Incident Response Specialist

1 day ago


Canberra, Australia BAE Systems Full time

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.

**Incident Response Specialist**

**Role summary**

We are looking for a talented and experienced Incident Response specialist to join our Security Consulting team. The role will be responsible for supporting our IR capabilities in-country and will oversee both our response to incidents as and when they occur, but also the growth and development of the capability to ensure it remains equipped and prepared to respond to incidents whenever and wherever they occur.

This role is situated in either Canberra or Melbourne and will require a government security clearance at NV1 (minimum), with potential expectation to undergo higher clearances.

**What you’ll be doing**
- Leading the investigation of cyber-attacks against our customers as part of the global Incident Response team, with a particular focus on Australia-based customers.
- Monitoring SIEM platforms for security concerns, providing tuning based on system performance, and developing new detection content based on changes in the threat environment.
- Developing tools, tradecraft, playbooks, and other materiel to support the response to, and investigation of, cyber security incidents.
- Supporting the triage and containment of cyber security incidents as and when they occur and supporting recovery and remediation efforts to restore systems to operational states.
- Conducting forensic analysis of Windows, Linux and macOS devices. Gathering and performing analysis of relevant log files such as operating system, firewall, proxy and DNS logs.
- Providing assessment and analysis of attacker tools, techniques, and procedures of different actors from hacktivist to criminal to nation state.
- Supervising and mentoring junior security consultants and supporting the development of their incident response skillsets.
- Help grow and evolve our delivery capability by documenting the delivery processes, feeding back lessons learned and working with the wider team in establishing best practices and repeatable processes.
- Collaborating with your peers across the Digital Intelligence business, both in Australia and overseas, to look for ways to continuously add value to the business, build your professional network, and share experiences

**What we’re looking for**

**Essential**:

- Demonstrable experience in leading and supporting the response and investigation of cyber security incidents across a range of system and technology types.
- Experience working with Splunk, including platform configuration, event review and detection content development.
- Experience using forensic tools such as EnCase, Axiom and Cellebrite UFED and their use in gathering and preserving digital forensic artefacts to facilitate or support investigative activities.
- Awareness of EDR tools such as Crowdstrike, Carbon Black, Microsoft Defender for Endpoint and Cylance.
- Ability to write Incident Response reports concisely and proficiently, as well as use (or generate) graphics to illustrate scenarios or datasets.
- Detailed knowledge of the cyber security product landscape, including familiarity with Azure and Amazon Web Services.
- Experience in developing, maintaining and exercising incident response plans, playbooks, and other tradecraft.
- Familiarity with the Australian Government Information Security Manual (ISM)
- Experience working with large groups of varied stakeholders, coordinating resources and achieving shared goals.
- Experience with working with end users and clients offering advice, guidance and thought leadership. Ability to communicate complicated technical challenges in business language for a range of stakeholders from IT teams to C-level executives.
- Excellent verbal and written communication and client-facing skills, including Microsoft Office suite use (Word/Excel/PowerPoint/Visio), ensuring a clear and professional quality of written materials.
- Time management and organizational skills to independently manage multiple delivery projects concurrently.
- Detail-oriented approach.
- Self-starter with ability to identify problems early and come up with solutions using own initiative.
- Familiarity with the threat landscape and knowledge of threat actors and campaigns.

**Highly desirable**:

- Splunk Core Certified Power User
- SANS FOR508 Digital Forensics & Incident response in person 6 days/or online
- Other certifications such as GIAC (GCFE, GCFA, GNFA, GCIH or GREM) or CREST (CCIM, CCHIA, CCNIA or CCMRE).

**Why BAE Systems?**

This is a place where you’ll be able to make a real difference. You’ll be part of an inclusive culture that values diversity of thought, rewards integrity, and merit, and where you’ll be empowered to fulfil your potential.



  • Canberra, ACT, Australia BAE Systems Full time $104,000 - $130,878 per year

    BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.Incident Response SpecialistRole...


  • Canberra, Australia Secureworks Full time

    We enjoy competitive compensation and benefits packages, and reward and recognize our employees for exceptional results. A constant focus on continued learning and growth keeps our team members engaged and excited about “what’s next.” We offer flexible work options when available, and emphasize the importance of work-life balance. We know that when our...


  • Canberra, Australia Secureworks Full time

    We enjoy competitive compensation and benefits packages, and reward and recognize our employees for exceptional results. A constant focus on continued learning and growth keeps our team members engaged and excited about “what’s next.” We offer flexible work options when available, and emphasize the importance of work-life balance. We know that when our...

  • Security Consultant

    5 days ago


    Canberra, Australia Anson McCade Full time

    Be a part of Australia's largest enterprise software company - Flexible hours - Competitive Salary Highly renowned cyber division of my client, a leading product vendor, is seeking a highly ambitious and dynamic Security Consultant to contribute to the team in order to expand the SecOps capabilities. As a Security Consultant, you will be involved in...


  • Canberra, Australia Leidos Full time

    Company Description Every person at Leidos plays an important and valued role bringing science, engineering and technology together to produce practical solutions for our customers’ most complex problems. It’s how we help to make the world safer, healthier and more efficient - work that matters and a mission, like those of our customers, we are...

  • Incident Manager

    2 weeks ago


    Canberra, Australia Leidos Full time

    **Description** - We’re a ‘Family Friendly’ certified workplace - we understand the often many and varied roles our team members need to play within their own unique family setting and actively support them. **Do Work That Matters** Leidos Australia delivers IT and airborne solutions that protect and advance the Australian way of life. Our 2000 local...

  • Incident Manager

    4 weeks ago


    Canberra, Australia Leidos Full time

    Description - We’re a ‘Family Friendly’ certified workplace – we understand the often many and varied roles our team members need to play within their own unique family setting and actively support them. Our team feel Leidos is a great place to work. Learn more about our culture and benefits by visiting us here...

  • Incident Manager

    1 week ago


    Canberra, ACT, Australia Leidos Australia Pty Ltd Full time $80,000 - $120,000 per year

    DescriptionWe're a 'Family Friendly' certified workplace - we understand the often many and varied roles our team members need to play within their own unique family setting and actively support them.Our team feel Leidos is a great place to work. Learn more about our culture and benefits by visiting us here Do Work That MattersLeidos Australia delivers IT...

  • Incident Manager

    4 days ago


    Canberra, ACT, Australia Leidos Full time $80,000 - $240,000 per year

    We're a 'Family Friendly' certified workplace – we understand the often many and varied roles our team members need to play within their own unique family setting and actively support them.Our team feel Leidos is a great place to work. Learn more about our culture and benefits by visiting us here Do Work That MattersLeidos Australia delivers IT and...

  • Incident Manager

    2 weeks ago


    Canberra, ACT, Australia Charterhouse Full time $90,000 - $120,000 per year

    We are seeking an experienced ITSM professional to join a high-performing service management team. This role focuses on leading Major Incident Management (MIM) and Problem Management practices within a complex IT environment, ensuring rapid resolution of high-impact issues and driving continuous service improvement.Role in Canberra and requires an active...