Why This Role Stands Out
This hybrid role offers significant growth potential within a reputable cyber security team, allowing you to deepen your expertise in threat detection and incident response using cutting-edge platforms. You'll thrive here if you're a proactive security professional eager to enhance cloud security and contribute to robust incident management. Apply now to leverage your skills in a dynamic and impactful environment.
Quick Overview
Job Description
Estimated start date: Monday, 28 September 2026
Extension term: 12 months
Number of extensions: 2
Location of work: QLD, WA, ACT, VIC, NSW, NT, SA, TAS
Working arrangements: Hybrid
Maximum hours: 40 hours per week
Security clearance: Must be able to obtain NV1
Job detailsJoin our Cyber Security team as a Senior Security Operations Specialist. This is a hands-on technical role focused on monitoring, detecting, and responding to cyber threats using platforms such as Microsoft Sentinel and Defender, while helping strengthen the security posture of our cloud-hosted solutions. Reporting to the Cyber Security Lead, you'll play a key role in both the planning/design and operational phases of our security capability. This role operates on a hybrid basis, requiring a minimum of two (2) days per week in the office, with in-office days to be agreed with your supervising manager.
Key duties and responsibilitiesSenior Security Operations Specialist willbe requiredto:
Security Monitoring & Detection Engineering: Configure, manage and optimise security monitoring platforms including development and tuning of analytics rules, dashboards and alerting use cases to detect malicious activity.
Incident Response: Lead and support the response to cyber security incidents, including investigation, containment, eradication and recovery. Conduct root cause analysis and implement remediation actions to prevent recurrence.
Security Operations & Investigation: Perform detailed analysis of security events, logs and alerts across cloud and enterprise environments. Triage and prioritise incidents based on risk and business impact.
Security Automation & Orchestration: Develop and maintain automation playbooks and scripts to improve response times and reduce manual effort in security operations.
Vulnerability Management: Identify, assess and prioritise vulnerabilities across systems, applications and infrastructure. Work with DevOps and development teams to ensure timely remediation.
Security Tool Management: Configure, maintain and optimise security tools and platforms, identifying opportunities for improvement, integration and automation.
Threat Intelligence & Use Case Development: Manage and utilise threat intelligence feeds, incorporating intelligence into detection use cases, analytics rules and threat hunting activities.
Collaboration and Continuous Improvement: Work closely with DevOps, developers and security teams to improve detection coverage and feed operational learnings into system design and control implementation.
Governance Support & Documentation: Maintain operational documentation, incident records and runbooks. Support alignment with WoAG policies through implementation and evidence collection.
CriteriaThe buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters.
- Hands-on cyber security operations, including security monitoring, incident response, threat analysis, and investigation in enterprise or cloud environments.
- Working with SIEM/SOAR platforms, preferably Microsoft Sentinel, including development of analytics rules, KQL queries, alert tuning and dashboards.
- Incident detection and response, including triaging alerts, investigating security events and performing root cause analysis.
- Security automation and scripting, using tools to support orchestration and response activities.
- Working in cloud environments (preferably Microsoft Azure), with understanding of logging, monitoring and security controls.
- Applying cyber security frameworks and best practices, including familiarity with Whole-of-Australian-Government (WoAG) policies such as ISM and Essential Eight
"Due to the requirement for immediate access to sensitive information and systems, personnel proposed for this role must hold a current NV1 security clearance at commencement."
Similar jobs
- CE
Lead Security Threat Analyst
NewCentorrino-Technologies-1
Canberra, Australian Capital Territory🇦🇺Hybrid5 hours agoSplunkTechnology - CT
Network Security Engineer
NewCentorrino Technologies
Melbourne, Victoria🇦🇺Hybrid11 hours agoTCP/IPDNSZero TrustTechnology - MA
Senior AI Security Engineer: Secure AI Products
NewMatchbox
Sydney🇦🇺Hybrid11 hours agoTechnology - AM
Security Specialist, Region Services Relocation Support
NewAmazon
Melbourne, Victoria🇦🇺Hybrid11 hours agoAWSTechnology - US
Senior AI Security Engineer - Secure-by-Design AI Products
NewUnited States Digital Space LLC
Sydney🇦🇺Hybrid11 hours agoKubernetesTechnology - LR
Regional Principal Information Security Engagement Engineer
NewLexisNexis Risk Solutions
Sydney🇦🇺Hybrid11 hours agoAdministrative