Nir Hason security · network · integrations

Nir Hason

Security & network engineer

Twelve years finding out what actually happened — WAF, SIEM, packet capture, and the integrations in between.

me [at] nirhason [dot] com

note to the curious

You typed the domain in. Most people don’t. Yes — it resolves. It always did; there was just nothing here worth serving until now.

monitored

Tracks

Two ways to use me

Same twelve years, read two ways. Which résumé you get depends on which problem you have.

Investigate

Security & network engineering

For when the traffic looks wrong and nobody can say why. WAF events, SIEM correlation, HTTP behaviour, packet captures — turned into an RCA that names the cause, mapped to OWASP Top 10 and MITRE ATT&CK, with a mitigation somebody can actually deploy.

Integrate

Technical support & integrations

For when systems need to talk to each other and refuse to. REST APIs, webhooks, JSON payloads, authentication, production escalations — plus the runbook and the documentation nobody else wanted to write.

History

Where the twelve years went

  1. 2025–2026

    Head of Operations & Technology

    Nonprofit organization · Israel

    • Owned the organization’s technology end to end — CRM, Google Workspace, telephony, time-tracking — and integrated them into one working system.
    • Built internal tools that automated budgeting, payment processing, logistics and asset tracking, and digital employee onboarding.
    • Shipped a donations website with live payment processing, and dashboards that made recurring issues visible instead of anecdotal.
    • Cut dozens of hours of manual work a month while improving traceability and documentation.
  2. 2018–2025

    Cloud Security Engineer, Enterprise Services

    Imperva / Thales · Israel

    • Ran technical delivery for large enterprise WAF and Cloud WAF accounts: production incidents, policy tuning, remediation guidance and customer-facing escalations.
    • Investigated web attacks using WAF events, SIEM and log data, HTTP traffic and packet captures; mapped findings to OWASP Top 10 and MITRE ATT&CK.
    • Built and operated centralised log-analysis environments in Graylog, Splunk and Grafana to filter noise and surface attacker behaviour.
    • Produced RCA findings, mitigation plans and escalation handoffs for incidents involving false positives, misconfiguration, availability and exposure.
    • Wrote Python reports and utilities to speed up evidence collection and recurring analysis.
  3. 2012–2018

    IT Communication & Telephony Focal Point

    Amdocs · Israel

    • Led IT support for enterprise network, communication and infrastructure issues; coordinated escalations across global support teams.
    • Troubleshot routing and switching, firewalls, load balancers, Active Directory, DNS, DHCP, Linux/Windows servers and VMware.
    • Configured and supported Cisco, Juniper, Check Point and F5 equipment; maintained documentation and trained engineers.
  4. 2009–2012

    Network Technician & NOC Supervisor

    Israeli Air Force

    • Supervised a 12-person NOC team and coordinated incident response for critical operational networks.
    • Maintained critical infrastructure remotely and on site, including Juniper-based routing and switching and IP camera networks.

Selected work

Mesharim

A production SaaS platform, designed and operated end to end.

live
  • Integrated transcription, payment, invoicing, SMS and document services through REST APIs and webhooks, with PostgreSQL/Supabase underneath for data inspection and troubleshooting.
  • Built structured logging, a sysadmin diagnostics toolbox, and in-app issue reporting with screenshot and HAR capture — so a bug report arrives with its own evidence attached.
  • Triaged incidents by severity and resolved them through staging and regression checks before they reached production.
  • Managed code, issues and releases in GitHub with CI/CD, and supported onboarding and daily use for the first live customer.

Toolbox

What’s actually in the kit

Investigate
WAF events · HTTP behaviour · packet captures · Wireshark · Fiddler · Nmap · VirusTotal
Analyze
Splunk · Graylog · Grafana · SIEM data · evidence collection · root cause analysis
Secure
Imperva WAF / Cloud WAF · OWASP Top 10 · MITRE ATT&CK · AWS IAM · Active Directory · defence in depth · least privilege
Automate
Python · PowerShell · REST APIs · webhooks · SQL / PostgreSQL · recurring analysis
Networks & systems
Cisco · Juniper · FortiGate · Check Point · F5 · TCP/IP · DNS/DHCP · Linux/Windows · VMware · Kubernetes basics
Workflow
ServiceNow · Salesforce · GitHub · CI/CD · Cloudflare · AWS

Credentials

On paper

Certifications

  • Cisco CCNA
  • Juniper JNCIA-ER
  • ITIL Foundation
  • CompTIA A+

Languages

  • Hebrew — native
  • English — full professional

Clearance

  • High-classification security clearance. Details on request.

Contact

You already have the address. It’s in the email that sent you here.

me [at] nirhason [dot] com

Based in Israel. Open to security engineering, technical support and integration roles.