# Incident Response Engineer

[Biocatch](https://gurify.com/jobs?q=Biocatch) · Tel Aviv-Yafo, Israel · Posted 3 days ago

[Apply on the original posting → (opens in a new tab)](https://www.comeet.com/jobs/biocatch/03.00E/incident-response-engineer/DE.C6E?+Capital+job+board)

## Job description

BioCatch is the leader in Behavioral Biometrics, a technology that leverages machine learning to analyze an online user’s physical and cognitive digital behavior to protect individuals online. BioCatch’s mission is to unlock the power of behavior and deliver actionable insights to create a digital world where identity, trust, and ease coexist.

Today, 34 of the world's largest 100 banks and 210 total financial institutions rely on BioCatch Connect™ to combat fraud, facilitate digital transformation, and grow customer relationships. BioCatch’s Client Innovation Board, an industry-led initiative including American Express, Barclays, Citi Ventures, and National Australia Bank, helps BioCatch to identify creative and cutting-edge ways to leverage the unique attributes of behavior for fraud prevention. With over a decade of analyzing data, more than 80 registered patents, and unparalleled experience, BioCatch continues to innovate to solve tomorrow’s problems. For more information, please visit www.biocatch.com.

We are seeking an Incident Response Engineer to join the IR team. This technical role focuses on active investigation, threat mitigation, and the continuous improvement of the security organization’s posture through detection engineering and automation development.

The successful candidate will be responsible for the full lifecycle of security incidents, from initial triage to recovery. Beyond reactive response, this role involves tuning SIEM correlation rules and developing SOAR workflows to increase operational efficiency.

### What You’ll Be Doing

- Incident Management: Execute the IR lifecycle (Triage, Containment, Eradication, Recovery) for complex security events.

- Technical Investigation: Perform root cause analysis and forensic examination across Windows, Mac, and Linux environments.

- Detection & Tuning: Collaborate with the IR team to create, test, and tune SIEM rules and dashboards to reduce false positives and improve visibility.

- Automation Engineering: Build and refine SOAR playbooks and automated response actions to streamline repetitive investigation tasks.

- Cloud Security: Monitor and mitigate cloud-native threats across Azure, AWS, and GCP environments.

### Requirements

- Experience as a SecOps/IR Analyst or Engineer with a heavy focus on active investigation.

- Deep understanding of the Incident Response lifecycle (Triage, Containment, Eradication, Recovery).

- Hands-on experience handling and managing security alerts, performing root cause analysis, and leading investigations.

- Experience working across cloud providers (Azure, AWS, GCP) to identify and mitigate cloud-native threats.

- Strong knowledge of operating systems (Mac, Windows, Linux) and their respective artifacts.

- Proficiency with Splunk or other SIEM platforms for log analysis and threat hunting.

- Experience with XSOAR or other security automation tools from an end-user/analyst perspective.

- Strong knowledge of security technologies, including EDR, Mail Relay, Vulnerability Scanning, Secure Access, and MDM.

- Scripting experience with Python or Bash to assist in data parsing and investigation tasks.

### Nice to Have

- Detection Engineering: Ability to build and improve SIEM rules, correlations, and dashboards.

- Automation Development: Experience developing new SOAR workflows, automated actions, and response playbooks.

- Technical Literacy: Familiarity with REST APIs and Regex for advanced querying and tool integration.

- Container Security: Familiarity and experience with K8S (Kubernetes).

- Consultative Skills: Ability to guide best practices in Cloud Security and SIEM operations.

**Live in Biocatch’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- BI [Senior DevOps Infra Engineer](https://gurify.com/job/senior-devops-infra-engineer-at-biocatch-8dd06af10b97) Biocatch · Tel Aviv-Yafo, Israel · 2 weeks ago
- BI [Technical Product Manager](https://gurify.com/job/technical-product-manager-at-biocatch-0af412b7fbd5) Biocatch · Tel Aviv-Yafo, Israel · last week
- BI [Student Position](https://gurify.com/job/student-position-at-biocatch-30b297b6a00c) Biocatch · Tel Aviv-Yafo, Israel · last week
- TH [DevOps Engineer](https://gurify.com/job/devops-engineer-at-thetaray-8da9175339b5) Thetaray · Hod Hasharon, Israel · last week
- NA [Senior DevOps Engineer](https://gurify.com/job/senior-devops-engineer-at-nayax-75a47cdb6502) Nayax · Herzliya, Israel · last week
- AU [DevOps Engineer](https://gurify.com/job/devops-engineer-at-audiocodes-38093dcdd8cb) Audiocodes · Or Yehuda, Israel · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Incident Response Engineer","description":"\u003Cp\u003EBioCatch is the leader in Behavioral Biometrics, a technology that leverages machine learning to analyze an online user\u2019s physical and cognitive digital behavior to protect individuals online. BioCatch\u2019s mission is to unlock the power of behavior and deliver actionable insights to create a digital world where identity, trust, and ease coexist.\u003C/p\u003E\u003Cp\u003EToday, 34 of the world\u0026#39;s largest 100 banks and 210 total financial institutions rely on BioCatch Connect\u2122 to combat fraud, facilitate digital transformation, and grow customer relationships. BioCatch\u2019s Client Innovation Board, an industry-led initiative including American Express, Barclays, Citi Ventures, and National Australia Bank, helps BioCatch to identify creative and cutting-edge ways to leverage the unique attributes of behavior for fraud prevention. With over a decade of analyzing data, more than 80 registered patents, and unparalleled experience, BioCatch continues to innovate to solve tomorrow\u2019s problems. For more information, please visit www.biocatch.com.\u003C/p\u003E\u003Cp\u003EWe are seeking an Incident Response Engineer to join the IR team. This technical role focuses on active investigation, threat mitigation, and the continuous improvement of the security organization\u2019s posture through detection engineering and automation development.\u003C/p\u003E\u003Cp\u003EThe successful candidate will be responsible for the full lifecycle of security incidents, from initial triage to recovery. Beyond reactive response, this role involves tuning SIEM correlation rules and developing SOAR workflows to increase operational efficiency.\u003C/p\u003E\u003Ch3\u003EWhat You\u2019ll Be Doing\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EIncident Management: Execute the IR lifecycle (Triage, Containment, Eradication, Recovery) for complex security events.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETechnical Investigation: Perform root cause analysis and forensic examination across Windows, Mac, and Linux environments.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDetection \u0026amp; Tuning: Collaborate with the IR team to create, test, and tune SIEM rules and dashboards to reduce false positives and improve visibility.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAutomation Engineering: Build and refine SOAR playbooks and automated response actions to streamline repetitive investigation tasks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECloud Security: Monitor and mitigate cloud-native threats across Azure, AWS, and GCP environments.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience as a SecOps/IR Analyst or Engineer with a heavy focus on active investigation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDeep understanding of the Incident Response lifecycle (Triage, Containment, Eradication, Recovery).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience handling and managing security alerts, performing root cause analysis, and leading investigations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working across cloud providers (Azure, AWS, GCP) to identify and mitigate cloud-native threats.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong knowledge of operating systems (Mac, Windows, Linux) and their respective artifacts.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProficiency with Splunk or other SIEM platforms for log analysis and threat hunting.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with XSOAR or other security automation tools from an end-user/analyst perspective.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong knowledge of security technologies, including EDR, Mail Relay, Vulnerability Scanning, Secure Access, and MDM.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EScripting experience with Python or Bash to assist in data parsing and investigation tasks.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENice to Have\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDetection Engineering: Ability to build and improve SIEM rules, correlations, and dashboards.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAutomation Development: Experience developing new SOAR workflows, automated actions, and response playbooks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETechnical Literacy: Familiarity with REST APIs and Regex for advanced querying and tool integration.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContainer Security: Familiarity and experience with K8S (Kubernetes).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EConsultative Skills: Ability to guide best practices in Cloud Security and SIEM operations.\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"incident-response-engineer-at-biocatch-38e624c07c1f"},"url":"https://gurify.com/job/incident-response-engineer-at-biocatch-38e624c07c1f","datePosted":"2026-08-14","validThrough":"2026-10-01T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Biocatch","sameAs":"https://www.comeet.com/jobs/biocatch"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"IL","addressLocality":"Tel Aviv-Yafo"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Israel","item":"https://gurify.com/jobs/israel"},{"@type":"ListItem","position":3,"name":"Incident Response Engineer","item":"https://gurify.com/job/incident-response-engineer-at-biocatch-38e624c07c1f"}]}
```
