Senior Cyber Security Incident Commander

1 week ago


North Sydney Council, Australia Splunk Inc Full time

The Opportunity

At Splunk, we are dedicated to transforming machine data into actionable insights, ensuring that our solutions are accessible and valuable to all users. Our team is composed of individuals who are deeply passionate about our mission and committed to delivering exceptional experiences for our clients. We prioritize collaboration, innovation, and the success of our colleagues.

The Role

The Advanced Response Team (ART) plays a crucial role in managing responses to all Cyber Security Incidents within Splunk. As a member of ART, you will oversee high-level responses to intricate cyber security incidents impacting both corporate and cloud environments. Successful incident leaders at Splunk are continuous learners with a strong passion for security. Critical thinking and excellent communication skills are essential for this position.

You will coordinate diverse teams across the organization to ensure rapid containment of incidents. Additionally, you will identify essential steps for conducting thorough technical investigations to uncover security vulnerabilities and malicious activities, facilitating both immediate and long-term remediation efforts. Following incident containment, you will provide expertise to non-technical external partners, offering context and insights to enhance security standards throughout the organization.

Key Responsibilities

  • Establish and maintain strong relationships with business stakeholders and service providers across Splunk.
  • Lead the response efforts for complex cyber security incidents across various teams and environments.
  • Guide analysts during technical investigations to reconstruct the sequence of events leading to cyber security incidents and perform necessary analyses.
  • Advocate for enhancements to Splunk's cyber security posture through initiatives in threat hunting, detection, architecture, communication, and risk management.
  • Effectively communicate the narratives of cyber security incidents through comprehensive reports and presentations to key business partners.

Qualifications

  • 5+ years of professional experience in IT or IT Security.
  • A minimum of 2 years of experience leading responses to cyber security incidents.
  • Proficiency in administering, defending, or analyzing MacOS or Linux systems.
  • Technical expertise in two or more of the following areas: digital forensics, detection creation, threat hunting, cloud administration, programming/automation.
  • Experience with SIEM log analysis from a variety of network, host, and identity data sources.
  • Ability to manage multiple incidents simultaneously or handle large-scale incidents.
  • Comfort in mentoring junior analysts.
  • Experience in documenting and automating repetitive tasks and playbooks, preferably using Python.
  • Familiarity with process development and creation.
  • Ability to apply the MITRE ATT&CK and Killchain frameworks to security operations.
  • Strong multitasking and prioritization skills, especially in high-pressure situations.
  • Ability to convey highly technical information to non-technical stakeholders effectively.
  • Excellent interpersonal skills and a customer-centric perspective.
  • Participation in ART's on-call rotation for off-hours/weekend incidents.
  • Eligibility to work in Australia without company sponsorship.


  • North Sydney Council, Australia Splunk Inc Full time

    About the RoleWe are seeking a highly skilled and experienced Cybersecurity Incident Commander to join our Advanced Response Team (ART) at Splunk Inc. As a key member of our team, you will be responsible for leading the response to complex cyber security incidents affecting our corporate and cloud environments.Key ResponsibilitiesBuild strong relationships...


  • North Sydney Council, Australia Splunk Inc Full time

    About the RoleWe are seeking a highly skilled and experienced Cybersecurity Incident Commander to join our Advanced Response Team (ART) at Splunk Inc. As a key member of our team, you will play a critical role in coordinating the response to complex cyber security incidents affecting our corporate and cloud environments.Key ResponsibilitiesLead the...

  • Cyber Security Officer

    3 months ago


    North Sydney, Australia Gallagher Full time

    Overview Gallagher is one of Australia’s and the world’s largest Insurance broking and risk management companies with over 35,000 employees globally. We pride ourselves on being a socially responsible, ethical and collaborative organisation expressed through our Shared Values, The Gallagher Way. We are also proud to be on the Forbes World’s Best...

  • SOC Analyst

    4 months ago


    Sydney, Australia Talent International Full time

    australia sydney permanent package + benefitsWe have a newly created opportunity for a Security Operations Centre Analyst to step up into an Incident Commander role as part of a growing Global Cyber Information Security team. Working for a leading, global insurance firm this person will have the proud responsibility of protecting all company divisions...

  • SOC Analyst

    3 months ago


    Sydney, Australia Talent International Full time

    **Job Details**: **Location** Sydney **Salary** + Super + Benefits **Job Type** Full Time **Ref** BBBH102910_1686894656 **Contact** Catherine Wiggett **Posted** about 2 hours ago We have a newly created opportunity for a Security Operations Centre Analyst to step up into an Incident Commander role as part of a growing Global Cyber Information...

  • Incident Responder

    3 months ago


    Sydney, Australia Quigly Cyber Full time

    Diverse, inclusive and supportive team - Proudly making a difference with the transition to renewable energy - You love Cyber Security Quigly are a boutique consultancy with a great network of clients across many industries. **Company Overview** Join one of Australia's top organizations. Our client improves the lives of millions - from lighting up sports...


  • North Sydney Council, Australia Splunk Inc Full time

    The OpportunityAt Splunk Inc, we are on a mission to transform machine data into valuable insights for everyone. Our team is driven by a passion for our innovative products and a commitment to delivering exceptional experiences for our clients. We prioritize collaboration, success, and enjoyment in our work environment.The RoleThe Advanced Response Team...


  • Sydney, Australia Salesforce Full time

    Job Category Enterprise Technology & Infrastructure Job Details **About Salesforce** We’re Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across every industry blaze new trails and connect with customers in a whole new way. And, we empower you to be a Trailblazer,...


  • North Sydney Council, Australia Nine Entertainment Full time

    Job OverviewCyber Security plays a vital role in the success of Nine Entertainment, and we're seeking a highly skilled Senior Cyber Security Analyst to join our team.The ideal candidate will have a strong background in cybersecurity, with experience in threat hunting, threat intelligence management, and incident response. They will be responsible for...


  • Sydney, Australia Atlassian Full time

    Working at AtlassianAtlassians can choose where they work – whether in an office, from home, or a combination of the two. That way, Atlassians have more control over supporting their family, personal goals, and other priorities. We can hire people in any country where we have a legal entity. Interviews and onboarding are conducted virtually, a part of...


  • North Sydney Council, Australia Nine Entertainment Full time

    Job OverviewCyber Security plays a vital role at Nine Entertainment, focusing on safeguarding data, systems, and suppliers from cyber threats.The Senior Cyber Security Analyst will be part of the security operations team, working to detect, hunt, and respond to cyber security threats. This role involves detection engineering, incident response, and...


  • Sydney, New South Wales, Australia XM Cyber Full time

    About XM CyberXM Cyber is a pioneering threat and exposure management solution that revolutionizes the way organizations approach cyber security. Our cutting-edge technology enables clients to identify and remediate vulnerabilities with unprecedented efficiency, driving the most effective remediation options.Job SummaryWe are seeking an experienced and...


  • Sydney, New South Wales, Australia Australian Energy Market Operator Full time

    About the RoleAustralian Energy Market Operator (AEMO) is seeking a highly skilled Cyber Security Analyst to join our Cyber Incident Response team. As a key member of our team, you will play a critical role in protecting our energy systems from cyber threats.Key ResponsibilitiesTake a technical leadership role in cyber defence and response activities,...


  • North Sydney, Australia Gallagher Full time

    About Us: Welcome to Gallagher - a global leader in insurance, risk management, and consulting services. With a growing team of more than 45,000 professionals worldwide, we empower businesses, communities, and individuals to thrive. At Gallagher, you can build a career whether it’s with our brokerage division, our benefits and HR consulting division, or...


  • North Sydney, Australia Nine Entertainment Full time

    Job Description Cyber Security operates as part of Product and Tech and focused on finding the best way to secure data, systems and suppliers to protect the Nine organisation from cyber threats. The Senior Cyber Security Analyst will be a part of the security operations team aspiring to detect, hunt and respond to cyber security threats to Nine. The...

  • Cyber Security Analyst

    3 months ago


    Sydney, Australia NSW Government -Department of Customer Service Full time

    **Role: Cyber Security Analyst Roles** **Grade: Ongoing - Grade 7/8** **Location: Sydney or Bathurst** ***Role Type: Full Time Permanent** **About the Role** Cyber Security NSW is looking for a Cyber Security Analyst, focusing on incident response, to join our Intelligence and Response Team. The Intelligence and Response Team leads and coordinates...


  • Sydney Eastern Suburbs, Australia Robert Half Full time

    Join this large & recognisable global firm in a newly created role to lead the execution & coordination of IR processes, automation, and cloud IR. - Newly created role in a well-known global firm - Lead CSIRT activities in the region - Full time permanent role | Hybrid working **THE COMPANY** This large and well-known organisation employs more than 70,000...


  • Sydney, New South Wales, Australia CommBank Full time

    About UsWe are a leading financial institution, dedicated to delivering exceptional customer service through world-class process excellence and technology innovation.Our Technology division is responsible for delivering the Group's information technology and banking operations functions, ensuring the highest levels of customer service.About the RoleWe are...


  • Sydney, New South Wales, Australia Government of New South Wales Full time

    About the RoleThe Government of New South Wales is seeking a highly skilled Senior Cyber Security Analyst to join the Cyber Threat Intelligence team in the Department of Customer Service (DCS). This is an exciting opportunity to work closely with DCS agencies to uplift and improve cyber security, ensuring DCS digital services are safe and secure.Key...


  • Sydney, New South Wales, Australia CommBank Full time

    About the RoleWe are seeking a highly skilled Cloud Security Incident Response Senior Analyst to join our team. As a key member of our Cyber Defence Operations team, you will play a critical role in guiding solutions, services, and project initiatives within AWS and Azure environments.Key ResponsibilitiesAct as the technical cloud security SME and escalation...