Job Description
B2Tech is looking for a mid-level Security Operations Engineer to strengthen day-to-day security monitoring, identity and endpoint protection, and cloud and network security controls across our hybrid AWS and on-prem environment.
This is a hands-on operational role: you will triage alerts, harden configurations, and execute on remediation plans defined by the SecOps Team Lead, while building toward greater independent ownership of specific security domains.
Key Responsibilities
Monitoring & Incident Response
- Manage and triage security alerts in Coralogix (SIEM), escalating and documenting incidents per established SOC/NOC escalation procedures
- Investigate suspicious activity using Entra ID sign-in logs, SentinelOne EDR telemetry, and Cloudflare audit logs
- Support incident investigations, including timeline reconstruction and evidence collection
Identity & Endpoint Security
- Administer and monitor Entra ID Conditional Access policies; investigate authentication anomalies and access issues
- Manage SentinelOne EDR agent health, policy configuration, and device control across the fleet
- Support Microsoft Intune compliance and configuration policies
Cloud & Infrastructure Security
- Manage AWS IAM permissions, cross-account access, and Secrets Manager configurations following least-privilege principles
- Monitor AWS CloudTrail activity and support AWS Organizations / SCP governance
- Assist in maintaining and reviewing Terraform-managed Cloudflare WAF rules and Zero Trust (WARP) access policies
Network & Application Security
- Monitor and tune Cloudflare WAF rules, rate limiting, and bot/challenge configurations
- Support Zero Trust network access rollout and troubleshooting for end users
Collaboration & Process
- Work with SOC, NOC, and Tech Support teams on cross-functional escalations
- Maintain accurate documentation of configurations, playbooks, and incident records
- Participate in access reviews and support ongoing security posture improvement initiatives
Required Qualifications
- 3-5 years of experience in a security operations, SOC analyst, or IT security engineering role
- Hands-on experience with at least one SIEM platform (e.g., Coralogix, Splunk, Microsoft Sentinel)
- Working knowledge of identity and access management concepts (SSO, Conditional Access, MFA)
- Experience with endpoint detection and response (EDR) tools
- Familiarity with core AWS services and basic cloud security principles
- Understanding of WAF, DNS, and network security fundamentals
- Strong analytical and documentation skills; comfortable working independently on defined tasks
Preferred Qualifications
- Direct experience with Cloudflare (WAF, Zero Trust/WARP)
- Exposure to Infrastructure-as-Code (Terraform) for security rule management
- Experience with Microsoft Intune or other MDM/UEM platforms
- Familiarity with GitHub Enterprise administration and RBAC
- Relevant certifications (Security+, SC-200, AWS Security Specialty, or similar)
WHAT WE OFFER:
- Annual Discretionary Performance Bonus 💵
- Annual Salary Review 📈
- Hybrid Model 🏠
- Semi-flexible Working Hours 🕒
- Keren Hishtalmut contribution from the start date 🎓
- Recuperation Pay 🩺
- ILS 1,000 Monthly Lunch Allowance via Cibus, with No Usage Restrictions 🍽️
- Happy Hour 🍻
- Exciting Career Paths 🎯
- Personalized Learning and Development Programs 📖
- Birthday Leave 🎂
- Marriage Leave Vacation 💍
- Service Awards Gifts 🏅
- Variety of Employee Perks 🎁
- HitechZone membership 🎫