24 Aug
|
Kbr
|
New South Wales
24 Aug
Kbr
New South Wales
Job Description
Key Responsibilities
n
n
Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents.
n
Perform initial triage and analysis of suspicious events and potential security incidents.
n
Determine incident severity, scope, and business impact.
n
Contain security incidents through actions such as:
n
Device isolation
n
IP and domain blocking
n
Escalate complex or high-severity incidents to senior security personnel.
n
Analyze endpoint, network, identity, and cloud telemetry.
n
Correlate indicators of compromise (IOCs) with threat intelligence sources.
n
Conduct malware investigations and support forensic analysis activities.
n
Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.;
n
Maintain detailed incident records and case documentation.
n
Create incident reports detailing findings, actions taken, and business impact.
n
Ensure evidence is collected, preserved, and documented appropriately.
n
Participate in post-incident reviews and lessons-learned sessions.
n
Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations.
n
Support major incident response activities and virtual war room operations during significant security events.
n
Contribute to development of SOC playbooks and response procedures.
n
Recommend improvements to detection rules, monitoring coverage, and response workflows.
n
Assist in threat hunting and security control validation activities.
n
Stay current with emerging threats, vulnerabilities, and industry best practices.
n
n
Required Qualifications
n
Education
n
n
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology,
or equivalent experience or,
n
2-5+ years of cybersecurity, SOC, incident response, or security operations experience.
n
Familiarity with Windows, Linux, cloud platforms, and enterprise networking.
n
n
Technical Skills
n
n
Familiarity with
n
SIEM technologies
n
Email security technologies
n
Identity platforms such as Active Directory and Entra ID
n
Network protocols and traffic analysis
n
n
Preferred Certifications
n
n
Baseline Clearance, NV-1 Eligible or Existing NV-1 Preferred
n
GCIA
n
GCFA
n
CISSP
n
Security+
n
CySA+
n
SC-200 (Microsoft Security Operations Analyst)
n
n
Working Conditions
n
n
Participation in a 24x7 SOC shift rotation and on-call coverage as required.
n
Support for major cybersecurity incidents outside normal business hours.
n
Ability to manage multiple concurrent security investigations.
n
n
Why Join KBR?
n
At KBR, our people are at the heart of everything we do. Our success is built on a culture of caring, collaboration, trust and continuous learning, where every team member feels safe, supported, valued and empowered to thrive.
n
We are committed to creating an inclusive environment where people can belong, connect and grow, while doing meaningful work that makes a lasting impact on communities across Australia. Through genuine collaboration and strong partnerships with our clients, we deliver innovative and sustainable solutions for a better tomorrow.
n
When you join KBR, you'll become part of a team that shares common values, works together towards a common purpose, and genuinely cares about the success and wellbeing of its people.
n
Benefits
n
n
Industry leading salaries reviewed annually.
n
Adaptable work arrangements (start/finish times, WFH, Flex time)
n
#J-*****-Ljbffr
📌 Soc Incident Responder (New South Wales)
🏢 Kbr
📍 New South Wales