Haystack
← Back to Jobs
Full time
Administrative
MM

Security Detection & Response Analyst roles

Morgan McKinleySydney, Sydney🇦🇺AustraliaPosted 11 Sept 2026

Why This Role Stands Out

This role offers a fantastic opportunity to contribute to critical security operations within a leading financial services organization, with a hybrid schedule allowing for flexibility. You'll thrive if you're a mid-senior security professional eager to hone your skills in threat detection, incident response, and automation while mentoring others. Apply now to join a dynamic team and advance your career in a high-impact field.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
On Site
Location
Sydney, Sydney, Australia

Job Description

There are multiple Security Detection and Response Analyst roles (Level 1 and Level 2) available with a large financial services organisation.

These roles have onsite requirement for 4 days.

Responsibilities:
  • Threat Detection & Engineering: Build, tune, and optimize high-quality detection logic mapped to the MITRE ATT&CK framework to maximize coverage and minimize false positives.
  • Incident Investigation & Response: Analyze logs and telemetry to determine attack scope and root causes, while executing containment, isolation, and remediation during active security events.
  • Automation & Metrics Optimization: Maintain and improve SOAR workflows, automated playbooks, and AI enhancements to reduce manual effort and measurably improve MTTR and signal-to-noise ratios.
  • Documentation & Stakeholder Communication: Document security incident findings, construct timelines, deliver clear updates to stakeholders, and conduct post-incident reviews to capture lessons learned.
  • Continuous Improvement & Mentorship: Identify monitoring gaps to drive operational maturity, integrate partner use cases, and guide junior team members toward their professional development goals.
Requirements:
  • Build, tune, and optimize high-quality detection logic mapped to the MITRE ATT&CK framework to maximize coverage and minimize false positives.
  • Analyze logs and telemetry to determine attack scope and root causes, while executing containment, isolation, and remediation during active security events.
  • Maintain and improve SOAR workflows, automated playbooks, and AI enhancements to reduce manual effort and measurably improve MTTR and signal-to-noise ratios.
  • Document security incident findings, construct timelines, deliver clear updates to stakeholders, and conduct post-incident reviews to capture lessons learned.

Similar jobs