Cyber Incident Response Specialist
4 days ago
**Summary**:
StickmanCyber is seeking a highly experienced Senior Incident Response Analyst with Digital Forensic expertise to direct and execute the company’s MSSP incident response capabilities. This individual will oversee complex investigations, own IR governance and playbooks, coordinate with cross-functional stakeholders during live incidents, and lead the development and tuning of detection logic across Google SecOps, Sentinel, CrowdStrike and other related security technologies across all the Customers within MSSP SOC. This is a mid-level leader, technical hands-on position supporting StickmanCyber’s MSSP SOC. The role requires handling sophisticated threats, forensics and detection engineering in high-velocity environments. As the Senior DFIR Expert, you will be assisting our analysts with daily investigations, evaluation of emerging compromises and vulnerabilities and helping to develop advanced use cases that can be used to detect active or attempted compromise on our client’s information systems. You are also required to be a personal motivator, working with analysts to develop their career, their skills, and overall team culture. You are expected to identify ways to positively impact team performance and encourage innovation, while displaying a positive customer service attitude to our partners and clients. Finally, you are required to review current SOC processes and work to improve to offer our clients world class SOC services.
**Primary DFIR Responsibilities**:
- Lead and manage high-impact cybersecurity incidents through all phase detection, containment, eradication, and recovery, ensuring mínimal business impact.
- Oversee detailed digital forensics investigations across endpoints, servers, and cloud platforms, maintaining evidence of integrity, chain of custody, and comprehensive reporting.
- Conduct proactive threat hunting leveraging behavioral analytics, threat intelligence, and hypothesis-driven techniques to identify stealthy adversaries and undetected compromises.
- Develop and enhance detection and hunting playbooks, focusing on MITRE ATT&CK-aligned TTPs, anomaly detection, and continuous improvement of detection coverage.
- Perform root-cause analysis and adversary profiling to uncover vulnerabilities, exploited vectors, and attacker TTPs; translate findings into actionable threat intelligence.
- Collaborate closely with SOC (L1-L3) teams, customers, law enforcement, and third-party IR partners to coordinate containment and recovery activities.
- Provide executive-level reporting and lessons learned to senior leadership, driving enhancements in controls, response workflows, and automation.
- Lead and facilitate incident response exercises, tabletop simulations, and threat of hunting sprints to validate readiness and strengthen operational resilience.
- Stay current with evolving threat landscapes, forensic methodologies, and detection technologies, integrating relevant advancements into SOC operations.
- Collaborate with the Security Engineering team to optimize SOAR automations that streamline incident responses and improve analyst efficiency.
- Coach and mentor junior analysts in incident handling, threat hunting, and forensic analysis to uplift team capability and maturity.
- Support critical incidents requiring after-hours response when necessary.
**Essential Skills & Experience**:
- Minimum 5-8 years’ experience in cyber security with strong incident response and/or digital forensics focus.
- Hands-on experience with forensic tools and techniques and log/event analysis.
- Proven experience investigating real-world security incidents, including advanced threats, ransomware, cloud breaches, or APT activity.
- Proficiency with endpoint, server, network, and cloud (AWS/Azure/GCP) forensics and incident response.
- Strong analytical, investigative, and root-cause skills. Ability to write clear incident reports and executive summaries.
- Solid understanding of security frameworks, incident response methodologies (e.g., NIST IR), and threat actor TTPs (e.g., MITRE ATT&CK).
- Experience developing incident response playbooks and forensics workflows.
- Excellent communication skills; able to engage technical teams, stakeholders and executive leadership.
- Relevant certifications GCIH, GCFA, GREM, CHFI etc. are preferred but not mandatory.
**Desirable Attributes**:
- Experience in SOC environments, including L2/L3 escalation and working with SOC triage/hunting teams.
- Familiarity with automation/orchestration (SOAR tools), scripting forensics workflows.
- Exposure to regulated environments (e.g., finance, critical infrastructure, government) and handling sensitive data/incidents.
- Ability to coach and mentor other analysts and drive capability building within the team. Comfortable working occasional odd hours where incident coverage is required.
Pay: From $83,612.86 per year
Work Location: In person
- 
					
						Cyber Security Operations Specialist
4 days ago
Osborne Park, Australia Racing and Wagering Western Australia Full time**Company Description**: **About Us** Racing and Wagering Western Australia (RWWA) is at the heart of WA’s racing and wagering industries. As a government trading enterprise, we regulate and develop the State’s racing sector and operate the TAB - a multifaceted wagering business with a presence across more than 300 retail outlets and a growing digital...
 - 
					
Cyber Security Operations Specialist
1 week ago
Osborne Park, Western Australia RWWA Full time $80,000 - $120,000 per yearCompany DescriptionAbout UsRacing and Wagering Western Australia (RWWA) is at the heart of WA's racing and wagering industries. As a government trading enterprise, we regulate and develop the State's racing sector and operate the TAB – a multifaceted wagering business with a presence across more than 300 retail outlets and a growing digital platform.Our...
 - 
					
						Cyber Security Operations Specialist
2 weeks ago
Osborne Park, Australia Racing and Wagering Western Australia Full time $80,000 - $120,000 per yearCompany DescriptionAbout Us Racing and Wagering Western Australia (RWWA) is at the heart of WA's racing and wagering industries. As a government trading enterprise, we regulate and develop the State's racing sector and operate the TAB – a multifaceted wagering business with a presence across more than 300 retail outlets and a growing digital platform.Our...
 - 
					
						Cyber Security Operations
6 days ago
Sydney Olympic Park, Australia NSW Government -NSW Police Force Full time**Computer Systems Officer - Level 5**: - **Temporary Full-Time up to 2026**: - **Sydney Olympic Park** **About us** The NSW Police Force (NSWPF) is one of the largest police forces in the western world, with more than 20,000 employees, including more than 4,000 administrative employees who support the sworn officers that provide a range of law and order...
 - 
					
						Incident & Problem Manager
12 hours ago
Macquarie Park, Australia Optus Full time**Location**: Macquarie-Park, NSW **Company**: Optus **Type**: Full Time **Job ID**: 161122 **Date**: 6 October 2024 1:54 AM We don’t sit back and wait for the future to happen, we are out there crafting our own path through new technology, innovation, and investment. We are truly a challenger brand, with challenger spirit. The Problem and Incident Manager...
 - 
					
						Specialist Hub Coordinator
6 days ago
Macquarie Park, Australia WiSE Medical Specialist Emergency Full timeWiSE Medical are on the hunt for a Specialist Hub Coordinator to join our Macquarie Park Cllinic. Why WiSE Medical? - Innovative Healthcare: Be part of a team dedicated to revolutionising healthcare services. - Collaborative Environment: Work with a dynamic and supportive team that values creativity and teamwork. - Career Growth: WiSE Medical is committed...
 - 
					
						Cyber Security Analyst
1 week ago
Oran Park, Australia Camden Council Full timeSALARY: $ 2,146.73- $2,459.38 pw + Super Work Type: Temporary Full Time - Up to 12 Months Location: Oran Park Administration Building - 70 Central Avenue, Oran Park 2570 - Enjoy a 35-hour working week - Flexibility through Flex leave provisions and hybrid work arrangements - Health program including free flu vaccinations, skin checks and health and...
 - 
					
						Cyber Security Consultant
2 weeks ago
Macquarie Park, Australia Stickmancyber Full time**Summary**: We are looking for a dedicated and detail-oriented Cyber Security Consultant who is risk-focused and has expertise in conducting ISO 27001 and SOC (Service Organization Control) audits. You will be responsible for evaluating internal controls, assessing risks, and supporting the growth and transformation of our...
 - 
					
						She Specialist
2 weeks ago
Macquarie Park, Australia Ecolab Full time**About Ecolab**: Every day, we make the world cleaner, safer and healthier - protecting people and vital resources. Ecolab is the global leader in water, hygiene and services. Around the world, businesses in foodservice, food processing, hospitality, healthcare, industrial, mining markets choose Ecolab products and services to keep their environment clean...
 - 
					
						Security Delivery Lead
7 days ago
Macquarie Park, Australia DXC Technology Full time $104,000 - $130,878 per yearJob Description:DXC Technology (NYSE:DXC) - where brilliant people embrace change and seize opportunities to advance their careers and amplify customer success. At DXC we pride ourselves on delivering excellence in everything we do. What this means for you is the opportunity to be a part of delivering innovative solutions and helping to solve real business...