Lead Security Analyst – Cyber Threat / SOC | Defence (Australian Capital Territory)

Lead Security Analyst – Cyber Threat / SOC | Defence (Australian Capital Territory)

17 Sep
|
Azooa
|
Australian Capital Territory

17 Sep

Azooa

Australian Capital Territory

Lead Security Analyst – Cyber Threat / SOC | Defence

Location: ACT or SA

Work Arrangement: Onsite

Contract: 12 months + 2 x 12-month extension options

Hours: Up to 40 hours per week

Estimated Start: 30 November 2026

Experience Level: Lead / EL1 equivalent

Security Clearance: Current TSPV required

Positions Available: 2

Azooa is seeking experienced Lead Security Analysts / Cyber Threat Analysts for a significant Australian Government Defence cyber security engagement supporting the Australian Signals Directorate (ASD) .

This opportunity is suited to highly experienced cyber security professionals with strong Security Operations Centre experience and hands-on capability across threat intelligence, security monitoring, Splunk Enterprise Security, EDR/NDR platforms, SOAR technologies, vulnerability analysis and incident response.

About the Role The Lead Security Analyst will be responsible for assessing, monitoring and strengthening the organisation's security posture using a threat-driven approach.

Working closely with technical teams and security leadership, you will analyse cyber threats, monitor security events, identify vulnerabilities, support incident response capability and ensure effective security controls and monitoring processes are in place across critical systems.

This is a senior hands-on security role requiring strong technical analysis capability as well as the ability to support technical leadership and system security assurance activities.

Key Responsibilities

You will be responsible for:

- Performing threat-driven analysis of system security.
- Analysing threat intelligence to identify system-specific cyber threats.
- Monitoring security events and security information for potential and confirmed security incidents.
- Developing, maintaining and using incident response plans and playbooks.
- Analysing security vulnerabilities and recommending appropriate remediation or risk treatments.
- Reviewing existing system security controls to identify vulnerabilities or weaknesses.
- Developing procedures for monitoring and analysing security information and events.
- Supporting the planning and delivery of test and evaluation activities for systems and products.




- Providing cyber security advice and support to the Technical Leadership team.
- Contributing to the ongoing improvement of security monitoring, detection and incident-response capabilities.

Essential Experience Successful candidates will need to demonstrate:

Security Operations Centre Experience

Strong demonstrated experience working within a Security Operations Centre (SOC) as a Security Analyst.

Splunk Enterprise Security

Demonstrated hands-on experience using Splunk Enterprise Security for security monitoring, investigation, analysis and/or detection.

Endpoint and Network Detection

Experience working with

- Endpoint Detection and Response (EDR) platforms; and
- Network Detection and Response (NDR) platforms.

Network Detection and Response Strong practical experience with NDR technologies, including security monitoring, detection, investigation and analysis.

Security Orchestration and Automation

Experience using a Security Orchestration, Automation and Response (SOAR) platform.

Desirable Experience

Highly regarded experience includes

- Knowledge of Australian Government information security requirements.
- Experience working within Defence, intelligence, national security or Federal Government environments.
- Knowledge or practical application of the ASD Information Security Manual (ISM).
- Knowledge and implementation experience relating to the Essential Eight.
- Threat intelligence analysis.
- Incident response and playbook development.
- Vulnerability assessment and remediation.
- Security control assessment and assurance.
- Security testing and system evaluation.

Security Clearance Candidates are required to hold a current TSPV security clearance .

The RFQ also specifies that personnel must be able to obtain Positive Vetting (PV) .





Successful candidates will be required to complete the ASD Organisation Suitability Assessment (OSA) before commencement.

Final work-area allocation will be determined by ASD according to operational requirements.

Working Arrangements The positions are available in:

- Australian Capital Territory (ACT)
- South Australia (SA)

The engagement is classified as onsite . Working arrangements will be determined by the assigned work area and operational requirements. Due to the nature of ASD operations, some work areas may not support working from home.

Contract Details

- Initial contract: 12 months
- Extension options: 2 x 12 months
- Maximum hours: 40 hours per week
- Estimated commencement: 30 November 2026
- Seniority: Lead / EL1 equivalent

Where an immediate business requirement is not identified, suitable candidates may also be considered for a merit pool.

What We Are Looking For

We are particularly interested in speaking with experienced cyber security professionals who combine robust SOC capability with hands-on expertise across technologies such as:

Splunk Enterprise Security | SIEM | EDR | NDR | SOAR | Threat Intelligence | Incident Response | Vulnerability Management | Security Monitoring | Cyber Detection | ISM | Essential Eight

Strong candidates will be able to demonstrate not simply exposure to these technologies, but specific examples of their personal contribution to security investigations, threat analysis, incident response, vulnerability remediation and improvements to cyber security controls.

Application Requirements

Candidates progressing for submission will be required to provide:

- Current CV/resume.
- Proposed hourly rate.
- Earliest available start date.
- Citizenship status.
- Current security clearance details.
- Written responses addressing each essential selection criterion.

Interested? If you hold a current TSPV clearance and have strong SOC, Splunk Enterprise Security, EDR/NDR and SOAR experience, we would be keen to hear from you.

Please apply with your updated CV, current clearance status, availability and expected hourly rate.

Azooa Pty Ltd

Federal Government & Defence ICT Contracting https://azooa.com.au

📌 Lead Security Analyst – Cyber Threat / SOC | Defence (Australian Capital Territory)
🏢 Azooa
📍 Australian Capital Territory

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead security analyst – cyber threat / soc | defence (australian capital territory) / australian capital territory

Subscribe to this job alert:

Get the latest job offers by email for: lead security analyst – cyber threat / soc | defence (australian capital territory) / australian capital territory