28 Sep
|
NSW Health
|
Chatswood
28 Sep
NSW Health
Chatswood
Senior Cyber Security Incident Handler (Health Manager Level 3)
Protect NSW Health's critical digital systems by investigating cyber threats, coordinating incident response and supporting secure healthcare services across NSW.
- Permanent Full-Time | Hybrid flexibility for work-life balance | Chatswood, St Leonards or Charlestown
- Attractive salary from $137,525 to $156,231 + 12% Super + 17.5% annual leave loading
- Opportunity to work across cyber incident response, security operations and digital forensics
Applications Close: 11:59pm, Monday 12 October 2026
Join the Cyber Security Investigations Team
In this senior role, you will help protect the systems, services and data that support healthcare across NSW. You will investigate cyber security events and incidents, work across incident response, digital forensics, phishing investigations and malware analysis, and help coordinate practical action when threats emerge.
The Cyber Security Investigations team provides specialist digital forensic services, incident response coordination, phishing investigation and malware analysis. Analysts collect evidence and digital artefacts from IT systems, complete objective analysis and produce accurate reporting. The team also triages cyber security incidents using multiple information sources and coordinates the involvement of staff, stakeholders, vendors and technical specialists.
Working closely with technical teams, ICT administrators, vendors and stakeholders, you will investigate potentially compromised systems, identify relevant evidence and provide practical advice throughout the incident lifecycle. This includes supporting containment, remediation and recovery activities in line with the NIST 800-61 Cyber Security Incident Response framework.
In this role, you will:
- Lead and coordinate cyber security incident triage, investigation and response across a large and complex digital environment, helping teams assess risk, contain threats and restore confidence in affected systems.
- Analyse security alerts, logs and technical evidence using SOC, SIEM and cyber analytical tools to identify suspicious activity, confirm incident scope and support timely containment and response.
- Investigate cyber threats including phishing, unauthorised access, unusual login activity, malware and potentially compromised systems.
- Collect, preserve and analyse digital evidence and artefacts using appropriate forensic practices, then produce clear,
objective findings and reports to support incident response decisions.
- Research, configure and maintain tools used for cyber event logging, analysis and investigation.
- Coordinate incident response activities, including war rooms, stakeholder updates, technical resources, vendor engagement, issue escalation and risk management.
- Translate complex technical information into clear advice, incident reporting, analysis and recommendations for technical and senior stakeholders.
- Improve incident handling practices by contributing to operational methods, procedures, policies and risk-based approaches that strengthen detection and response services.
- Maintain current knowledge of emerging cyber security threats, vulnerabilities, technologies and investigative techniques.
View the position description
About You
You will thrive in this role if you enjoy working through complex cyber incidents, following the evidence, making sound decisions under pressure and collaborating with others to protect critical digital services.
We are looking for someone who has:
- Demonstrated experience in cyber incident handling, incident response or security operations, ideally within a large, complex or highly regulated organisation where incidents require structured triage, clear escalation and coordinated response.
- Hands-on experience investigating security alerts and cyber threats using SOC or SIEM technologies, such as Microsoft Defender, Splunk or comparable security monitoring and analytical platforms.
- Strong analytical and investigative skills, including the ability to correlate information from multiple sources, exercise sound judgement and translate technical findings into practical response actions.
- Experience coordinating complex cyber incidents, including containment and remediation activities, technical teams, stakeholders, risks, issues and reporting.
- Knowledge of digital forensics and evidence handling, with experience collecting or analysing digital artefacts highly regarded.
- Strong written and verbal communication skills,
including the ability to explain complex cyber security matters clearly to technical and non-technical audiences.
- Confidence building collaborative relationships with ICT teams, customers, hospitals, agencies, vendors and senior stakeholders to support coordinated incident response and practical problem solving.
- The ability to remain organised and responsive in a high-volume environment where priorities and technologies can change quickly.
- Relevant qualifications in ICT or cyber security, or equivalent industry experience. Internationally recognised cyber security or digital forensic certifications will be highly regarded, particularly where they have been applied in practical incident response or forensic investigation settings.
Why work at eHealth NSW
At eHealth NSW, our are designed to provide you with the flexibility, growth and support when you need it. We provide:
- Hybrid and versatile working options to support balance and productivity
- Allocated day off per month in addition to annual leave
Salary packaging to maximise your take-home pay
Hear about how our team benefits from working at eHealth
Learn More About Us
- Find out
at eHealth NSW * Check out our
commitment
Your work matters at eHealth NSW
As the digital centre of excellence for NSW Health, we design and deliver secure, scalable technology that supports patient care across the state, helping clinicians provide better healthcare, now and into the future.
Join eHealth NSW to create real-world impact, drive meaningful outcomes and support the health of millions every day. Learn more about
How to apply
Submit your cover letter and most up to date resume (up to 5 pages), highlighting your relevant skills and experience. While we accept AI use - we want your application to feel genuine and true to you.
For questions around the role or recruitment process, including adjustments, please contact our or Hiring Manager, Craig and quote REQ692890.
Important information
- This recruitment may be used to establish a Talent Pool for similar roles (ongoing or temporary) that may arise over the next 18 months.
- To be eligible for this role you must have current Australian work rights (Australian citizen, permanent resident, New Zealand citizen with a current passport, or hold a valid visa with permission to work in Australia).
- If you currently reside outside NSW, please indicate in your application whether you are willing to relocate if successful.
.
📌 Senior Cyber Security Incident Handler (Chatswood)
🏢 NSW Health
📍 Chatswood