Cybersecurity Response

1 week ago


Sydney, Australia Kyndryl Australia Pty Ltd Full time

**Why Kyndryl**

Kyndryl was spun-off of IBM IT infrastructure services in 2021. Our global base of customers includes 75 of the Fortune 100 companies. With 88,449 skilled professionals operating from over 100 countries, we are committed to the success of our customers, collaborating with them, and helping them to realise their ambitions.

We help our customers design, manage, and modernise the technology systems they depend on every day. Kyndryl is the ‘hearts and lungs’ because we support mission critical infrastructure.

Kyndryl has operations in 63 countries; 450 data centres around the world are under our management. We have the majority of mainframe capacity, generating and running 9 million automated actions per month for our customers.

**Your Role and Responsibilities**

The Kyndryl CSIRT is looking for a Cybersecurity Response (CSIRT) Analyst to join an advanced team that drives proactive identification of threats within the organization, provide rapid response, monitors user activity, network events, and signals from security tools to identify events that merit attention, prioritization, and investigation. We are seeking a talented individual responsible for cybersecurity threat incidents including forensic investigations, and analysis in support of cyber incidents that are reported into the Incident Response team. This role will require the ability to triage and conduct thorough examinations of all information technology systems across diverse cloud environments, the ability to determine containment and/or remediation activities that may be required as well as identify potential threats. Reporting and collaborating with the different areas of business is required.

Responsibilities include:

- At least 5 years of experience in IT Security Digital Forensics
- At least 5 years of experience in Incident Response in a global corporate enterprise
- Demonstrated computer forensic investigations experience.
- Excellent technical writing and presentation skills.
- Expert-level knowledge of common attack vectors and penetration techniques.
- Solid working knowledge of networking technology and tools, firewalls, proxies, IDS/IPS and encryption.
- Demonstrated knowledge of forensic tools (Encase, FTK, Axiom Magnet, Black Bag, SIFT, Kali)
- Experience with malware analysis (reverse engineering).
- Experience managing large and small-scale cyber security incidents.
- Demonstrated understanding of database structures and SQL.
- Conduct examination of digital media (hard drives, network traffic, images, etc.).
- Capture / analyze network traffic for indications of compromise.
- Review log-based data, both in raw form and utilizing SIEM or aggregation tools.
- Perform live network assessments using leading packet capture and analysis software tools.
- Establish timelines and patterns of activity based on multiple data sources.
- Identify, document and prepare reports on relevant findings.
- Strong understanding of networking protocols
- Experience with programming or scripting languages (Python, Ruby, Powershell)
- Demonstrated system administration skills.

**NOTE**: This is a remote work from home.

**Required Technical and Professional Expertise**
- Extensive experience in IT Security and Digital Forensics
- Strong experience managing incidents in a global corporate environment
- Demonstrated computer forensic investigations experience.
- Excellent technical writing and presentation skills.
- Expert-level knowledge of common attack vectors and penetration techniques.
- Solid working knowledge of networking technology and tools, firewalls, proxies, IDS/IPS and encryption.
- Demonstrated knowledge of forensic tools (Encase, FTK, Axiom Magnet, Black Bag, SIFT, Kali)
- Experience with malware analysis (reverse engineering).
- Experience managing large and small-scale cyber security incidents.
- Demonstrated understanding of database structures and SQL.
- Conduct examination of digital media (hard drives, network traffic, images, etc.).
- Capture / analyze network traffic for indications of compromise.
- Review log-based data, both in raw form and utilizing SIEM or aggregation tools.
- Perform live network assessments using leading packet capture and analysis software tools.
- Establish timelines and patterns of activity based on multiple data sources.
- Identify, document and prepare reports on relevant findings.
- Strong understanding of networking protocols
- Experience with programming or scripting languages (Python, Ruby, Powershell)
- Demonstrated system administration skills.

**Preferred Technical and Professional Experience**

Any two of the following:

- ACE (Access Data Certified Examiner)
- EnCe ( EnCase Certified Examiner)
- AWS Security
- GCFE (GIAC Certified Forensics Examiner)
- GNFA (GIAC Network Forensics Analyst)
- GCIA (GIAC Certified Intrusion Analyst)
- GCIH (GIAC Certified Intrusion Handler)
- GREM (GIAC Reverse Engineering Malware)
- OSCP (Offensive Security Certified Professional)

**



  • Sydney, Australia Gridware Cybersecurity Full time

    **Location**: Sydney, Hybrid **Employment Type**: Full-Time **About Gridware** Gridware is a leading cybersecurity consulting firm based in Australia, dedicated to protecting organisations from cyber threats through innovative solutions and expert services. As part of our mission to inform and educate, we produce high-quality video content that supports...

  • Cybersecurity Lead

    1 day ago


    Sydney, New South Wales, Australia Motorcycle Holdings Full time $120,000 - $180,000 per year

    About the companyMotorCycle Holdings (MTO) is an ASX-listed market leader in the provision of motorbikes for retail and wholesale customers, operating across 50 retail outlets and 5 distribution warehouses nationally. With a strong reputation for innovation and customer service, we are investing in our digital and IT capabilities to support our continued...


  • Sydney, New South Wales, Australia FTI Consulting Full time

    About The RoleFTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth. The Cybersecurity Practice within FTI Consulting is a leading provider of independent cybersecurity and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness, Incident...


  • Sydney, Australia Rapid7 Full time

    **Cybersecurity Advisor** **About the Team** **About the Role** As a Cybersecurity Advisor, you will be the key trusted advocate to our customers. Your valuable experience and in-depth understanding of the security landscape will be pivotal in shaping the customer perception of Managed Services and its exceptional service. Our Cybersecurity Advisors are...


  • Sydney, Australia Rapid7 Full time

    **Cybersecurity Advisor** **About the Team** **About the Role** As a Cybersecurity Advisor, you will be the key trusted advocate to our customers. Your valuable experience and in-depth understanding of the security landscape will be pivotal in shaping the customer perception of Managed Services and its exceptional service. Our Cybersecurity Advisors are...


  • Sydney, Australia NSAA Security Full time

    **Overview** NSAA Security is seeking a **Cybersecurity Sales Specialist** with strong technical expertise and a consultative approach to drive business growth across Australia and international markets. This role is ideal for professionals experienced in delivering impactful product demos, leading pilots, and engaging in high-level security discussions...


  • Sydney, New South Wales, Australia Tech Mahindra Full time $180,000 - $220,000 per year

    Job SummaryJob Title: Senior Cybersecurity Project Manager Location: TechM AUS Sydney Years of Experience: 7 10 Years Job Summary We are seeking a highly skilled Senior Cybersecurity Project Manager to lead and manage cybersecurity projects within our organization. The ideal candidate will have extensive experience in project management, particularly in the...


  • Sydney, New South Wales, Australia FTI Consulting Full time $80,000 - $120,000 per year

    About The RoleFTI Consulting is the number one global expert firm for organisations facing crisis, transformation and moments of truth. The Cybersecurity Practice within FTI Consulting is a leading provider of independent cybersecurity and risk management advisory services with a core offering focused on (but not limited to) Cyber Readiness, Incident...


  • Sydney, New South Wales, Australia Data#3 Full time $120,000 - $180,000 per year

    6-Month Contract | Sydney CBD | Australian Citizen (preferably with AGSVA Baseline Clearance)Our client is seeking an experienced Cybersecurity Cloud Specialist to provide expert guidance across multiple cloud implementation projects. The successful candidate will work closely with internal staff, service integrators, and external engineers to ensure all...


  • Sydney, New South Wales, Australia Cybertify Full time $104,000 - $130,878 per year

    Job Title: Cybersecurity & IT Systems EngineerLocation: Sydney (5 days Onsite – CBD Office - Wynyard Station)About CybertifyCybertify is Australia's premier compliance-first cybersecurity consulting firm, proudly Australian owned, fully independent, and sovereign in every respect. We specialise in protecting and enabling organisations in the country's most...