Incident Response Consultant

7 months ago


Canberra, Australia Secureworks Full time

We enjoy competitive compensation and benefits packages, and reward and recognize our employees for exceptional results. A constant focus on continued learning and growth keeps our team members engaged and excited about “what’s next.” We offer flexible work options when available, and emphasize the importance of work-life balance. We know that when our people are rewarded, recognized, and rejuvenated, we win as a team.

Role Overview

The Incident Response Consultant is primarily focused on the delivery of emergency incident response services. This involves supporting customers by managing the technical and non-technical aspects of incident response, conducting investigative analysis using digital forensics methods to determine the nature, scope, and root cause of cyber incident activity, formulating recommendations for security posture enhancement, and developing tailored remediation plans.

Additionally, the Incident Response Consultant may be required to deliver a range of proactive incident response services. These services include cyber threat hunting to help customers identify unknown compromise activity and gaps in their cybersecurity controls, as well as workshops, training courses, and exercises to help customers improve their incident response capabilities.

Role Responsibilities
- Perform complex incident response investigative analysis and develop assessments based on the analysis of host, network, and cloud digital artifacts
- Document analysis findings and develop recommendations to present both orally and in written reports to customers
- Develop tailored incident response remediation plans for major cyber incidents to direct customer containment and recovery efforts
- Manage urgent and critical interactions with customers
- Maintain professional, calming, and authoritative presence during a crisis
- Participate in a 24x7 on-call rotation for supporting requests from global incident response customers
- Travel as needed to assist customers with on-site incident response efforts

This is a remote (work-from-home) position that may require up to 20% travel.

**Requirements**:

- Minimum five (5) years of cybersecurity experience in complex operating environments
- Minimum three (3) years in a customer facing support role (Security Engineer, Client Services, Consulting, Professional Services)
- Minimum of two (2) years of host forensics, network forensics, and cloud forensics experience for threat hunting and incident response efforts
- GCIH, GCFE, GCFA, GREM or similar certifications
- Strong communication skills (oral and written)
- Experience briefing senior-level leadership and conveying technical information to audiences of varying backgrounds and skill levels
- Ability to prioritize urgent tasks and work multiple consulting engagements concurrently
- Desire to work with customers to solve complex cybersecurity issues, including during crisis situations
- Theoretical and practical knowledge in the following areas:

- Windows and Linux operating systems
- AWS, Azure (including Microsoft 365), and GCP
- Exploits, vulnerabilities, intrusion vectors, and malware
- Tactics, techniques, and procedures (TTPs) commonly employed by threat actors
- Host forensics, network forensics, and malware analysis techniques
- Network traffic analysis, endpoint activity analysis, and log analysis techniques
- Enterprise cyber incident management and response processes
- Enterprise cybersecurity controls and failure modes
- Modern Enterprise Detection and Response (EDR) tools

**Job ID**:R239195
**Dell’s Flexible & Hybrid Work Culture**

At Dell Technologies, we believe our best work is done when flexibility is offered.

We know that freedom and flexibility are crucial to all our employees no matter where you are located and our flexible and hybrid work style allows team members to have the freedom to ideate, be innovative, and drive results their way. To learn more about our work culture, please visit our locations page.



  • Canberra, Australia Secureworks Full time

    We enjoy competitive compensation and benefits packages, and reward and recognize our employees for exceptional results. A constant focus on continued learning and growth keeps our team members engaged and excited about “what’s next.” We offer flexible work options when available, and emphasize the importance of work-life balance. We know that when our...

  • Incident Manager

    1 week ago


    Canberra, Australia HiTech Personnel Full time

    **Reference #**: - JF/NL0786**Title**: - Incident Manager - FED GOVT**Category**: - ICT**Location**: - ACT**Work Type**: - Contract**Remuneration**: - $Neg**Term**: - 6 months**Description**: - **Exciting opportunity within a Leading Federal Government Department**: - **6-month contract + extensions!!**: - **Rewarding Rates!** One of Australia’s...

  • Incident Managers

    1 week ago


    Canberra, Australia Powerdata Group Consulting Full time

    Open to: **NV1 Holders Only** location: **Canberra** **6 + Months** **Contract** The Incident Manager supports the ICT Change Manager in the day to day management of matters relating to incidents for technical ICT and core business operations, processes within the Service Operations Section of the Digital Technology Branch, including participating in...


  • Canberra, Australia GMT People Full time

    Melbourne, Canberra or Brisbane - Fed Gov - aviation sector - Aus Citizens only with ability to obtain a Security Clearance **The Opportunity**: As **Incident Process Practitioner**, you will work with stakeholders across the enterprise to drive the adoption of the Incident process and procedures, adapt it to the organisations needs and embed into the...


  • Canberra, Australia FinXL Full time

    Location: - Canberra CBD, Australian Capital Territory- Job Type: - Contract- Specialisation: - Commercial- Salary: - Negotiable- Reference: - CR/012817_1659334745**Canberra based** **12 months contract** **Great company** Our client is looking for an experienced **Incident/Release Co-ordinator** to work for a large consultancy in Canberra. **Skills and...


  • Canberra, Australia halcyonknights Full time

    We have an exciting opportunity for an **Incident Manager** to play a pivotal role in managing incidents for a federal department's technical ICT and core business operations. **About the Role**: In this role, you will collaborate closely with our ICT Change Manager to ensure the effective day-to-day management of incident-related matters. Your...

  • Incident Manager Afp

    2 weeks ago


    Canberra, Australia Genesis IT&T Pty Ltd Full time

    **Global IT Company**: - **Canberra location**: - **NV1 Required** To conduct incident management across the defined environment. Providing SME knowledge and guidance in order to govern and fulfil the Incident management capability. **Responsibilities**: - Provide governance and SME knowledge of the Incident Management environment. - Monitor the...


  • Canberra, Australia Aris Zinc Full time

    Federal Government - NV2 Security Clearance - Multiple Locations The position will undertake the Incident and Problem Manager functions, performing the following activities: - Incident and Problem tasking within operational support of the WNA; - Report on and provide advice to stakeholders and Project Senior Leadership Team on incidents that are...

  • Itil Incident Manager

    8 months ago


    Canberra, Australia Leidos Full time

    Company Description People join Leidos Australia for many different reasons. The interesting projects. Supportive and open-minded colleagues. The opportunities to develop. What unites us is the fact that everything we do benefits and safeguards Australia in some way. We’re proud of our Mission to make the world safer, healthier and more efficient, and...


  • Canberra, Australia Strata Results Recruitment Full time

    Based in Canberra - Multiple Positions - Exciting Role **Your New Role** The Event & Incident team is responsible for ensuring that all IT event and incident processes are effective in delivering restoration of normal service operations as soon as possible. **Key activities include** - Ensuring that event monitoring is conducted in line with appropriate...


  • Canberra, Australia Leidos Full time

    Company Description We’re a large scale systems integration company, committed to delivering trusted solutions that help to safeguard Australia. With over 20 years’ local experience and the backing of a 32,000 global network, we currently number 1,000 employees mainly in Canberra and Melbourne. We’re growing fast and are building a business that is...


  • Canberra, Australia Australian Government Full time

    Ongoing - Salary: $94 729 to $105 669 plus 15.4% superannuation - Canberra, ACT **Employment Opportunity** The Incident and Problem Manager (IPM) is a critical role in the IT Service Support team. This position offers the successful applicant the opportunity to create a real difference in the management of incidents and problems, with the potential to...


  • Canberra, Australia Leidos Full time

    Company Description We’re a large scale complex systems integration company, committed to delivering trusted solutions that help to safeguard Australia. With over 20 years’ local experience and the backing of a 32,000 people global network, we’re growing fast. The first thing you learn at Leidos Australia is to leave current thinking at the door. Our...


  • Canberra, Australia DXC Technology Full time

    DXC Technology (NYSE:DXC) - where brilliant people embrace change and seize opportunities to advance their careers and amplify customer success. At DXC we pride ourselves on delivering excellence in everything we do. What this means for you is the opportunity to be a part of delivering innovative solutions and helping to solve real business problems for a...


  • Canberra, Australia Ignite Specialist Recruitment Services Full time

    Contract Type Contract Reference BH-369705 Industry Public Sector & Government Salary Negotiable - Experienced security incident manager needed by a large goverment agency we are working with to review controls, provide uplift recommendations, and deliver training.**Responsibilities**: - Develop security incident management plan and Standard...


  • Canberra, Australia Fujitsu Full time

    **Major Incident Specialist** **We are Fujitsu** We use technology to make happier lives. We are a global leader in technology and business solutions that transform organizations and the world around us. We have a long heritage of bringing innovation and expertise, continuously working to contribute to the growth of society and our customers. **About the...


  • Canberra, Australia Onpoint 365 Full time

    Competitive hourly rates - Flexible working arrangements - 12 month contract - possible 12 month extension **Security Incident Management Analysts** **Location**: Canberra, ACT **Work terms**: Initial 12-month contract with possible 12-month extension. ***Must be in office a min of 3 days can WFH 2 days a week. **Department**:Department of Health and...


  • Canberra, Australia HiTech Personnel Full time

    **Reference #**: - JF/DS0048**Title**: - Protective Security Incident Management Analyst - Federal Govt**Category**: - ICT**Location**: - ACT**Work Type**: - Contract**Remuneration**: - $Neg**Term**: - 12 Months Plus 12 Mo**Description**: - Leading Federal Government Department - 12 -month contract + extension!! - Rewarding Rates and work from home...


  • Canberra, Australia Etainsolutions Full time

    **Location**: **Canberra (hybrid)** Open To: **Must have Baseline Security Clearance** Protective Security Incident Management Analysts. The role is within the Protective Security Operations you will be working with key stakeholders internally and externally to the department. You will be responsible for the day-to-day management of security arrangements...


  • Canberra, Australia Halcyon Knights Full time

    12 + 12 month contract - Woden location - Current Baseline (or higher) Security Clearance required **Protective Security Incident Management Analyst** - 12 + 12 month contract - Woden location - Current Baseline (or higher) Security Clearance required The role requires an experienced security incident manager (excluding cyber incidents) to review the...