Lead Cyber Security Incident Response Analyst

5 months ago


Sydney Eastern Suburbs, Australia Robert Half Full time

Join this large & recognisable global firm in a newly created role to lead the execution & coordination of IR processes, automation, and cloud IR.
- Newly created role in a well-known global firm
- Lead CSIRT activities in the region
- Full time permanent role | Hybrid working

**THE COMPANY**

This large and well-known organisation employs more than 70,000 staff in 100+ countries around the globe.

They are a creative and innovative business that are expanding their Cyber Security capabilities in Australia.

**THE ROLE & RESPONSIBILITIES**

Newly created Cyber Security Incident Response Team Lead role working alongside the global SOC and Threat Intelligence teams to act as a regional incident coordinator during events that require orchestrated responses.

You will be responsible for ensuring the organisations IT & cyber assets are monitored, improved, documented, automation, and protected to the highest standard.

**Key elements include**:

- Lead & manage the execution of Incident Response processes in the region.
- Design, develop & provide ongoing improvement to Incident Response processes.
- Prepare metrics to track & improve Incident Response processes.
- Lead the development of SOAR playbooks & become the SME for automated workflows and processes that adhere to compliance requirements (ISO 27001, GDPR etc).
- Lead the development of cloud-focused Incident Response processes.
- Assist in maintaining & improving the Incident Response framework.
- Act as the liaison between Senior Executives, Internal Audit & Legal teams, and business unites during major incidents and post incident investigations.
- Contribute to building out the security strategy.
- Lead & mentor junior CSIRT Analyst's.
- Work alongside a global team in a 'follow-the-sun' model.

**REQUIRED EXPERIENCE / BACKGROUND / KNOWLEDGE**

Suitable for a Lead/Senior CSIRT Analyst with proven experience executing & coordinating multi-level Incident Response processes as well as leading automation initiatives.

Ideal for a natural collaborator with excellent communication & stakeholder management abilities who can 'see the big picture' and think strategically.

**The following is required**:

- Proven Senior CSIRT exp and SME knowledge executing & coordinating Incident Response processes.
- SIEM threat hunting exp & ability to create queries to detect incidents.
- Endpoint & network analysis background identifying threats.
- Ability to translate orchestration design documents into SOAR playbooks.
- Cloud security knowledge, including techniques to secure cloud environments & cloud Incident Response.
- Scripting experience - e.g. Python, JavaScript, PowerShell,.Net etc
- MITRE ATT&CK framework experience.
- IT security framework knowledge - e.g. ISO 27001, COBIT, NIST etc
- Background inside enterprise environments working with globally dispersed teams.
- Strong attention to detail, problem-solving & analytical skills
- Excellent communication & stakeholder management abilities.

**This is a full-time permanent role located in Sydney with hybrid working available.**
- _Please note, unrestricted permanent Australian working rights are required to be considered for this position and successful applicants will be contacted. _


  • Cyber Security Analyst

    2 months ago


    Sydney, New South Wales, Australia Australian Energy Market Operator Full time

    About the RoleAustralian Energy Market Operator (AEMO) is seeking a highly skilled Cyber Security Analyst to join our Cyber Incident Response team. As a key member of our team, you will play a critical role in protecting our energy systems from cyber threats.Key ResponsibilitiesTake a technical leadership role in cyber defence and response activities,...


  • Sydney, New South Wales, Australia Australian Energy Market Operator Full time

    About the RoleAustralian Energy Market Operator (AEMO) is seeking a highly skilled Cyber Incident Response Analyst to join our team. As a key member of our Cyber Incident Response team, you will play a critical role in protecting our energy systems from cyber threats.Key ResponsibilitiesLead the investigation and response to cyber security incidents,...

  • Incident Responder

    5 months ago


    Sydney, Australia Quigly Cyber Full time

    Diverse, inclusive and supportive team - Proudly making a difference with the transition to renewable energy - You love Cyber Security Quigly are a boutique consultancy with a great network of clients across many industries. **Company Overview** Join one of Australia's top organizations. Our client improves the lives of millions - from lighting up sports...


  • Sydney, Australia The Decipher Bureau Full time

    The Company  Join an ASX-listed organisation that has one of Australia’s largest cybersecurity practices, which are expanding their new cyber defence team. Following the recent high-profile incidents in Australia, this organisation has taken a proactive approach, identifying the need to build a new cloud security capability. Just 18 months later, this...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking a highly skilled Cloud Security Incident Response Senior Analyst to join our team. As a key member of our Cyber Defence Operations team, you will be responsible for reviewing and performing analysis on incident response engagements involving AWS and/or Azure data, assisting with uplifting cloud cyber control hygiene, and helping...

  • Cyber Security Analyst

    5 months ago


    Sydney, Australia NSW Government -Department of Customer Service Full time

    **Role: Cyber Security Analyst Roles** **Grade: Ongoing - Grade 7/8** **Location: Sydney or Bathurst** ***Role Type: Full Time Permanent** **About the Role** Cyber Security NSW is looking for a Cyber Security Analyst, focusing on incident response, to join our Intelligence and Response Team. The Intelligence and Response Team leads and coordinates...

  • SOC Analyst

    5 months ago


    Sydney, Australia Genesis IT&T Pty Ltd Full time

    **9 Months Contract (with the view to extend)**: - **Global Technology Company**: - **Experience in Healthcare industry is mandatory** A leading global technology company is currently seeking for an experienced SOC Analyst to be responsible for ensuring the detection and resolution of cyber security incidents, exposures, and vulnerabilities across all...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the Role:The Commonwealth Bank of Australia is seeking a highly skilled Cloud Security Incident Response Senior Analyst to join our team. As a key member of our Cyber Defence Operations team, you will play a critical role in guiding solutions, services, and project initiatives within AWS and Azure environments.Key Responsibilities:Act as the technical...


  • Sydney, New South Wales, Australia Australian Energy Market Operator Full time

    About the RoleWe are seeking a Cyber Security Specialist - Threat Detection and Response to join our team at the Australian Energy Market Operator (AEMO). The successful candidate will be responsible for taking a technical leadership role in cyber defence and response activities.Investigate security incidents and provide response and containment against...


  • Sydney, New South Wales, Australia Australian Energy Market Operator Full time

    About the RoleAustralian Energy Market Operator (AEMO) is seeking a highly skilled Cyber Incident Response Specialist to join our team. As a key member of our Cyber Incident Response team, you will play a critical role in protecting our organization from cyber threats and ensuring the reliability and security of our energy systems.Key ResponsibilitiesLead...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking an experienced Cloud Security Incident Response Manager to join our Cyber Defence Operations team. As a key member of our team, you will be responsible for leading solutions, services, and project initiatives across Azure.Key ResponsibilitiesManage, mentor, and develop a team of cybersecurity analysts, promoting a collaborative...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking a highly skilled Cloud Security Incident Response Senior Analyst to join our team. As a key member of our Cyber Defence Operations (CDO) team, you will play a critical role in guiding solutions, services, and project initiatives within AWS and Azure environments.Key ResponsibilitiesAct as the technical cloud security SME and...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the Role:The Commonwealth Bank of Australia is seeking a highly skilled Cloud Security Incident Response Manager to join our Cyber Defence Operations team. As a key member of our team, you will be responsible for leading solutions, services, and project initiatives across Azure, drawing on your expertise in cloud security and incident response.Key...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking a highly skilled Cloud Security Incident Response Senior Analyst to join our team. As a key member of our Cyber Defence Operations (CDO) team, you will play a critical role in guiding solutions, services, and project initiatives within AWS and Azure environments.Key ResponsibilitiesAct as the technical cloud security SME and...


  • Sydney, New South Wales, Australia Australian Energy Market Operator Full time

    About the RoleWe are seeking a highly skilled Cyber Incident Response Specialist to join our team at the Australian Energy Market Operator (AEMO). As a key member of our Cyber Incident Response team, you will play a critical role in protecting our organization from cyber threats and ensuring the reliability and security of our energy systems.Key...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking a highly skilled Cloud Security Incident Response Senior Analyst to join our team at the Commonwealth Bank of Australia. As a key member of our Cyber Defence Operations team, you will play a critical role in guiding solutions, services, and project initiatives within AWS and Azure environments.Key ResponsibilitiesAct as the...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking a highly skilled Cloud Security Incident Response Manager to join our Cyber Defence Operations team. As a key member of our team, you will be responsible for leading solutions, services, and project initiatives across Azure, drawing on your expertise in cloud security and incident response.Key Responsibilities:Manage and mentor a...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking a highly skilled Cloud Security Incident Response Manager to join our team at the Commonwealth Bank of Australia. As a key member of our Cyber Defence Operations team, you will be responsible for leading incident response efforts and managing cloud security controls across Azure environments.Key ResponsibilitiesManage and mentor...


  • Sydney, Australia Deloitte Full time

    Job Requisition ID:  36349  Learn from the best in the business Mentoring, growth and training – receive support and coaching to progress your career Preventive and supportive mental health initiatives About the Role The Manager – Incident Response and Cyber Defence will play a key operational role in supporting the Head of...


  • Sydney, New South Wales, Australia Commonwealth Bank of Australia Full time

    About the RoleWe are seeking a highly skilled Cloud Security Incident Response Senior Analyst to join our team at the Commonwealth Bank of Australia. As a key member of our Cyber Defence Operations team, you will play a critical role in guiding solutions, services, and project initiatives within AWS and Azure environments.Key ResponsibilitiesAct as the...