- Investigate SIEM events, track emerging threats and uncover intrusion attempts
- Own incident response from triage through escalation to resolution
- Analyse phishing activity, suspicious domains and IP addresses to identify genuine risk
- Lead threat hunting and vulnerability assessments across customer environments
- Build high‑fidelity detections through alert tuning, rule creation and system improvements
- Mentor junior analysts and improve capability across the wider SOC
- Work across daily operations, threat analysis and proactive defence for a broad customer base
- Collaborate with SOC peers to strengthen detection capability and deliver customer outcomes
Requirements
- 3+ years working with modern detection and response tooling including SIEM, XDR and EDR
- Solid grounding in Microsoft security technologies
- Confidence working across Linux or Unix environments
- Background in enterprise‑scale security operations
- Exposure to incident response and digital forensics
- Working knowledge of MITRE ATT&CK;, NIST and ISO 27000 frameworks
- Clear communication skills and ability to translate technical detail for any audience
- Subject to state and federal police background checks
- Unrestricted right to work in Australia
- Visa sponsorship is not available
- Bonus: Broad understanding of cloud, networking and firewall technologies
- Bonus: Experience with vulnerability management tooling such as Rapid7, Tenable or Qualys
- Bonus: Familiarity with ITSM platforms and processes
Core Competencies
Demonstrates expertise in incident response, threat hunting, and vulnerability assessments, with a solid foundation in SIEM, XDR, and EDR tools. Proficient in Microsoft security technologies and familiar with frameworks such as MITRE ATT&CK;, NIST, and ISO 27000.