Cyber Threat Investigator

2 weeks ago


Melbourne, Victoria, Australia Rapid7 Full time

About the Role

Rapid7 is seeking a skilled Cyber Threat Investigator to join our Managed Detection and Response (MDR) team. As a Threat Hunter, you will work proactively to uncover malicious activity that may have been missed by traditional security measures, and develop strategies to mitigate current and future threats.

Key responsibilities include:

  • Conducting ongoing hypothesis-based threat hunts utilizing new Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise/Attack (IOCs/IOAs)
  • Serving as a core component of the Rapid7 Emergent Threat Response (ETR) team to provide expertise and conduct hunts based on classified emerging threats across MDR customers
  • Conducting targeted hunts during major incidents based on past attacker activity and Incident Manager direction
  • Helping document and improve hunting processes, tools, and capabilities
  • Developing new Velociraptor hunt packages based on research and findings
  • Working closely with engineering, endpoint, Threat Intelligence and Detection Engineering (TIDE), Rapid7 Labs, and Velociraptor teams to prioritize roadmap items that improve threat hunting capabilities
  • Providing timely reporting and feedback to stakeholders
  • When applicable, publishing threat hunting topics to the Rapid7 blog

Requirements

The ideal candidate will have:

  • 2+ years in a Digital Forensics and Incident Response (DFIR) role, primarily focused on endpoint forensics
  • Broad knowledge of threat actor groups and their TTPs
  • Experience with Security Information and Event Management (SIEM) platforms and querying/analyzing large data sets
  • Ability to work with minimal oversight and prioritize efficiently
  • Strong analytical and research skills
  • Ability to think creatively and intuitively

Preferred Qualifications

The following differentiators are highly valued:

  • SANS FOR508 or FOR608 (or similar) and/or associated certifications (GCFA, GEIR, etc.)
  • Experience conducting targeted threat hunting
  • LEQL experience
  • Experience with Velociraptor
  • AWS Athena familiarity
  • Experience with the InsightIDR SIEM/XDR platform
  • Coding, engineering, and/or development experience
  • Data science and/or AI experience

About the Team

Rapid7's MDR team is built from the ground up to bring motivated and passionate security talent face to face with emerging threats, practical challenges, and evil at scale. Our MDR service uses an impact-driven mindset to focus efforts on effective solutions, encouraging personal and technical innovation within the SOC.



  • Melbourne, Victoria, Australia Rapid7 Full time

    About the RoleRapid7 is seeking a skilled Cyber Threat Investigator to join our Managed Detection and Response (MDR) team. As a Cyber Threat Investigator, you will be responsible for conducting proactive, hypothesis-driven threat hunts across all MDR customers to identify emerging cyber threats and malicious activity on networks and systems.You will work...


  • Melbourne, Victoria, Australia Rapid7 Full time

    About the RoleRapid7's Threat Hunting team is seeking a skilled Cyber Threat Investigator to join their ranks. As a Threat Hunter, you will be responsible for conducting proactive, hypothesis-driven threat hunts across all Managed Detection and Response (MDR) customers to identify emerging cyber threats and malicious activity on networks and systems.The...


  • Melbourne, Victoria, Australia Insignia Financial Full time

    Lead Cyber Security Threat and Vulnerability ManagementInsignia Financial is seeking a highly skilled Cyber Security Threat and Vulnerability Manager to lead our proactive identification and mitigation of threats, analysing cyber intelligence and coordinating risk-based remediation.Key Responsibilities:Develop and implement processes for scanning, assessing,...


  • Melbourne, Victoria, Australia Bupa Full time

    About the RoleWe are seeking a highly skilled Cyber Threat Intelligence Manager to join our team at Bupa. As a key member of our Cyber Security team, you will be responsible for overseeing and coordinating the activities of our Cyber Threat Intelligence team, managing information analysis and intelligence relevant to threats facing our systems,...


  • Melbourne, Victoria, Australia Bupa Full time

    Bupa, a leading international healthcare group, is seeking a highly skilled Cyber Threat Intelligence Manager to join their APAC Cyber Team. The successful candidate will oversee and coordinate the activities of the Cyber Threat Intelligence team, managing information analysis and intelligence relevant to threats facing Bupa's systems, infrastructure, and...


  • Melbourne, Victoria, Australia Bupa Full time

    About the RoleWe are seeking a highly skilled Cyber Threat Intelligence Manager to join our team at Bupa. As a key member of our Cybersecurity team, you will be responsible for overseeing and coordinating the activities of our Cyber Threat Intelligence team, managing information analysis and intelligence relevant to threats facing our systems,...


  • Melbourne, Victoria, Australia TESSERENT Full time

    Tesserent: A Leader in Cybersecurity SolutionsWe are seeking a highly skilled Cyber Threat Detection Specialist to join our team at Tesserent. As a Cyber Threat Detection Specialist, you will be responsible for collecting, analyzing, and producing threat detection implementations within various security systems and platforms.Key Responsibilities:Stay...

  • Cyber Threat Lead

    3 weeks ago


    Melbourne, Victoria, Australia Technology People Australia Full time

    Job Title: Cyber Threat LeadThe OrganisationTechnology People Australia is working with a large critical infrastructure organisation on a role to lead their Threat Intelligence, Vulnerability Management and Threat Hunting functions.This organisation's security capability is mature, with very smart practitioners, best in breed tools and buy in from the board...


  • Melbourne, Victoria, Australia Davidson Full time

    Our client in Melbourne CBD is seeking a proactive Cyber Threat Management Specialist to join their team.Position Overview:The successful candidate will work closely with internal teams and third-party vendors, overseeing threat intelligence, vulnerability assessment, and risk reduction efforts across both IT and OT environments.Key Responsibilities:Conduct...


  • Melbourne, Victoria, Australia TESSERENT Full time

    Role OverviewTesserent is seeking an experienced and highly motivated SOC Security Analyst to join our Security Operations Centre (SOC) team. The successful candidate will be responsible for actively monitoring, investigating, and responding to security threats.This role will be an embedded role, where you will act as an embedded security analyst for an...


  • Melbourne, Victoria, Australia TESSERENT Full time

    Role OverviewTesserent is seeking an experienced and highly motivated Security Operations Centre (SOC) analyst to actively monitor, investigate, and respond to security threats.This embedded role will act as a security analyst for an individual client, with the opportunity to transition to a generalist security analyst role within the SOC team.This position...


  • Melbourne, Victoria, Australia Davidson Full time

    Cyber Threat Management Position OverviewDavidson is seeking a skilled Cyber Threat and Vulnerability Management Specialist to join their team. The role is pivotal in protecting critical infrastructure by identifying, analyzing, and coordinating the remediation of security vulnerabilities.Key Responsibilities:Conduct vulnerability assessments and prioritize...


  • Melbourne, Victoria, Australia TESSERENT Full time

    Role OverviewTesserent is seeking an experienced and highly motivated Security Operations Centre (SOC) Analyst to join our team. The successful candidate will be responsible for actively monitoring, investigating, and responding to security threats.This role will be an embedded role, where you will act as an embedded security analyst for an individual...


  • Melbourne, Victoria, Australia FourQuarters Recruitment Full time

    Job Description:We are seeking a highly skilled Cyber Security Threat Analyst to join our Security Operations team. As a key member of the team, you will be responsible for providing major incident response, vulnerability management, and engineering services to support our clients.About the Role:Provide major incident response as part of a small team, as an...


  • Melbourne, Victoria, Australia Latitude IT Full time

    Latitude IT is seeking a talented Cyber Security Strategist to join our team. As a Cyber Security Strategist, you will work on the development and enhancement of cyber security strategies, collaborating with internal teams to address current and emerging threats.Key Responsibilities:Develop and enhance cyber security strategies; identify and prioritize...


  • Melbourne, Victoria, Australia Latitude IT Full time

    Job Title: Cyber Security SpecialistJob Summary:We are seeking a highly skilled Cyber Security Specialist to join our team at Latitude IT. As a Cyber Security Specialist, you will be responsible for working on the development and enhancement of cyber security strategies, collaborating with internal teams to address current and emerging threats, and designing...


  • Melbourne, Victoria, Australia Latitude IT Full time

    DFIR AnalystWe are seeking a talented individual to join our client's team as a DFIR Analyst.Key Responsibilities:Develop and enhance cyber security strategies to protect our organisation from current and emerging threats.Collaborate with internal teams to address cyber security incidents and provide actionable intelligence to stakeholders.Design and conduct...


  • Melbourne, Victoria, Australia Cyber Crime Full time

    Job Title: Security Operations SpecialistWe are seeking a highly skilled Security Operations Specialist to join our team. As a key member of our Cyber Crime organization, you will be responsible for providing support to our customers' Security Operations Centers by applying analytical and technical skills to investigate intrusions, identify malicious...


  • Melbourne, Victoria, Australia Cyber Crime Full time

    Job Title: Security Operations SpecialistWe are seeking a highly skilled Security Operations Specialist to join our team. As a key member of our Cyber Crime organization, you will be responsible for providing support to our customers' Security Operations Centers by applying analytical and technical skills to investigate intrusions, identify malicious...


  • Melbourne, Victoria, Australia Asahi Beverages Full time

    About the RoleCyber Security Analysts play a critical role in protecting Asahi Beverages' operations from cyber threats. In this key position, you will lead the detection, analysis, and response to cyber incidents across our operations.Main ResponsibilitiesMonitor security alerts and manage day-to-day incident response activities.Conduct thorough analyses of...