Apply Edge Start your job search

Head of Incident Response & DFIR | Founding Leadership Role

Up Security (Formerly Wake-up Cyber) · Israel

Apply & track with Apply Edge
About Up SecurityUp Security (formerly Wake-up Cyber) is a fast-growing cybersecurity services company supporting nearly 100 technology-focused organizations across Cloud Security, SecOps, AppSec, AI Security, Privacy, GRC and CISO services.Build it. Own it. Lead it.We’re looking for a Head of Incident Response & DFIR to build and lead a new cyber response practice at Up Security.This is not a role where you inherit an existing IR team or operating model.You’ll have the mandate to build the capability from the ground up- while remaining deeply hands-on: leading complex incidents, conducting investigations and forensics, defining methodology and tooling, and working directly with technology companies and their leadership teams.You’ll report directly to the company’s owners, and as the practice grows, recruit and lead your own IR team and help shape the services, business model and direction of the activity.What You’ll OwnBuild and lead Up Security’s Incident Response & DFIR practiceLead complex cyber incidents end-to-endStay hands-on across investigation, forensics, containment, eradication and recoveryLead threat hunting and compromise assessmentsInvestigate Windows, AD / Entra ID, endpoint, cloud and identity attacksDefine IR methodologies, playbooks, tooling and customer-facing servicesWork directly with CISOs, executives and technical teams during critical incidentsRecruit and lead the IR team as the practice growsWhat We’re Looking ForStrong hands-on Incident Response / DFIR experienceProven ownership of complex, real-world cyber incidentsStrong digital forensics and investigation capabilitiesExperience with EDR, SIEM and enterprise environmentsStrong understanding of attacker TTPs, MITRE ATT&CK and the incident lifecycleAbility to lead customers and technical teams under pressureA builder mindset - someone ready to create and own a capability, not simply operate within an existing one.Experience in IR/DFIR consulting, CERT/CSIRT or multi-customer environments is a strong advantage.Cloud IR, malware analysis, threat hunting and scripting experience are also valuable.Why This Role?You’re not joining an established IR team. You’re being given the mandate to create one.You’ll have an existing customer base, Up Security’s broader cybersecurity capabilities behind you, direct access to company ownership, and the opportunity to turn the practice you build into a significant business activity.If the next Senior IR role feels like more of the same, and you’re ready to build something of your own - we’d like to meet you.