24 Aug
|
TheDriveGroup
|
Melbourne
24 Aug
TheDriveGroup
Melbourne
We’re looking for a highly technical Senior Cyber Security Analyst to join a large critical infrastructure organisation, taking a senior role across incident response, threat hunting, detection and cyber investigations.
This isn’t a traditional SOC role centred around alert triage. You’ll take ownership of complex investigations across IT and OT environments, act as a senior technical escalation point, and coordinate offshore security resources when incidents require deeper investigation.
There’s no requirement to have formally managed a team, but you’ll need the technical credibility and confidence to lead investigations, coordinate resources and make decisions when incidents become complex.
What you’ll be doing
- Lead complex cyber security investigations and incident response activities
- Investigate endpoint, identity and network-based threats across Windows and Linux environments
- Analyse Windows and Linux forensic artefacts to understand attacker activity and determine the scope of compromise
- Use CrowdStrike Falcon, Microsoft Defender and Microsoft Sentinel to investigate suspicious activity
- Query and analyse security data using KQL
- Conduct threat hunting based on attacker behaviours, TTPs and threat intelligence
- Perform network analysis to identify compromise, lateral movement and malicious behaviour
- Coordinate offshore analysts and other technical teams during investigations
- Develop and tune detections across SIEM, EDR and XDR platforms
- Improve incident response processes, runbooks and investigation procedures
- Support cyber security monitoring and investigations across IT and Operational Technology (OT) environments
What we’re looking for You’ll ideally come from a Senior SOC, Incident Response, DFIR,
Threat Detection or Cyber Defence background and be comfortable independently owning an investigation from initial alert through to containment and remediation.
Strong experience across:
- Incident Response / DFIR / Cyber Investigations
- Windows and Linux forensic artefacts
- Network and traffic analysis
- CrowdStrike Falcon
- Microsoft Defender
- Microsoft Sentinel & KQL
- Active Directory / Entra ID investigations
- Threat hunting and attacker TTPs
- SIEM / EDR / XDR technologies
- Python, PowerShell or security automation
Exposure to OT/ICS environments, critical infrastructure, energy, utilities, mining or other highly regulated environments would be highly regarded.
The person Technical capability is important, but so is how you operate.
We’re looking for someone who takes ownership, investigates beyond the initial alert and can piece together activity across endpoints, identities and networks to understand what has actually happened.
You’ll be comfortable working independently, taking initiative and acting as a senior technical point of escalation while collaborating with both local and offshore teams.
If you’re a senior cyber security skilled who enjoys getting deep into investigations while taking greater technical ownership and leadership, apply now for a confidential discussion.
If you have any questions about this role or others we have available, you can contact Hayley directly via ••••@thedrivegroup.com.au.
TheDriveGroup is 100% committed to improving meaningful diversity in the technology industry. We partner with clients who embrace diversity and seek candidates across all backgrounds, abilities, genders, sexualities, cultures and beliefs.
If you would like to find out more about TheDriveGroup and our opportunities, please visit our website or follow us on LinkedIn.
📌 Senior Cyber Security Analyst (Melbourne)
🏢 TheDriveGroup
📍 Melbourne