Operations Engineer will manage daily security monitoring, triage alerts, and execute remediation plans across hybrid AWS and on-prem environments. The role involves administering identity and endpoint protection policies while collaborating with cross-functional teams to improve the overall security posture.

What they look for

Security Operations SIEM Identity and Access Management Endpoint Detection and Response AWS Security Cloud Security Network Security WAF Terraform Incident Response Entra ID Microsoft Intune Zero Trust Documentation Analytical Skills

Requirements

Candidates must have 3-5 years of experience in security operations or IT security engineering with hands-on knowledge of SIEM platforms and cloud security principles. Proficiency in identity management, EDR tools, and network security fundamentals is required, along with strong analytical and documentation skills.

Benefits

Annual Discretionary Performance Bonus Annual Salary Review Hybrid Model Semi-flexible Working Hours Keren Hishtalmut contribution Recuperation Pay Monthly Lunch Allowance Happy Hour Career Paths Learning and Development Programs Birthday Leave Marriage Leave Vacation Service Awards Gifts Employee Perks HitechZone membership

Full description

B2Tech is looking for a mid-level Security Operations Engineer to strengthen day-to-day security monitoring, identity and endpoint protection, and cloud and network security controls across our hybrid AWS and on-prem environment.

This is a hands-on operational role: you will triage alerts, harden configurations, and execute on remediation plans defined by the SecOps Team Lead, while building toward greater independent ownership of specific security domains.

Key Responsibilities

Monitoring & Incident Response

  • Manage and triage security alerts in Coralogix (SIEM), escalating and documenting incidents per established SOC/NOC escalation procedures
  • Investigate suspicious activity using Entra ID sign-in logs, SentinelOne EDR telemetry, and Cloudflare audit logs
  • Support incident investigations, including timeline reconstruction and evidence collection

Identity & Endpoint Security

  • Administer and monitor Entra ID Conditional Access policies; investigate authentication anomalies and access issues
  • Manage SentinelOne EDR agent health, policy configuration, and device control across the fleet
  • Support Microsoft Intune compliance and configuration policies

Cloud & Infrastructure Security

  • Manage AWS IAM permissions, cross-account access, and Secrets Manager configurations following least-privilege principles
  • Monitor AWS CloudTrail activity and support AWS Organizations / SCP governance
  • Assist in maintaining and reviewing Terraform-managed Cloudflare WAF rules and Zero Trust (WARP) access policies

Network & Application Security

  • Monitor and tune Cloudflare WAF rules, rate limiting, and bot/challenge configurations
  • Support Zero Trust network access rollout and troubleshooting for end users

Collaboration & Process

  • Work with SOC, NOC, and Tech Support teams on cross-functional escalations
  • Maintain accurate documentation of configurations, playbooks, and incident records
  • Participate in access reviews and support ongoing security posture improvement initiatives

Required Qualifications

  • 3-5 years of experience in a security operations, SOC analyst, or IT security engineering role
  • Hands-on experience with at least one SIEM platform (e.g., Coralogix, Splunk, Microsoft Sentinel)
  • Working knowledge of identity and access management concepts (SSO, Conditional Access, MFA)
  • Experience with endpoint detection and response (EDR) tools
  • Familiarity with core AWS services and basic cloud security principles
  • Understanding of WAF, DNS, and network security fundamentals
  • Strong analytical and documentation skills; comfortable working independently on defined tasks

Preferred Qualifications

  • Direct experience with Cloudflare (WAF, Zero Trust/WARP)
  • Exposure to Infrastructure-as-Code (Terraform) for security rule management
  • Experience with Microsoft Intune or other MDM/UEM platforms
  • Familiarity with GitHub Enterprise administration and RBAC
  • Relevant certifications (Security+, SC-200, AWS Security Specialty, or similar)

WHAT WE OFFER:

  • Annual Discretionary Performance Bonus 💵
  • Annual Salary Review 📈
  • Hybrid Model 🏠
  • Semi-flexible Working Hours 🕒
  • Keren Hishtalmut contribution from the start date 🎓
  • Recuperation Pay 🩺
  • ILS 1,000 Monthly Lunch Allowance via Cibus, with No Usage Restrictions 🍽️
  • Happy Hour 🍻
  • Exciting Career Paths 🎯
  • Personalized Learning and Development Programs 📖
  • Birthday Leave 🎂
  • Marriage Leave Vacation 💍
  • Service Awards Gifts 🏅
  • Variety of Employee Perks 🎁
  • HitechZone membership 🎫