16 Aug
|
Jobtailor
|
City of Sydney
16 Aug
Jobtailor
City of Sydney
- Lead a team of subject matter experts and analysts to ensure Information Security is managed and continuously improved in line with Bank policy and procedure.
- Supporting the development and progression of the Information Security Analyst team from both a technical and professional perspective.
- Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include:
- Cloud Infrastructure/Security.
- Endpoint Detection and Response.
- Perimeter detection tooling.
- Conduct Quality Assurance for Triage case handling, mitigation actions and shift handover, collating lessons learned and implementing improvements where required.
- Interpret logs from a variety of sources (e.g. cloud, endpoint, network) to identify root cause and determine next steps for containment, eradication and recovery as part of incident response activities.
- Work together with other teams in the organisation to analyse, contain, eradicate and recover from cyber security incidents
- Continuous development and maintaining of incident handling, response and readiness processes.
- Support the wider SecOps team with detection engineering - creating and optimising analytic triggers to enhance alert efficacy - and threat hunting based on threat intelligence.
- Documentation of incidents and investigations, including analysis findings, containment steps and root cause.
- Plan and participate in Tabletop Exercises.
- Present investigation findings to technical and non-technical audiences.
Requirements
- 5+ years experience in an in-house SOC role and team, including cyber incident response and digital forensics function.
- Experience in a similar role leading,
developing and motivating a team of subject matter experts and other managers in Information & Cyber Security.
- Understanding of AWS Security Solutions (or other Public Cloud Solutions)
- Analysis and Incident Response experience with Cloud systems (GCP, AWS)
- Experience working and supporting analytics/SIEM platforms.
- Experience supporting and conducting Incident Response engagements.
- Experience in endpoint based investigations.
- Experience in cloud based investigations.
- Experience with Incident Command and conducting Tabletop Exercises.
- Experience in acting as both Commander and SME during incidents and investigations.
- Be a Self Starter with the ability to lead, inspire and drive change through an organisation.
- Excellent communication skills (both verbal and written), ability to communicate technical concepts to both technical and non-technical audiences.
- Demonstrated teamwork and collaboration skills as part of a multi-functional team
- Time management, problem-solving and interpersonal skills.
- Eagerness to learn and apply knowledge to new security challenges.
- Willingness to share knowledge with the team and mentor colleagues.
- - A high level understanding of mobile, network and operating system security controls.
- Preferred
- Experience in forensics:
cloud (GCP, AWS); endpoint/server (Windows, MacOS, Linux); and/or network.
- Any experience of programming in Python, Go and/or Java.
- A Cyber/Information Security related degree and/or relevant cyber security qualification(s) would be desired but not required
- Understanding of malware analysis techniques
Core Competencies
Demonstrates expertise in Incident Response, Cyber Security, and Team Leadership, with a robust focus on developing and mentoring teams while managing security incidents effectively. Proficient in utilizing Cloud Security Solutions and analytics platforms to enhance security posture and incident handling processes.
Highest-signal resume keywords
- Incident Response Management
- Cloud Security Solutions (AWS, GCP)
- Team Leadership and Development
- Analytic/SIEM Platform Support
- Digital Forensics Expertise
ATS Optimization Keywords
Hard Skills
- Incident Triage
- Cloud Systems Analysis
- Endpoint Investigation
- Malware Analysis Techniques
- Programming (Python, Go, Java)
Soft Skills
- Excellent Communication Skills
- Teamwork and Collaboration
- Time Management
- Problem-Solving
- Interpersonal Skills
Certifications & Qualifications
- Cyber/Information Security Degree
- Relevant Cyber Security Qualifications
Industry Keywords
- Information Security
- Cyber Security
- Digital Forensics
- Incident Command
- Tabletop Exercises
Tools & Technologies
- Cloud Infrastructure Security
- Endpoint Detection and Response
- Perimeter Detection Tooling
- SIEM Platforms
- Incident Command Systems
#J-18808-Ljbffr
📌 Information Security Operations Lead (City of Sydney)
🏢 Jobtailor
📍 City of Sydney