Cybersecurity Response

4 weeks ago


Sydney, Australia Kyndryl Australia Pty Ltd Full time

**Why Kyndryl**

Kyndryl was spun-off of IBM IT infrastructure services in 2021. Our global base of customers includes 75 of the Fortune 100 companies. With 88,449 skilled professionals operating from over 100 countries, we are committed to the success of our customers, collaborating with them, and helping them to realise their ambitions.

We help our customers design, manage, and modernise the technology systems they depend on every day. Kyndryl is the ‘hearts and lungs’ because we support mission critical infrastructure.

Kyndryl has operations in 63 countries; 450 data centres around the world are under our management. We have the majority of mainframe capacity, generating and running 9 million automated actions per month for our customers.

**Your Role and Responsibilities**

The Kyndryl CSIRT is looking for a Cybersecurity Response (CSIRT) Analyst to join an advanced team that drives proactive identification of threats within the organization, provide rapid response, monitors user activity, network events, and signals from security tools to identify events that merit attention, prioritization, and investigation. We are seeking a talented individual responsible for cybersecurity threat incidents including forensic investigations, and analysis in support of cyber incidents that are reported into the Incident Response team. This role will require the ability to triage and conduct thorough examinations of all information technology systems across diverse cloud environments, the ability to determine containment and/or remediation activities that may be required as well as identify potential threats. Reporting and collaborating with the different areas of business is required.

Responsibilities include:

- At least 5 years of experience in IT Security Digital Forensics
- At least 5 years of experience in Incident Response in a global corporate enterprise
- Demonstrated computer forensic investigations experience.
- Excellent technical writing and presentation skills.
- Expert-level knowledge of common attack vectors and penetration techniques.
- Solid working knowledge of networking technology and tools, firewalls, proxies, IDS/IPS and encryption.
- Demonstrated knowledge of forensic tools (Encase, FTK, Axiom Magnet, Black Bag, SIFT, Kali)
- Experience with malware analysis (reverse engineering).
- Experience managing large and small-scale cyber security incidents.
- Demonstrated understanding of database structures and SQL.
- Conduct examination of digital media (hard drives, network traffic, images, etc.).
- Capture / analyze network traffic for indications of compromise.
- Review log-based data, both in raw form and utilizing SIEM or aggregation tools.
- Perform live network assessments using leading packet capture and analysis software tools.
- Establish timelines and patterns of activity based on multiple data sources.
- Identify, document and prepare reports on relevant findings.
- Strong understanding of networking protocols
- Experience with programming or scripting languages (Python, Ruby, Powershell)
- Demonstrated system administration skills.

**NOTE**: This is a remote work from home.

**Required Technical and Professional Expertise**
- Extensive experience in IT Security and Digital Forensics
- Strong experience managing incidents in a global corporate environment
- Demonstrated computer forensic investigations experience.
- Excellent technical writing and presentation skills.
- Expert-level knowledge of common attack vectors and penetration techniques.
- Solid working knowledge of networking technology and tools, firewalls, proxies, IDS/IPS and encryption.
- Demonstrated knowledge of forensic tools (Encase, FTK, Axiom Magnet, Black Bag, SIFT, Kali)
- Experience with malware analysis (reverse engineering).
- Experience managing large and small-scale cyber security incidents.
- Demonstrated understanding of database structures and SQL.
- Conduct examination of digital media (hard drives, network traffic, images, etc.).
- Capture / analyze network traffic for indications of compromise.
- Review log-based data, both in raw form and utilizing SIEM or aggregation tools.
- Perform live network assessments using leading packet capture and analysis software tools.
- Establish timelines and patterns of activity based on multiple data sources.
- Identify, document and prepare reports on relevant findings.
- Strong understanding of networking protocols
- Experience with programming or scripting languages (Python, Ruby, Powershell)
- Demonstrated system administration skills.

**Preferred Technical and Professional Experience**

Any two of the following:

- ACE (Access Data Certified Examiner)
- EnCe ( EnCase Certified Examiner)
- AWS Security
- GCFE (GIAC Certified Forensics Examiner)
- GNFA (GIAC Network Forensics Analyst)
- GCIA (GIAC Certified Intrusion Analyst)
- GCIH (GIAC Certified Intrusion Handler)
- GREM (GIAC Reverse Engineering Malware)
- OSCP (Offensive Security Certified Professional)

**


  • Cybersecurity Manager

    2 weeks ago


    Sydney, Australia ALSTOM Full time

    Req ID:411983 We create smart innovations to meet the mobility challenges of today and tomorrow. We design and manufacture a complete range of transportation systems, from high-speed trains to electric buses and driverless trains, as well as infrastructure, signalling and digital mobility solutions. Joining us means joining a truly global community of more...


  • Sydney, New South Wales, Australia Stickmancyber Full time

    Interested in joining us on our mission for a safer digital world? View our available positions below.Position:Principal Cybersecurity Consultant Location: Sydney, Australia Role Type: Hybrid Stickmancyber is a leading Cybersecurity as a Service (CSaa S) company based in Sydney, Australia.We are committed to providing comprehensive cybersecurity services and...

  • Bdm Cybersecurity

    1 week ago


    Sydney, New South Wales, Australia The Cyber Hunters Embassy Full time

    Work for an identified WATCH cybersecurity vendor - huge career growth potential BDM Role autonomous role. Combination of HUNTING and Account Management. Hybrid role, excellent comms, training and benefits.You will be the FACE of this up-and-coming Cybersecurity Vendor. Based out of Sydney in a newly created BDM role, you will be responsible for HUNTING,...

  • Head of Cybersecurity

    3 weeks ago


    Sydney, Australia Stickmancyber Full time

    **Summary**: The Head of Cybersecurity - GRC is a key leadership role that combines deep technical expertise in cybersecurity with governance, risk, and compliance acumen. This role involves leading client projects as a GRC expert, recruiting and managing a skilled team, nurturing client relationships, and ensuring effective delivery of GRC...


  • Sydney, New South Wales, Australia Stickmancyber Full time

    Interested in joining us on our mission for a safer digital world? View our available positions below. Position: Principal Cybersecurity Consultant Location: Sydney, AustraliaRole Type: HybridStickmancyber is a leading Cybersecurity as a Service (CSaaS) company based in Sydney, Australia. We are committed to providing comprehensive cybersecurity services and...


  • Sydney, New South Wales, Australia Dynamo Recruitment Full time

    Australian Citizen ACT based Hybrid Long 12+ month contractWe have an exciting new role "Documentation Specialist - Cybersecurity & Assurance - long 12month contract working for a reputable Govt body on an innovative project Must be a Australian Citizen to apply Immediate start ACT based HybridThe Documentation Specialist - Cybersecurity & Assurance is...


  • Sydney, New South Wales, Australia TalentWeb Full time

    Leading Australian wealth management business requires a hands-on permanent Cybersecurity Specialist for there Sydney CBD office. Your role will see you help uplift the Cybersecurity maturity along with complying with APRA's regulatory requirements. Day to day responsibilities include: Complying with Security Standards and Frameworks such as APRA CPS234,...


  • Sydney, New South Wales, Australia Fti Consulting, Inc Full time

    FTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth.The Cybersecurity Practice within FTI Consulting is a leading provider of independent cybersecurity and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness, Incident Response and Complex...


  • Sydney, New South Wales, Australia Talent Web Full time

    Title:- Cyber Security SpecialistLocation:- SydneyLength:- Permanent Salary:- $170 to $180k PackageLeading Australian wealth management business requires a hands-on permanent Cybersecurity Specialist for there Sydney CBD office. Your role will see you help uplift the Cybersecurity maturity along with complying with APRA's regulatory requirements. Day to day...


  • Sydney, New South Wales, Australia TalentWeb Consulting Full time

    Security (Information & Communication Technology)Title:Cyber Security Specialist Location:Sydney Length:Permanent Salary:$170 to $180k Package Leading Australian wealth management business requires a hands-on permanent Cybersecurity Specialist for there Sydney CBD office.Your role will see you help uplift the Cybersecurity maturity along with complying with...


  • Sydney, Australia Dynamo Recruitment Full time

    Australian Citizen - ACT based - Hybrid - Long 12+ month contract We have an exciting new role **"Documentation Specialist - Cybersecurity & Assurance -** long 12month contract working for a reputable Govt body on an innovative project! - Must be a Australian Citizen to apply - Immediate start - ACT based - Hybrid The** Documentation Specialist -...


  • Sydney, New South Wales, Australia FTI Consulting, Inc Full time

    FTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth. The Cybersecurity Practice within FTI Consulting is a leading provider of independent cybersecurity and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness, Incident Response and Complex...

  • Bid Technical Lead

    1 month ago


    Sydney, Australia Alstom Full time

    Alstom’s state-of-the-art signalling solutions allow operators to ensure the highest standards in safe, seamless travel with urban and mainline solutions that meet the specific needs of each operation environment. International Exposure Global Mobility to Australia Career enhancement by joining the Australian team Experience in the Brownfield...

  • Bid Technical Lead

    3 weeks ago


    Sydney, Australia Alstom Full time

    Alstom’s state-of-the-art signalling solutions allow operators to ensure the highest standards in safe, seamless travel with urban and mainline solutions that meet the specific needs of each operation environment. International Exposure Global Mobility to Australia Career enhancement by joining the Australian team Experience in the Brownfield...

  • Bid Technical Lead

    1 week ago


    Sydney, Australia Alstom Full time

    Alstom’s state-of-the-art signalling solutions allow operators to ensure the highest standards in safe, seamless travel with urban and mainline solutions that meet the specific needs of each operation environment. International Exposure Global Mobility to Australia Career enhancement by joining the Australian team Experience in the Brownfield...

  • Bid Technical Lead

    1 month ago


    Sydney, Australia Alstom Full time

    Alstom’s state-of-the-art signalling solutions allow operators to ensure the highest standards in safe, seamless travel with urban and mainline solutions that meet the specific needs of each operation environment. Internal Benefit International Exposure Global Mobility to Australia Career enhancement by joining the Australian team Experience...

  • Bid Technical Lead

    3 weeks ago


    Sydney, Australia Alstom Full time

    Alstom’s state-of-the-art signalling solutions allow operators to ensure the highest standards in safe, seamless travel with urban and mainline solutions that meet the specific needs of each operation environment. Internal Benefit International Exposure Global Mobility to Australia Career enhancement by joining the Australian team Experience...

  • Bid Technical Lead

    4 weeks ago


    Sydney, Australia Alstom Full time

    Alstom’s state-of-the-art signalling solutions allow operators to ensure the highest standards in safe, seamless travel with urban and mainline solutions that meet the specific needs of each operation environment. International ExposureGlobal Mobility to Australia Career enhancement by joining the Australian teamExperience in the Brownfield network.This...

  • Bid Technical Lead

    4 weeks ago


    Sydney, Australia Alstom Full time

    Alstom’s state-of-the-art signalling solutions allow operators to ensure the highest standards in safe, seamless travel with urban and mainline solutions that meet the specific needs of each operation environment.   International Exposure Global Mobility to Australia Career enhancement by joining the Australian team Experience in the...

  • Bid Technical Lead

    4 weeks ago


    Sydney, Australia Alstom Full time

    Alstom’s state-of-the-art signalling solutions allow operators to ensure the highest standards in safe, seamless travel with urban and mainline solutions that meet the specific needs of each operation environment.   International Exposure Global Mobility to Australia Career enhancement by joining the Australian team Experience in the...