Haystack
← Back to Jobs
Full time
Technology
NH

Senior Cyber Security Incident Handler

NSW HealthWilloughby, New South Wales🇦🇺AustraliaPosted 4 Oct 2026

Why This Role Stands Out

You'll safeguard critical digital systems within NSW Health, gaining invaluable experience in incident response and digital forensics, with a competitive salary and hybrid flexibility. This impactful role is perfect for a seasoned cybersecurity professional eager to contribute to secure healthcare services while developing their skills in a reputable organization. Apply now to make a significant difference and advance your career.

Quick Overview

Salary
A$137.5k - A$156.2k/yr
Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Willoughby, New South Wales, Australia
Splunk

Job Description

Senior Cyber Security Incident Handler (Health Manager Level 3)

Protect NSW Health's critical digital systems by investigating cyber threats, coordinating incident response and supporting secure healthcare services across NSW.

  • Permanent Full-Time Hybrid flexibility for work life balance Chatswood, St Leonards or Charlestown
  • Attractive salary from $137,525 to $156,231 + 12% Super + 17.5% annual leave loading
  • Opportunity to work across cyber incident response, security operations and digital forensics


Applications Close: 11:59pm, Monday 12 October 2026

Join the Cyber Security Investigations Team

In this senior role, you will help protect the systems, services and data that support healthcare across NSW. You will investigate cyber security events and incidents, work across incident response, digital forensics, phishing investigations and malware analysis, and help coordinate practical action when threats emerge.

The Cyber Security Investigations team provides specialist digital forensic services, incident response coordination, phishing investigation and malware analysis. Analysts collect evidence and digital artefacts from IT systems, complete objective analysis and produce accurate reporting. The team also triages cyber security incidents using multiple information sources and coordinates the involvement of staff, stakeholders, vendors and technical specialists.

Working closely with technical teams, ICT administrators, vendors and stakeholders, you will investigate potentially compromised systems, identify relevant evidence and provide practical advice throughout the incident lifecycle. This includes supporting containment, remediation and recovery activities in line with the NIST 800-61 Cyber Security Incident Response framework.

In this role, you will:

  • Lead and coordinate cyber security incident triage, investigation and response across a large and complex digital environment, helping teams assess risk, contain threats and restore confidence in affected systems.
  • Analyse security alerts, logs and technical evidence using SOC, SIEM and cyber analytical tools to identify suspicious activity, confirm incident scope and support timely containment and response.
  • Investigate cyber threats including phishing, unauthorised access, unusual login activity, malware and potentially compromised systems.
  • Collect, preserve and analyse digital evidence and artefacts using appropriate forensic practices, then produce clear, objective findings and reports to support incident response decisions.
  • Research, configure and maintain tools used for cyber event logging, analysis and investigation.
  • Coordinate incident response activities, including war rooms, stakeholder updates, technical resources, vendor engagement, issue escalation and risk management.
  • Translate complex technical information into clear advice, incident reporting, analysis and recommendations for technical and senior stakeholders.
  • Improve incident handling practices by contributing to operational methods, procedures, policies and risk based approaches that strengthen detection and response services.
  • Maintain current knowledge of emerging cyber security threats, vulnerabilities, technologies and investigative techniques.

You will thrive in this role if you enjoy working through complex cyber incidents, following the evidence, making sound decisions under pressure and collaborating with others to protect critical digital services.

We are looking for someone who has:

  • Demonstrated experience in cyber incident handling, incident response or security operations, ideally within a large, complex or highly regulated organisation where incidents require structured triage, clear escalation and coordinated response.
  • Hands on experience investigating security alerts and cyber threats using SOC or SIEM technologies, such as Microsoft Defender, Splunk or comparable security monitoring and analytical platforms.
  • Strong analytical and investigative skills, including the ability to correlate information from multiple sources, exercise sound judgement and translate technical findings into practical response actions.
  • Experience coordinating complex cyber incidents, including containment and remediation activities, technical teams, stakeholders, risks, issues and reporting.
  • Knowledge of digital forensics and evidence handling, with experience collecting or analysing digital artefacts highly regarded.
  • Strong written and verbal communication skills, including the ability to explain complex cyber security matters clearly to technical and non technical audiences.
  • Confidence building collaborative relationships with ICT teams, customers, hospitals, agencies, vendors and senior stakeholders to support coordinated incident response and practical problem solving.
  • The ability to remain organised and responsive in a high volume environment where priorities and technologies can change quickly.
  • Relevant qualifications in ICT or cyber security, or equivalent industry experience. Internationally recognised cyber security or digital forensic certifications will be highly regarded, particularly where they have been applied in practical incident response or forensic investigation settings.
Why work at eHealth NSW

At eHealth NSW, our benefits are designed to provide you with the flexibility, growth and support when you need it. We provide:

  • Hybrid and flexible working options to support balance and productivity
  • Allocated day off per month in addition to annual leave

Salary packaging to maximise your take home pay

Hear about how our team benefits from working at eHealth

As the digital centre of excellence for NSW Health, we design and deliver secure, scalable technology that supports patient care across the state, helping clinicians provide better healthcare, now and into the future.

Join eHealth NSW to create real world impact, drive meaningful outcomes and support the health of millions every day. Learn more about us at eHealth NSW

NSW Health acknowledges the people of the many traditional countries and language groups of New South Wales. It acknowledges the wisdom of Elders past and present, and pays respect to all Aboriginal communities of today.

Similar jobs