21 Aug
|
Baidam
|
New South Wales
21 Aug
Baidam
New South Wales
Job Description
Sydney, Brisbane or Perth (hybrid working available - three days in the office)
n
Employment
n
Full-time, rotating roster supporting 24x7 SOC operations
n
About Baidam Solutions
n
Baidam Solutions is an Australian-owned cybersecurity services provider with a robust social impact mission. We partner with First Nations communities, customers, and global technology providers to deliver leading-edge security solutions while creating pathways for Indigenous participation in the ICT industry.
n
Our Security Operations Centre (SOC) is growing, and we are seeking talented Level 2 SOC Analysts who are passionate about defending organisations against cyber threats, improving detection and response processes, and contributing to a skilled and diverse cyber workforce in Australia.
n
Why Join Us
n
n
- Competitive salary and clear progression pathways into senior cyber security roles.
n
- Investment in ongoing training and industry-recognised certifications, including SANS, Microsoft, CrowdStrike and Splunk.
n
- Hybrid working flexibility within a supportive, collaborative and multicultural team environment.
n
- Hands‐on exposure to leading security technologies, including Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon Next‐Gen SIEM, SOAR and advanced threat intelligence platforms.
n
- The opportunity to join a purpose‐driven organisation that delivers measurable social impact.
n
n
Key Responsibilities
n
n
- Investigate, validate, triage and respond to security alerts and incidents across Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon Next‐Gen SIEM, EDR/XDR, SOAR and cloud security platforms.
n
- Perform deeper technical analysis of complex incidents across endpoint, identity, cloud and network environments, and escalated matters requiring specialist or senior support.
n
- Lead or support incident response activities for escalated security events, including containment, eradication, recovery and post‐incident review.
n
- Conduct proactive threat hunting using telemetry from CrowdStrike Falcon, Microsoft Sentinel, Microsoft Defender XDR and other security technologies.
n
- Onboard new customers, data sources and security technologies into the SOC, including validating data quality, parsing, normalisation and end‐to‐end alerting.
n
- Develop, test, tune and maintain detection rules, correlation logic and analytics to improve coverage,
increase alert fidelity and reduce false positives.
n
- Create and maintain KQL and other investigation queries, analytics rules, automation workflows, SOAR playbooks and investigation documentation.
n
- Identify gaps in visibility, logging, telemetry and detection coverage, and recommend practical improvements.
n
- Work directly with customers to investigate incidents, communicate findings and provide clear, actionable technical recommendations.
n
- Produce high‐quality documentation, including incident reports, post‐incident reviews, knowledge articles, investigation procedures and SOC playbooks.
n
- Support the continuous improvement of SOC processes, playbooks, response procedures, detections and operational maturity.
n
- Mentor Level 1 SOC Analysts, assist with complex investigations and contribute to the ongoing development of the wider SOC team.
n
- Stay current with emerging threats, vulnerabilities, attacker techniques and modern detection engineering practices.
n
- Participate in an on‐call rotation to support incident escalation and operational requirements outside standard business hours.
n
n
What We're Looking For
n
Skills and Experience
n
n
- Previous experience working in a SOC, security operations, cyber defence or incident response role is mandatory.
n
- Hands‐on experience investigating, validating and responding to security alerts and incidents.
n
- Experience performing Level 2 analysis and managing complex investigations across Windows, Microsoft 365, Azure, endpoint, identity and cloud environments.
n
- Experience onboarding customers, log sources, security products or data integrations into a SIEM platform.
n
- Experience developing, testing and tuning security detections, correlation rules and alert logic.
n
- Strong practical knowledge of Microsoft Sentinel, Microsoft Defender XDR and CrowdStrike Falcon Next‐Gen SIEM.
n
- Experience with enterprise SIEM platforms such as Microsoft Sentinel, CrowdStrike Falcon Next‐Gen SIEM, Splunk, Google SecOps or similar.
n
- Experience with EDR/XDR platforms, SOAR technologies and security automation workflows.
n
- Familiarity with KQL, SPL or similar query languages; basic PowerShell or Python scripting capability is desirable.
n
- Understanding of common attack techniques, identity threats, endpoint security, cloud security and the MITRE ATT&CK; framework.
n
- Ability to identify security gaps and translate technical findings into practical improvements.
n
- Strong written and verbal communication skills, with the ability to engage effectively with technical and non‐technical stakeholders.
n
- A proactive, team-oriented approach to problem‐solving and continuous improvement.
n
- Ability to prioritise multiple incidents in a fast‐paced, 24x7 managed SOC environment.
n
- Experience working within a Managed Security Service Provider (MSSP) or customer‐facing managed SOC environment.
n
- Demonstrated hands‐on experience with Microsoft Sentinel, Microsoft Defender XDR and CrowdStrike products.
n
- Experience supporting multiple customer environments and balancing competing operational priorities.
n
n
Security Knowledge
n
n
- Incident response and security operations best practice.
n
- Threat intelligence and threat hunting.
n
- Malware analysis fundamentals and digital forensics concepts.
n
- MITRE ATT&CK; framework and Cyber Kill Chain.
n
- Microsoft Azure and Microsoft 365 security.
n
n
Clearance Requirements
n
n
- Australian Citizenship is required.
n
- Ability to obtain and maintain an Australian Government Security Clearance.
n
n
Desirable Certifications
n
n
- CrowdStrike Falcon Administrator or Falcon Hunter
n
- Microsoft SC‐200
n
- Microsoft AZ‐500
n
- CompTIA Security+
n
- GIAC GCIH or GCIA
n
- Security Blue Team certifications
n
n
Salary and Benefits
n
n
- Salary range of AUD $110,000-$140,000 plus superannuation, depending on experience.
n
- Dedicated training budget for Microsoft, CrowdStrike and SANS certifications.
n
- Exposure to enterprise government, critical infrastructure and commercial environments.
n
- Career pathways into Senior SOC Analyst, Detection Engineer, Incident Response and Threat Hunting roles.
n
- Indigenous mentoring, education programs and career pathways unique to Baidam Solutions.
n
- Flexible hybrid work model with SOC presence in Sydney, Brisbane and Perth.
n
#J-18808-Ljbffr
📌 Security Operations Center Analyst (New South Wales)
🏢 Baidam
📍 New South Wales