At 2Bsecure, we’re looking for a Senior Incident Response & DFIR Consultant to join our Cyber Consulting team and help organizations respond to sophisticated cyber threats.
This role combines hands-on Incident Response, Digital Forensics, Threat Hunting, and strategic cybersecurity consulting. You’ll investigate real-world attacks, lead incident response engagements, work directly with customer executives and technical teams, and help organizations improve their security posture before the next attack happens.
If you thrive under pressure, enjoy solving complex technical challenges, and want to work on some of the most interesting cyber engagements in the industry—we’d love to meet you
Responsibilities
- Lead end-to-end Incident Response engagements across enterprise environments.
- Conduct Digital Forensics investigations and preserve digital evidence.
- Analyze endpoints, servers, Active Directory, Microsoft 365, and cloud environments to identify attack activity.
- Conduct proactive Threat Hunting activities to identify hidden threats.
- Collaborate with customer executives, IT teams, security teams, and external vendors throughout incident response engagements.
- Produce clear technical reports, executive summaries, and actionable remediation recommendations
- Participate in cybersecurity consulting projects, including risk assessments and security reviews.
- Perform penetration testing engagements based on experience and customer needs
- Support customers in improving their cyber resilience through practical security recommendations.
Requirements
- 3+ years of hands-on experience in Incident Response and Digital Forensics (DFIR).
- Proven experience leading cyber incident investigations for enterprise customers.
- Strong experience with Windows environments, Active Directory, and log analysis.
- Deep understanding of the MITRE ATT&CK framework.
- Experience writing professional technical reports in both Hebrew and English.
- Excellent analytical thinking, problem-solving, and communication skills with the ability to work directly with customers.
- Ability to manage multiple engagements independently, perform under pressure, and present findings to executive audiences.
- Advantages
- Technologies & Tools: Microsoft Defender XDR, Microsoft Sentinel, CrowdStrike, Cortex XDR, Splunk, IBM QRadar, Velociraptor, KAPE, Axiom.
- Additional Experience: Microsoft 365 investigations, Cloud environments (Azure, AWS, GCP), Threat Hunting, Penetration Testing, Risk Assessments & Security Audits.
- Relevant Certifications: GCFA, GCIH, GCFE, CHFI, OSCP, CEH, HDE, PNPT