Senior Cyber Security Incident Handler (New South Wales)

Senior Cyber Security Incident Handler (New South Wales)

29 Sep
|
eHealth NSW
|
New South Wales

29 Sep

eHealth NSW

New South Wales

Senior Cyber Security Incident Handler (Health Manager Level 3)
Protect NSW Health's critical digital systems by investigating cyber threats, coordinating incident response and supporting secure healthcare services across NSW.
Permanent Full-Time | Hybrid flexibility for work-life balance | Chatswood, St Leonards or Charlestown
Attractive salary from $137,525 to $156,231 + 12% Super + 17.5% annual leave loading
Prospect to work across cyber incident response, security operations and digital forensics
Applications Close: 11:59pm, Monday 12 October ****
Join the Cyber Security Investigations Team
In this senior role, you will help protect the systems, services and data that support healthcare across NSW.
You will investigate cyber security events and incidents, work across incident response, digital forensics, phishing investigations and malware analysis, and help coordinate practical action when threats emerge.
The Cyber Security Investigations team provides specialist digital forensic services, incident response coordination, phishing investigation and malware analysis.
Analysts collect evidence and digital artefacts from IT systems, complete objective analysis and produce accurate reporting.
The team also triages cyber security incidents using multiple information sources and coordinates the involvement of staff, stakeholders, vendors and technical specialists.
Working closely with technical teams, ICT administrators, vendors and stakeholders, you will investigate potentially compromised systems, identify relevant evidence and provide practical advice throughout the incident lifecycle.
This includes supporting containment, remediation and recovery activities in line with the NIST ****** Cyber Security Incident Response framework.
In this role, you will:
Lead and coordinate cyber security incident triage, investigation and responseacross a large and complex digital environment, helping teams assess risk, contain threats and restore confidence in affected systems.
Analyse security alerts, logs and technical evidenceusing SOC, SIEM and cyber analytical tools to identify suspicious activity, confirm incident scope and support timely containment and response.




Investigate cyber threatsincluding phishing, unauthorised access, unusual login activity, malware and potentially compromised systems.
Collect, preserve and analyse digital evidence and artefactsusing appropriate forensic practices, then produce clear, objective findings and reports to support incident response decisions.
Research, configure and maintaintools used for cyber event logging, analysis and investigation.
Coordinate incident response activities, including war rooms, stakeholder updates, technical resources, vendor engagement, issue escalation and risk management.
Translate complex technical informationinto clear advice, incident reporting, analysis and recommendations for technical and senior stakeholders.
Improve incident handling practicesby contributing to operational methods, procedures, policies and risk-based approaches that strengthen detection and response services.
Maintain current knowledgeof emerging cyber security threats, vulnerabilities, technologies and investigative techniques.
View the position descriptionhere
About You
You will thrive in this role if you enjoy working through complex cyber incidents, following the evidence, making sound decisions under pressure and collaborating with others to protect critical digital services.
We are looking for someone who has:
Demonstrated experience in cyber incident handling, incident response or security operations, ideally within a large, complex or highly regulated organisation where incidents require structured triage, clear escalation and coordinated response.
Hands-on experience investigating security alerts and cyber threatsusing SOC or SIEM technologies, such as Microsoft Defender, Splunk or comparable security monitoring and analytical platforms.
Strong analytical and investigative skills,



including the ability to correlate information from multiple sources, exercise sound judgement and translate technical findings into practical response actions.
Experience coordinating complex cyber incidents, including containment and remediation activities, technical teams, stakeholders, risks, issues and reporting.
Knowledge of digital forensics and evidence handling, with experience collecting or analysing digital artefacts highly regarded.
Strong written and verbal communication skills, including the ability to explain complex cyber security matters clearly to technical and non-technical audiences.
Confidence building collaborative relationshipswith ICT teams, customers, hospitals, agencies, vendors and senior stakeholders to support coordinated incident response and practical problem solving.
The ability to remain organised and responsivein a high-volume environment where priorities and technologies can change quickly.
Relevant qualificationsin ICT or cyber security, or equivalent industry experience.
Internationally recognised cyber security or digital forensic certifications will be highly regarded, particularly where they have been applied in practical incident response or forensic investigation settings.
Why work at eHealth NSW
At eHealth NSW, ourbenefitsare designed to provide you with the flexibility, growth and support when you need it.
We provide:
Hybrid and flexible working options to support balance and productivity
Allocated day off per month in addition to annual leave
Salary packaging to maximise your take-home pay
Learn More About Us
How we hire
Diversity and inclusioncommitment
For questions around the role or recruitment process, including adjustments, please contact ourTalent Advisoror Hiring Manager, Craig and quote REQ******.
To be eligible for this role you must have current Australian work rights (Australian citizen, permanent resident, New Zealand citizen with a current passport, or hold a valid visa with permission to work in Australia).
If you currently reside outside NSW, please indicate in your application whether you are willing to relocate if successful.
#J-*****-Ljbffr

📌 Senior Cyber Security Incident Handler (New South Wales)
🏢 eHealth NSW
📍 New South Wales

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior cyber security incident handler (new south wales) / new south wales

Subscribe to this job alert:

Get the latest job offers by email for: senior cyber security incident handler (new south wales) / new south wales