Haystack
← Back to Jobs
Full time
Technology
XS

SOC Analyst

XPT Software Australia Pty LtdMelbourne, Victoria🇦🇺AustraliaPosted 31 May 2026

Why This Role Stands Out

This hybrid SOC Analyst role offers you the chance to significantly enhance your skills in cybersecurity assessments and vulnerability remediation within a reputable company, while enjoying the flexibility of a hybrid work model. You'll thrive here if you are a proactive, hands-on security professional eager to drive impactful security improvements and collaborate with diverse technical teams. Apply today to join a dynamic environment focused on continuous growth and robust security practices.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
On Site
Location
Melbourne, Victoria, Australia
Splunk

Job Description

XPT Software Australia Pty Ltd Contract

SOC Analyst

Melbourne, Australia Posted on 05/19/2026

  • XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
  • XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
  • We have 120+technocrats in Australia working at our clientlocations.
  • XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
  • We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Job Description

Role Summary

The Cyber Security Engineer isresponsible for supporting NIST CSF / NIST 800 assessments, triagingpenetration test findings, and driving remediation activities acrossapplication, infrastructure, network security, and monitoring platforms.

The role is hands-on and deliveryfocused, working closely with architects, platform owners, SOC, andinfrastructure/application teams to translate security findings into actionablefixes, validate control effectiveness, and support audit ready evidence forregulated/government environments.

Key Responsibilities

NIST Assessment Support (CSF / NIST 800Series)

  • SupportNIST CSF / NIST assessments through:
  • Controlevidence collection
  • Gapanalysis support
  • Mappingtooling controls to NIST requirements
  • Assistarchitects and governance teams in preparing:
  • Controlimplementation summaries
  • Toolcapability mapping
  • Evidencepacks for audits and client reviews
  • Trackand manage security gaps, risks, and remediation actions in line withagreed timelines
  • Supportcontinuous improvement initiatives driven by assessment outcomes

Penetration Test Findings &Remediation

  • Triageand analyse application, infrastructure, and network penetration testfindings
  • Workwith platform and application teams to:
  • Prioritiseremediation based on risk and exploitability
  • Executeor support remediation actions such as:
  • Controlenablement or enhancement
  • Trackremediation status and provide clear closure evidence for governance andaudit forums
  • Activitiesinclude:
  • Policytuning and baseline hardening
  • Coverageand health checks
  • Supportingremediation of vulnerabilities and misconfigurations

Support security controls across:

  • Ciscosecurity platforms
  • Imperva
  • MicrosoftGSA / related network security controls

Responsibilities include:

  • Supportingfirewall / network security rule reviews and clean ups
  • Assistingwith remediation of network related pen test findings
  • Supportingchange validation and post implementation checks
  • Workingwith network teams to ensure security controls align with NIST and secure by designprinciples
  • SupportSIEM and monitoring platforms:
  • Splunk
  • MicrosoftSentinel
  • Assistwith:
  • Detection coverage checks related to NIST andpen test scenarios
  • Validation that remediated controls generateexpected telemetry
  • SupportSOC teams with investigation data where required
  • Remediationactions
  • Controlchanges
  • Evidencerequired for audits and MSSR / governance reviews
  • Incident and problem reviews (P1 / P2 support)
  • Root cause analysis where control gaps areidentified
  • Followstructured change and release processes (CAB, validation, rollback awareness)

Skills &Experience

  • 5 years experience in security engineering / SecOps / blue teamroles
  • Exposure to NIST CSF or NIST 800 frameworks
  • Hands on experience supporting remediation across:
  • Endpoint / infrastructuresecurity tools
  • Vulnerability managementplatforms
  • Network security controls
  • Experience working with penetration test reports and remediationtracking
  • Familiarity with SIEM platforms (Splunk and/or Sentinel)

Similar jobs