Security Incident Handler

4 months ago


Canberra, Australia DXC Technology Full time

DXC Technology (NYSE:DXC) - where brilliant people embrace change and seize opportunities to advance their careers and amplify customer success.

At DXC we pride ourselves on delivering excellence in everything we do. What this means for you is the opportunity to be a part of delivering innovative solutions and helping to solve real business problems for a wide variety of valued clients.

**What you will be doing**

As part of this role, the Security Incident Handler will be required to undertake reviews of alerts received into the SIEM platform or other security tools or means. This will involve investigating alerts that have been escalated to them by the Tier 1 and 2 staffs which require more detailed investigation before declaring an incident or escalating outside the Security Monitoring team.

**Responsibilities**:

- Perform detailed investigations into security alerts escalated from the Security Monitoring team
- Conduct thorough analysis of escalated security incidents, including threat extent, timeline analysis, and potential business impact
- Advise clients on containment, eradication, and recovery strategies for security incidents
- Write post-incident review reports for high-priority incidents
- Update tickets to adhere to documented standards, ensuring clean handovers
- Monitor components of the Security Monitoring service for operational issues and escalate as required
- Investigate and respond to frequently occurring or common security alerts
- Develop use cases for detecting security incidents, adhering to the MITRE ATT&CK Framework
- Conduct fine-tuning activities with clients and implement improvements
- Conduct tabletop exercises with clients on incident response
- Develop processes, procedures, and runbooks for security alerts

**Skills & Qualifications**:

- 3+ years’ as a Security Analyst or working in a Cyber Security Operations centre
- 3+ years’ experience working with standard operating systems (Windows, Unix)
- Hands-on experience with one or more SIEM systems (ArcSight, Splunk, Sentinel, SumoLogic)
- Hands-on experience with EDR / XDR products like MS Defender, CrowdStrike, SentinelOne etc
- Demonstrated security knowledge of Windows/Linux/Unix platforms and networking protocols
- Strong understanding of TCP/IP and networking concepts (OSI Model)
- Experience assisting the development and maintenance of tools, procedures, and documentation
- Experience with reviewing raw log files, data correlation, and analysis (i.e. firewall, network flow, IDS, system logs)
- Experience qualifying and documenting indicators of compromise (IOC’s)
- Solid and demonstrable comprehension of Information Security including malware, emerging threats, attacks, and vulnerability management
- Demonstrated understanding of the MITRE ATT&CK framework
- Knowledge of IT security controls (Network IPS, Vulnerability Scanning, Endpoint Protection, Firewalls, Cloud Access Security Brokers)
- Diploma/Certificate/Degree in Information Technology (Security preferred)
- Relevant industry certifications such as CEH, GCIH, Security+, Network+, MCSP, CCNA
- Cloud services (Amazon Web Services, Azure, Google Cloud) (Desirable)
- Forensic experience with computer systems (Desirable)

**Our culture & benefits**

DXC is committed to building better futures for our customers, colleagues, environment, and communities. We take care of each other and foster a culture of inclusion, belonging and corporate citizenship. We put this to action developing and implementing societal initiatives within our Social Impact Practice. #WeAreDXC

As an employer of choice, our “people first” philosophy means we offer competitive remuneration, benefits, training and career opportunities that reflect our commitment to improving the lives of our employees, and the communities in which we live and work.

In return, we agree to ensure a hiring process that is enjoyable, thorough, and fair. We strive to provide an environment that lets you thrive and show off the very best version of yourself, while learning about us at the same time.

Interviews and onboarding are conducted online, as part of us being a virtual-first company.

**We are an Equal Opportunity Employer**

DXC is proud to be an equal opportunity employer and we welcome submissions from people from all walks of life. We celebrate our diversity and recognise it is the unique contributions of our people that give us our edge.



  • Canberra, Australia Malware Security Full time

    The Australian Signal's Directorate's (ASD) is seeking cyber security professionals to fill a variety of roles for the delivery of projects under the REDSPICE program. If you possess knowledge and skills related to threat analysis, incident response, system security, risk assessments and/or security architecture, we want to hear from you. Location: ACT...


  • Canberra, Australia MSS Security Full time

    About the Company As one of Australia’s leading security companies, with a national footprint across Australia, MSS Security has unrivalled experience in delivering the highest quality of service & protecting some of the nation’s highest profile sites. To find out more visit our website at Culture Our employees enjoy working with MSS because we: -...


  • Canberra, Australia Wilson Security Full time

    Security Patrols Coordinator opportunity! - Immediate start - Monday - Friday (0600-1700) - Employer of Choice! Wilson Security is the leading provider in the provision of security services across Australia and New Zealand. Our services are supported by a highly experienced management team, industry-leading expertise and a strong local and national...

  • Incident Responder

    1 day ago


    Canberra, Australia Aris Zinc Full time

    Federal Government - NV2 Security Clearance - Multiple Locations **Requirements**: - Experience in Service Desk at level 2 or 3 with incident and Problem - 5 years experience in Defence Industry - 5 years ITIL Framework The position will undertake the Incident and Problem Manager functions, performing the following activities: - Incident and Problem...


  • Canberra, Australia Wilson Security Full time

    12 Hour shifts (rotational roster) - Work in a small team with strong positve company culture - Employer of Choice! Wilson Security is the leading provider in the provision of security services across Australia and New Zealand. Our services are supported by a highly experienced management team, industry-leading expertise and a strong local and national...

  • Security Officers

    7 months ago


    Canberra, Australia Wilson Security Full time

    Permanent Night Relief - 12hr shifts - Attractive pay rates! - Work for the Employer of Choice! Wilson Security is the leading provider in the provision of security services across Australia and New Zealand. Our services are supported by a highly experienced management team, industry-leading expertise and a strong local and national structure. We are...

  • Incident Manager

    17 hours ago


    Canberra, Australia Leidos Full time

    Company Description At Leidos you’ll enjoy 12 weeks’ paid parental leave as a primary carer, competitive remuneration, flexible work practices, discounted health insurance, novated leasing and more. You have the option for an additional 12 Days leave when you enrol into the Life Days Program. Foster your career through complete access to mentoring and...


  • Canberra, Australia Aris Zinc Full time

    Federal Government - NV2 Security Clearance - Multiple Locations The position will undertake the Incident and Problem Manager functions, performing the following activities: - Incident and Problem tasking within operational support of the WNA; - Report on and provide advice to stakeholders and Project Senior Leadership Team on incidents that are...


  • Canberra, Australia Secureworks Full time

    We enjoy competitive compensation and benefits packages, and reward and recognize our employees for exceptional results. A constant focus on continued learning and growth keeps our team members engaged and excited about “what’s next.” We offer flexible work options when available, and emphasize the importance of work-life balance. We know that when our...


  • Canberra, Australia Secureworks Full time

    We enjoy competitive compensation and benefits packages, and reward and recognize our employees for exceptional results. A constant focus on continued learning and growth keeps our team members engaged and excited about “what’s next.” We offer flexible work options when available, and emphasize the importance of work-life balance. We know that when our...

  • Itil Incident Manager

    7 months ago


    Canberra, Australia Leidos Full time

    Company Description People join Leidos Australia for many different reasons. The interesting projects. Supportive and open-minded colleagues. The opportunities to develop. What unites us is the fact that everything we do benefits and safeguards Australia in some way. We’re proud of our Mission to make the world safer, healthier and more efficient, and...


  • Canberra, Australia Fujitsu Full time

    **Major Incident Specialist** **We are Fujitsu** We use technology to make happier lives. We are a global leader in technology and business solutions that transform organizations and the world around us. We have a long heritage of bringing innovation and expertise, continuously working to contribute to the growth of society and our customers. **About the...


  • Canberra, Australia Talent International Full time

    australia australian capital territory contract negotiable- Exciting opportunity for a Security Operations Analyst - 12 Month contract + multiple extension opportunities - ACT Located - Must hold an NV1 Security Clearance to apply **The Client** Our Client is the Australian government agency responsible for foreign signals intelligence, support to military...


  • Canberra, Australia BSI People Full time

    **Security Operations Analyst.** Up to 36 month contract. Cyber security experience is essentail and core to this position. The Australian Signals Directorate (ASD) is a statutory agency in the Defence portfolio that defends Australia against global threats and advances our national interests through the provision of foreign signals intelligence, cyber...

  • Cyber Security Analyst

    18 hours ago


    Canberra, Australia Digital61 Full time

    **The Role**: The Senior Cyber Security Analyst is responsible for monitoring customer SIEM incidents and alerts, as well as managing and performing minor configuration of security monitoring tools. They prioritise alerts or issues and perform initial triage to confirm a real security incident is taking place. They investigate alerts and incidents,...


  • Canberra, Australia Launch Recruitment Full time

    Attractive day rate on offer - Large Federal Government agency | ACT - 12 month contract - likely extension **About The Role** A Federal Government Agency is on the lookout for an Associate Cyber Security Analyst for a 12 month contract. This is a great opportunity to gain exposure working with other cyber security gurus. **Duties** - Conducting research...

  • Security Advisor

    7 days ago


    Canberra, Australia Chandler Macleod Full time

    As one of the Australia's largest providers of human resources solutions, Chandler Macleod has a proven track record of unleashing potential in people and companies. For over 40 years Chandler Macleod's recruitment business has connected leading-edge projects and employers with outstanding business professionals. Our Federal Government client is seeking to...

  • Cyber Security Analyst

    2 months ago


    Canberra, Australia CYOS Solutions Full time

    **Application closing date**: Friday, 06 December 2024 - 11:59pm, Canberra time (in Canberra) **Estimated start date**: Monday, 13 January 2025 **Location of work**: ACT **Working arrangements**:The AEC's preference is for on-site work at the Canberra office but hybrid WFH arrangements may be considered. **Length of contract**: 12 months **Contract...


  • Canberra, Australia IT Alliance Australia Full time

    Canberra **Department of Defence (SA)** One of our **Federal Government** clients is looking for **Security Operations Analyst **in **Canberra**.** **We are looking for the following Skills/Experience**: - Performing initial assessment of any potential damage associated with security incidents. - Demonstrated 3+ years of cyber security experience. -...


  • Canberra, Australia Talent International Full time

    **Job Details**: **Location** Canberra **Salary** Negotiable **Job Type** Contract **Ref** BBBH95019_1666327800 **Contact** Yvonne Yang **Posted** about 4 hours ago - **Australian citizen with the ability to obtain security clearance**: - ** Open to Canberra and Geelong Victoria** *** **About the role** - Proactive monitoring, investigations...