Career Summary

👁️ 🐝 M I am a Security Architect at IBM, Specializing in threat management and utilizing advanced technologies such as SIEM, SOAR, XDR, EDR, and ASM. With a strong focus on designing robust security solutions, I collaborate with cross-functional teams to create resilient systems that protect critical data and assets. My expertise in analyzing complex infrastructures and identifying vulnerabilities allows me to develop comprehensive security strategies aligned with business objectives and industry standards. Let's connect and discuss how we can enhance your organization's security posture.

Work Experience

Security Architect

IBM
Apr 2023 - Present

Security Architect - Threat Management

Technologies used:

  • QRadar SIEM
  • QRadar SOAR
  • QRadar EDR
  • QRadar Log Insights
  • Randori ASM

MSSP Senior Solution Architect

2BSecure@matrix
Aug 2021 - Apr 2023

Lead technical design and implementation of complex multisystem solutions.
• Pre-sale and project management for the MSSP department.
• Managing the company's AWS cloud and data center production environment.
• Leading highly technological meetings and proof-of-concepts with clients.
• Conduct POCs with vendors and create a SaaS module from scratch for the MSSP department (architecture design, deployment, 24/7 monitoring solution, SIEM integration).

MSSP Technical Leader

Jul 2020 - Aug 2021 (1 year 2 months)

Lead the technical team of Tier-2 and Professional Services.
• SIEM/SOC Production Management.
• Training new employees.
• Writing manuals and procedures for using the QRadar system.
• System hardening and maintenance

SIEM/SOC Senior Professional Services

Apr 2020 - Jul 2021 (4 months)

QRadar Expert
• Implementation, Maintenance and deployment of IBM QRadar SIEM.
• Integrating and parsing Log sources.
• Writing and implementing custom rules according to customer requirements.
• Improvement of existing systems, regular maintenance, fault handling.
• Maintaining Firewalls, Networks and AWS Cloud Production environment.

Technologies used:

  • AWS Cloud
  • IBM QRadar
  • SentinelOne EDR
  • Fortigate FW
  • Reblaze WAF
  • Windows & Linux
  • PostgreSQL & AQL
  • Visio
  • Jira
  • Adtive Directory
  • VMware ESX

Information Security Specialist

QMasters Security Services Ltd
May 2019 - Apr 2012 (1 year)

Plan and implement QRadar for complex projects for a variety of clients.
• Manage the Ministry of Health's SIEM system.
• Manage deployment and connect hospitals and medical centers for 24/7 monitoring.
• Integrating the end organization's information security devices with the SIEM.
• Perform system maintenance, create and implement correlation rules according to customer specifications.

Technologies used:

  • IBM QRadar
  • Linux & Windows
  • Server
  • Firewalls

Information Security Analyst

White-Hat Ltd
Oct 2018 - May 2019 (8 months)

Working in a team of analysts, providing 24/7 monitoring to a variety of the company's clients.
• Working with various SIEM systems, led by QRadar.
• Examine threats to determine their urgency and conduct investigations.
• Responding to incidents, resolving severe attacks that have escalated, assessing the scope of the attack and the affected systems, and collecting data for further analysis.
• Perform threat hunting, which looks for weaknesses proactively.

Technologies used:

  • IBM QRadar
  • AlienVault USM
  • Arcsight
  • Rapid7 Insight Platform
  • IDS/IPS
  • VIRUSTOTAL
  • UBA
  • Sandbox

Help Desk Specialist

ELTA Systems Ltd
Apr 2018 - Oct 2018 (7 months)

Providing first point of contact for enterprise employees (large company - 3,500 employees).
• Walk the customer through the process of solving the problem.
• Experience working with monitoring systems, servers, and information security products.
• Resolving complex computing problems and providing technical assistance.

Technologies used:

  • Windows & Linux
  • Antivirus Engines
  • Secured File Servers
  • FTP
  • Mail Servers
  • Active Directory
  • SIEM
  • NAC
  • FW
  • SCCM
  • DLP
  • CDR Kiosk

IT Technician - Temporary Project

Applied Materials
Jan 2018 - Apr 2018 (4 months)

Worked on a temporary project in IT department:
• backing up data on NAS servers, formatting laptops, installing and upgrading operating systems, and resolving installation errors in the company's software.
• Configuring computers in accordance with Applied Materials policy, installing software, and connecting to a domain.

Technologies used:

  • IBM QRadar
  • Linux & Windows
  • Server
  • Firewalls

Certifications

Tools

  • AWS Cloud
  • Linux & Windows
  • SIEM
  • Networking
  • Firewalls
  • IDS/IPS
  • EDR
  • Active Directory
  • VMware/Hyper-V/KVM
  • Git
  • Docker
  • Bash scripting

Education

  • DevSecOps Engineer
    Bar Ilan University, Israel
    2021 - 2022
  • Technion Certified Security Administrator
    Technion, Israel Institute of Technology
    2017 - 2018