--- title: 'SOC Analyst at Cato Networks' canonical: 'https://feeny.ai/job/soc-analyst-cato-networks-tel-aviv-30y16xz5xtnb' type: 'job' last_seen: '2026-09-06' --- # SOC Analyst at Cato Networks - **Company:** Cato Networks - **Location:** Tel Aviv, Israel - **Posted:** 2026-09-02 - **Last confirmed live:** 2026-09-06 - **Apply:** https://www.catonetworks.com/careers/careers-post/4966895101?gh_jid=4966895101 ## Job description Welcome to the future of cloud networking and security! Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by networking and security pioneer Shlomo Kramer (Check Point, Imperva) and early investor (Palo Alto Networks, Exabeam, Trusteer and more). Cato’s unique technology inspired a brand-new product category, later named “SASE” by Gartner and a market expected to reach $28.5 billion by 2028. This is your opportunity to get on the rocket ship and join a company that is building a cutting-edge enterprise network and secure cloud platform, and is on a fast track to becoming the worldwide market leader – don’t miss it! As a SOC Analyst, you will be part of the team responsible for real-time monitoring, detection, investigation, and response to security incidents affecting our global infrastructure and services, within a 24x7 operational environment. This is a hybrid analyst and operations role. Beyond investigating incidents, you will own significant parts of how the SOC runs: the SIEM platform, the detection rule lifecycle, exclusion and exception handling, response automation, and the AI-assisted workflows we use to accelerate triage and investigation. You will be the only SOC analyst based in Israel, while the rest of the analyst team operates from the Philippines. You will act as the SOC’s local anchor — the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve, not only to operate. ## Responsibilities - Monitoring and Detection: Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions to identify potential threats. - Incident Response: Serve as one of the first levels of escalation for security incidents - investigate, contain, and drive resolution before escalating to the senior SecOps members, in accordance with defined procedures and SLAs. - Incident Coordination: Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items. - Threat Analysis: Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts to determine root cause, scope, impact, and remediation steps. - SIEM and Detection Engineering: Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, and maintain detection rules while measuring their effectiveness. - Exclusion and Exception Management: Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically. - Automation and AI-Assisted Operations: Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output. - Investigation Documentation: Create and maintain detailed incident tickets, including investigation audit trail, action items, and timelines. - Technical Leadership: Act as the senior operational reference for the analyst team: help prioritize workload, assure investigation quality, maintain consistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling and methodology. - Collaboration: Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones. - Continuous Improvement: Drive improvements to detection logic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents. - Compliance and Reporting: Support reporting for compliance audits, management reviews, and threat intelligence updates. ## Requirements - 3–5 years of hands-on experience in a SOC or cybersecurity operations role. - Proven experience with a SIEM platform, including detection rule engineering and content development (Advantage: Elastic). - Experience with EDR and additional security tools and platforms (Advantage: CrowdStrike Falcon). - Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes. - Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls. - Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert. - High degree of ownership and autonomy - able to operate as the only analyst on site, set priorities independently, and drive tasks to closure. - Excellent communication skills and the ability to work effectively with distributed teams across time zones. - Ability to work effectively on time-sensitive tasks, with a service-oriented approach toward internal stakeholders. - Proficiency in written and verbal English is a must. Advantage - Experience building SOAR pipelines or agentic AI workflows in a security context. - Experience with cloud security monitoring (AWS, Azure) and container/Kubernetes telemetry. - Experience working with or supporting an offshore/outsourced SOC team. - Experience with threat intelligence platforms (e.g., MISP) and intel-driven detection. ## About Cato Networks ## Company Overview - **One-liner**: Cato Networks provides the world’s leading single-vendor SASE (Secure Access Service Edge) platform, converging networking and security into a global, AI-powered cloud service. - **Entity Type**: Private (Series G funded, valuation >$4.8B) - **Headquarters**: Tel Aviv, Israel - **Founded**: 2015 - **Founders**: Shlomo Kramer (Co-Founder & CEO) and Eyal Heiman (Co-Founder & CTO) ## Core Business - **Primary industry**: Computer and Network Security (SASE, SD-WAN, Zero Trust, Cloud Security) - **Target customers**: Enterprise organizations (B2B) of all sizes, from mid-market to large global enterprises - **Mission or purpose statement**: To redefine enterprise security for the digital and AI era by simplifying infrastructure, unifying policy, and embedding security and AI into the digital business. ## Products & Services - **Cato SASE Cloud Platform**: A cloud-native service that converges SD-WAN, network security (firewall, threat prevention), Zero Trust Network Access (ZTNA), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), and Digital Experience Monitoring (DEM) into a single, global, AI-powered cloud service. - **Cato SSE (Security Service Edge)**: A standalone security offering that provides zero-trust protection, AI-driven incident detection, and data security independent of networking infrastructure. - **Cato Next Gen Networking**: A software-defined, cloud-optimized networking solution for resilient, high-performance connectivity between users, sites, and clouds. - **Cato AI Security**: A suite of capabilities securing AI interactions, including safe use of third-party AI, runtime protection of homegrown AI apps, and protection against agentic AI threats. - **Unified Management (CMA) & Platform API**: A single-pane-of-glass management application and API for policy enforcement, monitoring, and automation. ## Market Standing - **Valuation**: Over $4.8 billion (as of 2025) - **Key Metric**: Over $350 million in Annual Recurring Revenue (ARR) in 2025, growing at 43% year-over-year. - **Total Funding**: Over $1 billion raised since 2015 (Series G of $409M led by Vitruvian Partners and ION Crossover Partners in July 2025). - **Notable Investors/Partners**: Greylock, Lightspeed Venture Partners, Aspect Ventures, U.S. Venture Partners, Swisscom Ventures, Vitruvian Partners, ION Crossover Partners. - **Growth Signals**: Named a Leader in the 2025 Gartner® Magic Quadrant™ for SASE Platforms for the second consecutive year. Over 4,000 enterprise customers across thousands of global locations. Headcount grew 34.5% YoY to over 1,500 employees. ## Competitive Advantages - **First-Mover & Category Creator**: Cato pioneered the SASE category, which Gartner later named, giving it deep expertise and a proven track record. - **Unified Platform**: True single-vendor SASE with a single-pass engine, single data lake, and single policy enforcement, eliminating the complexity of managing multiple point solutions. - **Global Cloud-Native Architecture**: A self-optimizing global cloud service that rapidly deploys new capabilities and maintains security posture without customer effort. - **AI-Native Security**: Built-in AI for threat prevention, optimization, and governance of AI usage, positioning it for the next wave of enterprise security. - **Strong Financials & Backing**: Over $1B in funding and a $4.8B+ valuation signal strong market confidence and long-term stability. ## Strategic Focus - **SASE Convergence**: Driving the adoption of unified networking and security from the cloud, replacing legacy MPLS and disjointed security stacks. - **AI Security**: Capitalizing on the growing need to secure and govern AI usage within enterprises, including agentic AI. - **Global Expansion**: Expanding its employee base (25+ countries) and customer footprint, with strong presence in North America, Europe, and APJ. - **Platform Depth**: Continuously adding new capabilities (e.g., XDR, DEM, AI Security) to deepen the platform’s value and increase customer stickiness. ## Why Work Here - **High-Growth Environment**: The company is in a hypergrowth phase (43% ARR growth, 34.5% headcount growth), offering significant career advancement opportunities and the chance to work on cutting-edge technology. - **Industry Leadership**: Employees work on a category-defining platform recognized by Gartner, with the chance to shape the future of enterprise security. - **Experienced Leadership**: Founded by Shlomo Kramer (co-founder of Check Point and Imperva), providing a proven playbook for building a successful security company. - **Global & Diverse Team**: Over 1,500 employees across 25 countries, with a strong emphasis on internal promotion and professional growth. - **Culture & Perks**: Employees rate the company 4.3/5.0 on Glassdoor (251 reviews), with high marks for career development (4.2), culture (4.1), and compensation (4.1). The company emphasizes a “biggest and most rewarding challenge” ethos, with pride in employee growth. - **Remote/Hybrid Policy**: Not explicitly stated, but the global nature of the team (25 countries) suggests a flexible, remote-friendly culture, with significant hubs in Tel Aviv, the US, UK, and Philippines. ## Sources 1. [Cato Networks Official Site](https://www.catonetworks.com/) 2. [Cato Networks Careers Page](https://www.catonetworks.com/careers/) 3. [Cato Networks Company Page](https://www.catonetworks.com/company/) 4. [LinkedIn Company Profile](https://il.linkedin.com/company/cato-networks) 5. [Tracxn Company Profile](https://tracxn.com/d/companies/catonetworks/__ewuh_6rJuGM335IVQhRs851Q5ox4fDz1E6orZgkXKsg) ## Other roles at Cato Networks - [Biz Ops Coordinator (Temporary position for Maternity Leave)](https://feeny.ai/job/biz-ops-coordinator-temporary-position-for-maternity-leave-cato-networks-tel-4kmax8vvqsne) — Tel Aviv, Israel - [Channel Sales Engineer](https://feeny.ai/job/channel-sales-engineer-cato-networks-amsterdam-north-holland-jv3me0n4mgbh) — Amsterdam North Holland, Netherlands / Brussels, Belgium - [Channel Enablement Lead, Americas](https://feeny.ai/job/channel-enablement-lead-americas-cato-networks-united-states-193x17ag9839) — United States - [Sales Engineer, Northern Florida](https://feeny.ai/job/sales-engineer-northern-florida-cato-networks-jacksonville-florida-ppnx781cp7jn) — Jacksonville Florida, United States - [Support Enablement Engineer](https://feeny.ai/job/support-enablement-engineer-cato-networks-tel-aviv-72ak9y2f90n6) — Tel Aviv, Israel - [Payroll Specialist](https://feeny.ai/job/payroll-specialist-cato-networks-prague-rkpvb61nky5y) — Prague, Czech Republic - [Front End Platform Engineer](https://feeny.ai/job/front-end-platform-engineer-cato-networks-prague-ea3tr85v4y8n) — Prague, Czech Republic - [Regional Sales Director, Quebec](https://feeny.ai/job/regional-sales-director-quebec-cato-networks-montreal-anb0kc2vvv4f) — Montréal, Canada - [Product Support Engineer, T3](https://feeny.ai/job/product-support-engineer-t3-cato-networks-manila-bqa9w7x2eh7k) — Manila, Philippines - [Head of Sales Development](https://feeny.ai/job/head-of-sales-development-cato-networks-singapore-ea3bmv71m82t) — Singapore