Incident Response Analyst

Fortinet
Tel Aviv
Workplace: HybridFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 3+ yearsSkills: ["Communication","Teamwork","Proactive","Ownership-driven"]

Investigate and respond to workspace security incidents across email, browser security, and perimeter domains. Triage customer investigation requests, perform phishing analysis, and conduct threat hunting using attack patterns, behaviors, and indicators. Build and improve detections for emerging attack types, and collaborate with development and research teams to deliver incident-driven insights and new detection engines. Contribute to 24/7 rotating shifts and publish research-focused blog posts based on incident findings.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Fortinet
Fortinet
8 hours ago

Incident Response Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live
Reposted: similar role first listed 1 month ago

Job Summary

Investigate and respond to workspace security incidents across email, browser security, and perimeter domains. Triage customer investigation requests, perform phishing analysis, and conduct threat hunting using attack patterns, behaviors, and indicators. Build and improve detections for emerging attack types, and collaborate with development and research teams to deliver incident-driven insights and new detection engines. Contribute to 24/7 rotating shifts and publish research-focused blog posts based on incident findings.
Location: Tel Aviv
Workplace: Hybrid
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Investigate and respond to workspace security incidents across email, browser security, and perimeter security domains.
  • •Handle customer-submitted investigation requests.
  • •Perform targeted phishing analysis and investigate new attack campaigns.
  • •Conduct threat hunting using attack patterns, behaviors, and indicators, and build/improve detections for emerging attacks.
  • •Collaborate with development and research teams to generate incident-driven insights and develop new detection engines; write blog posts based on incident investigations and attack trends.

Key Requirements

  • •At least 3 years of experience in Incident Response or Security Operations roles.
  • •Strong understanding of attack vectors, including phishing, BEC, email spoofing/impersonation, malware, and ATO.
  • •Knowledge of email protocols and security concepts such as SMTP, SPF/DKIM/DMARC, and headers/authentication methods.
  • •Strong querying skills using SQL, SPL, KQL, or AQL.
  • •Familiarity with static and dynamic techniques and the ability to read and analyze potentially malicious scripts; Python/JavaScript/Visual Basic or similar.
  • •Excellent written and verbal communication in English.
  • •Team player with a proactive, ownership-driven approach.
Experience:3+ yearsCybersecurityIncident responseSecurity operations
Skills:CommunicationTeamworkProactiveOwnership-driven
Languages:English
Tech Stack:EmailBrowser securityPerimeter securityPhishing analysisThreat huntingSQLSPLKQLAQLPythonJavaScriptVisual BasicSMTPSPFDKIMDMARCHeadersAuthentication methodsStatic analysisDynamic analysis

Company Brief

Fortinet
Provides enterprise cybersecurity solutions including data protection, cloud security, network security, and user and entity behavior analytics to help organizations prevent insider threats, secure cloud and on-premises environments, and enforce data loss prevention policies.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Austin, United States
Founded: 1994
WebsiteLinkedIn