SecOps Detection & Response

Aidoc
Aidoc

Tel Aviv District, Israel · Tel Aviv-Yafo, Israel

Posted on Jul 22, 2026

About Aidoc

Aidoc is the market leader in healthcare AI and has developed the world's largest clinical frontier model, supporting nearly 50 million patients each year.
Aidoc is deployed in more than 2,000 medical centers worldwide. Since our founding in 2016, Aidoc has raised over $500 million and achieved a record number of FDA-cleared solutions.

Medical diagnosis is hitting a breaking point, where the number of physicians hasn't kept up with the rapidly growing patient load. This leads to misdiagnosis and treatment delays that result in hundreds of thousands of deaths every year. Aidoc assists clinicians by precisely highlighting diseases directly on medical images, preventing misdiagnosis and ensuring that urgent patients receive the immediate attention they need.

About this role

As a Security Operations Analyst, Detection & Response, you will help protect Aidoc’s cloud environments, products, corporate systems, and sensitive healthcare data by investigating SIEM alerts, supporting incident response, and improving the quality of security monitoring.

This is a hands-on security operations role for someone who can analyze security signals, understand real risk, communicate clearly, and help the organization respond quickly and effectively to security events.

You will work closely with real production environments, where accurate investigation, clear documentation, and practical escalation are critical to protecting sensitive healthcare data, customer trust, and the reliability of Aidoc’s clinical AI platform.

Responsibilities

  • Own the end-to-end investigation of SIEM alerts across cloud, product, identity, endpoint, and SaaS environments: analyze the relevant evidence, separate false positives from real threats, and prioritize cases based on risk and impact.
  • Escalate high-risk findings with a clear summary of what happened, what is affected, why it matters, and what actions are required.
  • Support incident response by collecting evidence, assisting with containment, tracking remediation, and maintaining clear investigation records for internal reviews, compliance needs, and post-incident learning.
  • Improve SIEM rules, dashboards, alert logic, playbooks, telemetry coverage, and detection quality to reduce noise and strengthen security monitoring.
  • Work with Security, IT, DevOps, R&D, Product Security, and Compliance teams to resolve issues and improve security operations.

Requirements

  • 2+ years of experience in Security Operations, SOC analysis, detection and response, incident response, cloud security operations, or a similar hands-on security role.
  • Hands-on experience with SIEM-based investigations, including alert triage, log analysis, event correlation, evidence review, case prioritization, and escalation.
  • Experience working with security telemetry from cloud platforms, identity providers, endpoints, SaaS systems, network tools, application logs, and production environments.
  • Familiarity with cloud-native environments, including IAM, storage access, workloads, Kubernetes, containers, APIs, logging, monitoring, and CI/CD pipelines.
  • Understanding of common attack techniques, including credential compromise, phishing, privilege escalation, suspicious API activity, malware, data exposure, lateral movement, and cloud misconfigurations.
  • Experience with identity and endpoint investigation, including SSO, MFA, service accounts, privileged access, EDR alerts, and suspicious user or device activity.
  • Ability to use query or scripting languages such as KQL, SPL, SQL, Python, Bash, or similar.
  • Familiarity with incident response workflows, case management, evidence collection, remediation tracking, and post-incident review.
  • Strong analytical judgment, with the ability to separate false positives from real risk and explain findings clearly.
  • Ability to work independently, document investigations clearly, and escalate issues with the right level of urgency.
  • Strong communication skills and the ability to work with Security, IT, DevOps, R&D, Product Security, Compliance, and business stakeholders.
  • Close attention to detail, strong ownership, and comfort working in a fast-moving production environment.

Additional Strengths

  • Experience in healthcare, healthtech, medical devices, digital health, or regulated software environments.
  • Familiarity with HIPAA, GDPR, SOC 2, ISO 27001, NIST CSF, or similar security and privacy frameworks.
  • Familiarity with MITRE ATT&CK, detection logic, attacker behavior, and investigation playbooks.
  • Experience with threat hunting, detection engineering, malware analysis, forensics, or advanced incident response.
  • Experience with SOAR platforms, case management systems, threat intelligence feeds, detection-as-code, or SOC automation.
  • Experience improving SOC metrics such as alert noise, false-positive rate, time to triage, time to escalation, and investigation quality.
  • Experience working with sensitive data, PHI/PII, customer-facing environments, or audit-ready evidence collection.

Working at Aidoc

Our Perks:

  • Be part of something big - using cutting-edge technologies to transform the Healthcare industry (while saving patients’ lives)
  • We work in a hybrid model, with our new offices located at 34 HaMasger Street in Tel Aviv and parking for employees.
  • Amazing and healthy breakfasts and lunches prepared daily by our personal chef!
  • Stocked up kitchen & meal card
  • Wellness: Aidoc employees-only gym, plus Pilates, Yoga, and functional workouts classes.
  • Amazing culture - collaborative, transparent & fun!
  • Attractive compensation package & benefits

Aidoc is deeply committed to creating an inclusive workplace, and to the principle of equal opportunity for all individuals. We prohibit discrimination and harassment based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other status protected by law.