Cyber Security Operations Analyst (SOC / Threat Detection)
Monitor, triage, and remediate security events, incident responses, and threat telemetry within an Australian defence/enterprise supply chain context.
Key Responsibilities & Deliverables
- Triage and investigate alerts generated by SIEM and EDR platforms (Splunk, CrowdStrike, Microsoft Sentinel).
- Conduct triage, containment, and eradication for security incidents following Australian standard playbooks.
- Assist in the operationalisation of ACSC Essential Eight mitigation strategies across client endpoints and cloud environments.
- Participate in threat hunting exercises and threat intelligence correlation.
Candidate Requirements & Vetting Criteria
- 3+ years experience in a Security Operations Centre (SOC) or security engineering role in Australia.
- Strong understanding of network protocols, operating system internals, and MITRE ATT&CK framework.
- Relevant industry certifications (Security+, CySA+, CEH, or GIAC) preferred.
- Must hold or be eligible to obtain an Australian Government Security Clearance (NV1 preferred).
Target Competencies & Skill Matrix
Remuneration Package & Benefits
We are seeking a Cyber Security Operations Analyst to join an established security operations centre (SOC) in Canberra. This role is responsible for proactive threat hunting, incident triage, and hardening enterprise assets against evolving cyber threats.
Ready to apply?
Your profile will be reviewed strictly by the assigned sector practice lead.
Similar Roles in IT & Technology
Lead Cloud & DevOps Engineer (AWS / Kubernetes / Terraform)
Drive cloud infrastructure modernization, multi-cluster Kubernetes orchestration, and automated GitOps pipelines for a prominent national logistics organisation.
Senior Full-Stack Software Engineer (TypeScript / Node.js / React)
Lead the design and development of modern cloud-native distributed microservices for an established Australian enterprise fintech platform.