Nir Hason

Nir Hason

Cloud security & technical support engineer

Twelve years finding out what actually happened — WAF, SIEM, packet capture, and the integrations in between.

Best fit Technical Support Engineer · Cloud Security Engineer · Security Integrations

me [at] nirhason [dot] com

  • 12 yearssecurity, networking & support
  • 7 yearsCloud WAF, enterprise services
  • Escalationslarge enterprise production incidents
  • SIEM & captureSplunk, Graylog, Wireshark
  • APIsREST, webhooks & automation

note to the curious

You typed the domain in. Most people don’t. It always resolved — it just took me until now to put something here worth the round trip.

monitored
[ 03:14:09 ]

something to do while you decide

There is a compromised host on this site. It has logs, a mailbox nobody can read, a sudoers file with a mistake in it, and six flags. It runs entirely in your own tab and cannot reach anything. Open ARACHNE →

6 flags

Tracks

Two ways to use me

Same twelve years, read two ways. Which résumé you get depends on which problem you have.

Investigate

Security & network engineering

For when the traffic looks wrong and nobody can say why. WAF events, SIEM correlation, HTTP behaviour, packet captures — turned into an RCA that names the cause, mapped to OWASP Top 10 and MITRE ATT&CK, with a mitigation somebody can actually deploy.

Integrate

Technical support & integrations

For when systems need to talk to each other and refuse to. REST APIs, webhooks, JSON payloads, authentication, production escalations — plus the runbooks and documentation that keep the next incident boring.

Experience

Where the twelve years went

  1. 2025–2026

    Head of Operations & Technology

    Nonprofit organization · Israel

    • Owned the organization’s technology end to end — CRM, Google Workspace, telephony, time-tracking — and integrated them into one working system.
    • Built internal tools that automated budgeting, payment processing, logistics and asset tracking, and digital employee onboarding.
    • Shipped a donations website with live payment processing, and dashboards that made recurring issues visible instead of anecdotal.
    • Cut dozens of hours of manual work a month while improving traceability and documentation.
  2. 2018–2025

    Cloud Security Engineer, Enterprise Services

    Imperva / Thales · Israel

    • Ran technical delivery for large enterprise WAF and Cloud WAF accounts: production incidents, policy tuning, remediation guidance and customer-facing escalations.
    • Investigated web attacks using WAF events, SIEM and log data, HTTP traffic and packet captures; mapped findings to OWASP Top 10 and MITRE ATT&CK.
    • Built and operated centralised log-analysis environments in Graylog, Splunk and Grafana to filter noise and surface attacker behaviour.
    • Produced RCA findings, mitigation plans and escalation handoffs for incidents involving false positives, misconfiguration, availability and exposure.
    • Wrote Python reports and utilities to speed up evidence collection and recurring analysis.
  3. 2012–2018

    IT Communication & Telephony Focal Point

    Amdocs · Israel

    • Led IT support for enterprise network, communication and infrastructure issues; coordinated escalations across global support teams.
    • Troubleshot routing and switching, firewalls, load balancers, Active Directory, DNS, DHCP, Linux/Windows servers and VMware.
    • Configured and supported Cisco, Juniper, Check Point and F5 equipment; maintained documentation and trained engineers.
  4. 2009–2012

    Network Technician & NOC Supervisor

    Israeli Air Force

    • Supervised a 12-person NOC team and coordinated incident response for critical operational networks.
    • Maintained critical infrastructure remotely and on site, including Juniper-based routing and switching and IP camera networks.

Selected work

Mesharim

A live SaaS platform spanning transcription, payments and invoicing, document handling and day-to-day support workflows — designed and operated end to end, through to its first paying customer.

live
  • Integrated transcription, payment, invoicing, SMS and document services through REST APIs and webhooks, with PostgreSQL/Supabase underneath for data inspection and troubleshooting.
  • Built structured logging, a sysadmin diagnostics toolbox, and in-app issue reporting with screenshot and HAR capture — so a bug report arrives with its own evidence attached.
  • Triaged incidents by severity and resolved them through staging and regression checks before they reached production.
  • Managed code, issues and releases in GitHub with CI/CD, and supported onboarding and daily use for the first live customer.

Toolbox

What’s actually in the kit

Investigate
WAF events · HTTP behaviour · packet captures · Wireshark · Fiddler · Nmap · VirusTotal
Analyze
Splunk · Graylog · Grafana · SIEM data · evidence collection · root cause analysis
Secure
Imperva WAF / Cloud WAF · OWASP Top 10 · MITRE ATT&CK · AWS IAM · Active Directory · defence in depth · least privilege
Automate
Python · PowerShell · REST APIs · webhooks · SQL / PostgreSQL · recurring analysis
Networks & systems
Cisco · Juniper · FortiGate · Check Point · F5 · TCP/IP · DNS/DHCP · Linux/Windows · VMware · Kubernetes basics
Workflow
ServiceNow · Salesforce · GitHub · CI/CD · Cloudflare · AWS

Credentials

On paper

Certifications

  • Cisco CCNA
  • Juniper JNCIA-ER
  • ITIL Foundation
  • CompTIA A+

Languages

  • Hebrew — native
  • English — full professional

Clearance

  • High-classification security clearance. Details on request.

Contact

Want the short version? Email me — or scroll back and read the work.

me [at] nirhason [dot] com

Prefer to skim first? Experience, selected work, or the toolbox.

Based in Israel. Open to cloud security, technical support engineering and integration roles. Happy to talk through a specific incident or integration problem — that tends to be the fastest interview.