28 Aug
|
Kbr
|
New South Wales
28 Aug
Kbr
New South Wales
Job Description
Key Responsibilities
n
n
- Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents.
n
- Perform initial triage and analysis of suspicious events and potential security incidents.
n
- Determine incident severity, scope, and business impact.
n
- Contain security incidents through actions such as:
n
- Device isolation
n
- IP and domain blocking
n
- Escalate complex or high-severity incidents to senior security personnel.
n
- Analyze endpoint, network, identity, and cloud telemetry.
n
- Correlate indicators of compromise (IOCs) with threat intelligence sources.
n
- Conduct malware investigations and support forensic analysis activities.
n
- Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.;
n
- Maintain detailed incident records and case documentation.
n
- Create incident reports detailing findings, actions taken, and business impact.
n
- Ensure evidence is collected, preserved, and documented appropriately.
n
- Participate in post-incident reviews and lessons-learned sessions.
n
- Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations.
n
- Support major incident response activities and virtual war room operations during significant security events.
n
- Contribute to development of SOC playbooks and response procedures.
n
- Recommend improvements to detection rules, monitoring coverage, and response workflows.
n
- Assist in threat hunting and security control validation activities.
n
- Stay current with emerging threats, vulnerabilities, and industry best practices.
n
n
Required Qualifications
n
Education
n
n
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology,
or equivalent experience or,
n
- 2-5+ years of cybersecurity, SOC, incident response, or security operations experience.
n
- Familiarity with Windows, Linux, cloud platforms, and enterprise networking.
n
n
Technical Skills
n
n
- Familiarity with
n
- SIEM technologies
n
- Email security technologies
n
- Identity platforms such as Active Directory and Entra ID
n
- Network protocols and traffic analysis
n
n
Preferred Certifications
n
n
- Baseline Clearance, NV-1 Eligible or Existing NV-1 Preferred
n
- GCIA
n
- GCFA
n
- CISSP
n
- Security+
n
- CySA+
n
- SC-200 (Microsoft Security Operations Analyst)
n
n
Working Conditions
n
n
- Participation in a 24x7 SOC shift rotation and on-call coverage as required.
n
- Support for major cybersecurity incidents outside normal business hours.
n
- Ability to manage multiple concurrent security investigations.
n
n
Why Join KBR?
n
At KBR, our people are at the heart of everything we do. Our success is built on a culture of caring, collaboration, trust and continuous learning, where every team member feels safe, supported, valued and empowered to thrive.
n
We are committed to creating an inclusive workplace where people can belong, connect and grow, while doing meaningful work that makes a lasting impact on communities across Australia. Through genuine collaboration and strong partnerships with our clients, we deliver innovative and sustainable solutions for a better tomorrow.
n
When you join KBR, you'll become part of a team that shares common values, works together towards a common purpose, and genuinely cares about the success and wellbeing of its people.
n
Benefits
n
n
- Industry leading salaries reviewed annually.
n
- Flexible work arrangements (start/finish times, WFH, Flex time)
n
n
#J-18808-Ljbffr
📌 SOC Incident Responder (New South Wales)
🏢 Kbr
📍 New South Wales