Lead Security Operations Analyst

5 months ago


Canberra, Australia Xero Full time

Xero is a beautiful, easy-to-use platform that helps small businesses and their accounting and bookkeeping advisors grow and thrive.

At Xero, our purpose is to make life better for people in small business, their advisors, and communities around the world. This purpose sits at the centre of everything we do. We support our people to do the best work of their lives so that they can help small businesses succeed through better tools, information and connections. Because when they succeed they make a difference, and when millions of small businesses are making a difference, the world is a more beautiful place.

**About the role**

As the Lead Security Operations Analyst you will work with internal Xero teams and 3rd party security service providers to monitor, detect and respond to events impacting the security of Xero and its customers.

You'll be expected to take a leading role in the Security Operations team from a technical perspective; demonstrating an EQ-driven approach in collaborating with and communicating and delivering to stakeholders across Xero.

As part of a 24 x 7 Security Operations capability, you will lead the triaging & investigation of alerts received from the SIEM and other sources. This will involve working with CX and Legal counterparts to ensure we communicate to regulatory authorities and customers in a timely manner; documenting standards and defining requirements and working with the other security teams to ensure these operational security standards are communicated and met across Xero.

You will take ownership of invoking and managing the Security Incident Response Plan, performing root cause analysis and recommend security improvements.

Whilst we don't need you have to used all the tools we do, we hope you have exposure to some of the following:

- Using a SIEM toolset to monitor alerts. E.g. Sumo logic, Splunk, Microsoft Sentinel, ELK stack. Ideally, you would be versed in understanding and contributing to detection logic that sits behind the SIEM tool.
- Using a SOAR function to perform automatic response and remediation actions within the SIEM.
- Using the AWS platform from a security detection and response perspective, e.g. reviewing CloudTrail logs, investigating anomalies in AWS accounts, reviewing GuardDuty alerts.
- Investigating alerts from an Endpoint Detection and Response (EDR) toolset e.g. Crowdstrike Falcon, Microsoft Defender for Endpoint, SentinelOne.
- Leading security incidents as an incident manager, and directing detection, containment, eradication, and recovery efforts.
- Performing windows and linux forensics in a cloud environment. Threat hunting and cyber threat intelligence would also be ideal.

**What you'll do**:

- Define requirements to automate and continuously improve the efficiency of threat detection, alerting and response.
- Exploit security tools to continuously improve the detection, prevention and analysis of security incidents.
- Keep informed as to emerging security threats that have the potential to impact Xero and implement/recommend mitigating strategies. Utilise available threat intelligence sources to inform and improve attack detection techniques.
- Ensure the analyst team develops and maintains security operations playbooks and runbooks in support of the Security Incident Response Plan.
- Coach and mentor members of the security operations team to increase the technical efficacy of the team
- Assist the people leader with people-focused tasks including recruitment, training and development.
- Mentor pod team members from other disciplines about security operations and raise awareness of security and operational concerns as a key consideration of product development.
- Have a influential role in the development of the SOC design and how the tools and resourcing requirements to achieve this might be established
- Be actively engaged with the Product Owner to shape and develop the roadmap for Defense and Response Pods

**What you'll bring**:

- Previous experience in a role within the Information Security Practice
- Extensive experience in security operations.
- Proven experience in developing and maintaining a highly motivated team of individuals.
- Been recognised as a technical lead or the senior contributor in your team.
- Strong coordination and incident management skills.
- Excellent stakeholder management.
- Fast learner, detail oriented, decisive, and enjoys fast paced work environment.

**Why Xero?**

At Xero we support many types of flexible working arrangements that allow you to balance your work, your life and your passions. We offer a great remuneration package including shares plus a range of leave options to suit your well-being. Our work environment encourages continuous improvement and career development and you’ll get to work with the latest technology.

Our collaborative and inclusive culture is one we’re immensely proud of. We know that a diverse workforce is a strength that enables businesses, including ours, to



  • Canberra, Australia Talent International Full time

    australia australian capital territory contract negotiable- Exciting opportunity for a Security Operations Analyst - 12 Month contract + multiple extension opportunities - ACT Located - Must hold an NV1 Security Clearance to apply **The Client** Our Client is the Australian government agency responsible for foreign signals intelligence, support to military...


  • Canberra, Australia BSI People Full time

    **Security Operations Analyst.** Up to 36 month contract. Cyber security experience is essentail and core to this position. The Australian Signals Directorate (ASD) is a statutory agency in the Defence portfolio that defends Australia against global threats and advances our national interests through the provision of foreign signals intelligence, cyber...


  • Canberra, ACT, Australia Talent International Full time

    Job Title: Security Operations Centre AnalystOur client is a leading provider of cybersecurity services, tasked with protecting Australia's national interests from foreign threats. As a Security Operations Centre Analyst, you will play a critical role in ensuring the security and integrity of our client's systems and networks.Key Responsibilities:Investigate...


  • Canberra, Australia IT Alliance Australia Full time

    Canberra **Department of Defence (SA)** One of our **Federal Government** clients is looking for **Security Operations Analyst **in **Canberra**.** **We are looking for the following Skills/Experience**: - Performing initial assessment of any potential damage associated with security incidents. - Demonstrated 3+ years of cyber security experience. -...


  • Canberra, Australia HAYS Full time

    Are you a Security Analyst looking for your next role?? **Your new company** This highly sought after and agile Government Agency is a vital member of Australia’s national security community and oversees many functions including intelligence, cyber security and offensive operations. **Your new role** In this role you will be tasked with promoting,...


  • Canberra, Australia AUSTRAC Full time

    Locations: Canberra, Sydney, Melbourne - Hybrid working arrangement offering working from home and office split - Ongoing **About the role** As Lead Analyst, Security Advisory, you will play a crucial role in ensuring the security and integrity of AUSTRACs systems and data. You will be a key member of the Technology Platforms and Solutions Operational...


  • Canberra, ACT, Australia Kinexus Full time

    About the RoleAs a SOC Analyst at Kinexus, you will play a critical role in managing the administration and monitoring of security systems. This includes integration of security and monitoring services within customer networks, as well as engagement with customers on security requirements and ongoing security improvement to systems.The ideal candidate will...


  • Canberra, ACT, Australia Kinexus Full time

    About the RoleWe are seeking a highly skilled Security Operations Centre Analyst to join our team at Kinexus. As a SOC Analyst, you will be responsible for managing the administration and monitoring of security systems, including integration of security and monitoring services within customer networks.The ideal candidate will have experience in a Security...

  • Security Analyst

    6 months ago


    Canberra, Australia The Business Agility Group Full time

    **About the job Security Analyst**: Please find the JD for your review from Services Australia and share your interest. **Note, to apply; applicants must have the following** - ** The requisite skills and experiences defined below,** - **Have Australian Citizenship to be able to obtain Baseline Security clearance; and**: - ** At least five year's relevant...

  • Security Analyst

    5 months ago


    Canberra, Australia Gateway Synergy Recruitment Full time

    Experience with analysing gateway & network security monitoring solutions - Canberra based, must have Baseline security clearance Gateway Synergy is looking for highly experienced Security Analyst contractor. The security infrastructure analyst will have experience in performing current state analysis, requirements analysis definition and implementation of...

  • IT Security Analyst

    3 months ago


    Canberra, Australia QinetiQ Full time

    QinetiQ employs more than 8500 people in more than 50 locations around the world, offering our customers premier expertise in advice, services and creative technology-based products. QinetiQ Australia, part of the global QinetiQ group, provides technological and scientific expertise to help customers protect and advance their vital interests. As an...

  • Security Analyst

    5 months ago


    Canberra, Australia Etainsolutions Full time

    Open To: **Australian Citizens With Baseline Clearance** **Location**: **Canberra - Brisbane - Melbourne - Adelaide (Hybrid Role)** As the steams new Security infrastructure analyst you will have had experience in performing current state analysis, requirements analysis definition and implementation of cyber security monitoring and reporting services,...


  • Canberra, Australia HiTech Personnel Full time

    **Reference #**: - JF/JA0896**Title**: - Cyber Security GRC analyst - ISM, PSPF, Essential 8**Category**: - ICT**Location**: - ACT**Work Type**: - Contract**Remuneration**: - $Neg**Term**: - 12mths + EXT**Description**: - **Join a leading Federal Government Department**: - **Initial 12 month contract with a 1 year extension!**: - **Rewarding hourly...


  • Canberra, ACT, Australia HiTech Group Full time

    HiTech Group is seeking a skilled Cyber Security Operations Analyst to join their team.Key ResponsibilitiesProvide technical advice and direction as a Cyber Security SME.Implement essential eight controls and uplift maturity.Assist in the architecture and development of secure platforms based on zero trust principals.Work closely with the site monitoring and...


  • Canberra, ACT, Australia Kinexus Full time

    About the Role:We are seeking a highly skilled SOC Security Specialist to join our team at Kinexus. As a key member of our cybersecurity operations team, you will be responsible for managing the administration and monitoring of security systems, including integration of security and monitoring services within customer networks, as well as engagement with...


  • Canberra, ACT, Australia Kinexus Full time

    About the RoleWe are seeking a highly skilled SOC Security Specialist to join our team at Kinexus. As a key member of our cybersecurity operations team, you will be responsible for managing the administration and monitoring of security systems, including integration of security and monitoring services within customer networks, as well as engagement with...

  • Security Analyst

    6 months ago


    Canberra, Australia The Business Agility Group (Australia) Pty Ltd Full time

    Please find the JD for your review from Services Australia and share your interest. Note, to apply; applicants must have the following The requisite skills and experiences defined below, Have Australian Citizenship to be able to obtain Baseline Security clearance; and At least five year's relevant local working experience. **Requirements**: The security...

  • Security Analyst

    5 months ago


    Canberra, Australia Peoplebank Full time

    Location: - Canberra- Job Type: - Contract- Posted: - 1 day ago- Contact: - Param Kaur- Discipline: - General IT - Reference: - 256909Our Federal Government Client is seeking a Security Analyst for a long-term contract role with an initial duration of 5 months. There is a possibility of extensions for up to 6 months, with a total of 2 extensions. The...

  • Cyber Security Analyst

    7 months ago


    Canberra, Australia IT Alliance Australia Full time

    Canberra **Department of Home Affairs** One of our **Federal Government** clients is looking for **Cyber Security Analyst **in **Canberra**.** **We are looking for the following Skills/Experience**: - Demonstrated experience as a Senior Cyber Security Analyst working in Security Operations Centre, including detection engineering and incident response...


  • Canberra, ACT, Australia Whizdom Recruitment Full time

    At Whizdom Recruitment, we are seeking a highly skilled Cybersecurity Threat Response Specialist to join our team in the ACT.The ideal candidate will have experience in a Security Operations Centre (SOC) including security monitoring and incident response, with a proven track record of developing SOC documentation, including analyst play-books and security...