Manager - Incident Response and Cyber Defence

2 months ago


Melbourne, Australia Deloitte Full time

Job Requisition ID: 36349 

  • Learn from the best in the business
  • Mentoring, growth and training – receive support and coaching to progress your career
  • Preventive and supportive mental health initiatives

About the Role

The Manager – Incident Response and Cyber Defence will play a key operational role in supporting the Head of Cyber Defence, focusing on incident detection, response, and containment. This individual will oversee SOC operations, ensure SIEM alerts are properly managed, and lead efforts to respond to critical cyber incidents. They will also handle IOCs and threat intelligence, working proactively to prevent security breaches. The Manager will act as a key escalation point for cyber incidents and provide leadership in threat detection, ensuring seamless security operations. With the potential to grow into a second-in-command (2IC) role, this position offers an opportunity for long-term leadership development.

Key Responsibilities

Incident Response & Cyber Resilience:

  • Lead the response to cyber incidents, ensuring rapid mitigation, containment, and resolution.
  • Maintain and execute the organization’s Incident Response Plan (IRP) with alignment to regulatory requirements and business goals.
  • Oversee post-incident reviews to identify gaps, implement improvements, and update the IRP accordingly.
  • Manage coordination with external response partners and regulators when necessary during significant incidents.
  • Regularly conduct tabletop exercises and simulations to test the organization’s preparedness and refine response processes.

SOC & Threat Detection:

  • Manage the Security Operations Centre (SOC) to ensure 24/7 monitoring and effective incident handling.
  • Oversee the tuning of SIEM platforms, IDS/IPS, and other monitoring tools to optimize detection accuracy and reduce false positives.
  • Ensure critical vulnerabilities generating alerts in the SIEM are properly identified, escalated, and responded to promptly.
  • Coordinate the response to Indicators of Compromise (IOCs), leveraging intelligence sources to contain and prevent incidents.
  • Monitor SOC metrics and incident trends to identify areas for operational improvement.

Threat Intelligence & IOC Handling:

  • Collaborate with threat intelligence teams to incorporate actionable intelligence into detection and response efforts.
  • Manage IOC handling by ensuring timely responses to new threat indicators and their integration into detection tools.
  • Lead proactive threat hunting efforts within the SOC to identify potential threats before they materialize.
  • Stay updated on emerging threat landscapes and ensure response strategies adapt to new vulnerabilities and attack vectors.

Leadership & Operational Support:

  • Act as a key partner to the Head of Cyber Defence, supporting strategic initiatives and taking on operational leadership when required.
  • Serve as the primary escalation point for complex incidents and operational challenges, including weekend support for critical systems (e.g., firewalls).
  • Provide mentorship and guidance to SOC analysts and incident responders, ensuring continuous skill development within the team.
  • Collaborate with IT, legal, compliance, and business units to align security response efforts with operational priorities.

 Continuous Improvement & Future 2IC Potential:

  • Partner with the Head of Cyber Defence to assess and refine incident response processes and SOC operations continuously.
  • Identify areas for optimization and automation within incident response workflows.
  • Take on additional leadership responsibilities to develop into a second-in-command (2IC) role over time, supporting the head of function in strategic and operational capacities.
  • Play an active role in the design and execution of defensive strategies to align with evolving threats and best practices.

About the team
Join Deloitte’s Cyber Defence team, a crucial part of our organisation, dedicated to protecting our diverse business portfolio and its 13,000 users. Our team operates in four core areas:

  • Cyber GRC (Govern and Support)
  • Cyber Assurance (Design & Deploy)
  • Cyber Operations (Operate & Maintain)
  • Cyber Defence (Protect & Defend)

Enough about us, let’s talk about you.
You are someone with:

Required:

  • 5+ years of experience in cybersecurity, with a focus on incident response, SOC and threat detection.
  • Proven experience in handling cyber incidents in complex enterprise environments, including managing escalations.
  • Strong operational background in SOC including familiarity with SIEM platforms and response tools.
  • Expertise in incident response frameworks (e.g., NIST, MITRE ATT&CK, Cyber Kill Chain).
  • Experience with SIEM platforms (e.g., Splunk, ArcSight, QRadar) and optimizing detection rules.
  • Strong knowledge of IDS/IPS, IOCs, and proactive threat hunting methodologies.
  • Familiarity with cloud security monitoring (AWS, Azure, GCP) is a plus.

Preferred:

  • GIAC Certified Incident Handler (GCIH) 
  • GIAC Security Operations Certified (GSOC) 

Why Deloitte? 

At Deloitte, we focus our energy on interesting and impactful work. We’re always learning, innovating and setting the standard; making a positive difference to our clients and our society. We put coaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.  

We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone’s perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong. 

We prioritise flexibility and choice. At Deloitte, you get trust on Day 1. We know our people get their best work done when they’re in control of where and how they work, designing their work week around their client, team and personal commitments.

We help you live and work well. To support your personal and professional life, we offer a range of perks and benefits, including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.

Next Steps 
Sound like the sort of role for you? Apply now. 

By applying for this job, you’ll be assessed against the Deloitte Talent Standards. We’ve designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.



  • Melbourne, Victoria, Australia KPMG Full time

    At KPMG, we are seeking a talented Cyber Defence Specialist to join our team. The successful candidate will be responsible for supporting our cyber defence and initial incident response activities for KPMG Australia, Fiji, and Papua New Guinea.This role will play a key part of our Security Operations team, using data and logs, and cyber defence tools to...


  • Melbourne, Australia AGL Energy Full time

    Powering Australian Life. At AGL, we believe energy makes life better. That’s why we’re passionate about powering the way Australians live, work and move. Like you, we believe that the world is going through extraordinary challenges. We don’t shy away from the tough questions and we consider the answers carefully. We work in partnership with our...


  • Melbourne, Australia nbn™ Full time

    Job Expectations An exciting opportunity has presented itself at nbn as an Incident Response Manager reporting to the Senior Manager CSOC. A bit about your role The Incident Response Manager will play a pivotal leadership role in nbn’s Cybersecurity Practice. You will oversee the delivery of efficient and effective cyber-incident containment with a...


  • Melbourne, Australia Melbourne Water Full time

    **Job Number**: 979121 **Work type**: Permanent Full Time **Location**: Melbourne - Docklands **Categories**: Information Technology **Who we are**: In Melbourne, water is essential to our way of life. As caretakers for Melbourne’s water cycle, we care for water, life and land throughout Melbourne: both its people and its biodiversity. Each time you...


  • Melbourne, Australia Defence Bank Full time

    **Introduction**: About us. A unique life requires a unique bank. Defence Bank is a member-owned bank that has been proudly serving the Defence Community for 49 years. With 26 branches across Australia and our award-winning app, Defence Bank is where our members need us - anywhere, anytime. The bank provides financial products and services to the Australian...


  • Melbourne, Australia Triskele Labs Full time

    Triskele Labs are one of the leading providers of cybersecurity services in Australia. We assist clients to navigate the uncertainty of cyber incident response in order to ensure the safe recovery of their business. Triskele Labs’ Digital Forensics and Incident Response (DFIR) team works across Australia / New Zealand to respond to ransomware, data...


  • Melbourne, Australia Triskele Labs Full time

    Triskele Labs are one of the leading providers of cybersecurity services in Australia. We assist clients to navigate the uncertainty of cyber incident response in order to ensure the safe recovery of their business.  Triskele Labs’ Digital Forensics and Incident Response (DFIR) team works across Australia / New Zealand to respond to ransomware, data...

  • Cyber Defence Tl

    6 months ago


    Melbourne, Australia Cenitex Full time

    Location: Melbourne | Parkville Job type: Full time Organisation: Cenitex **Salary**: $151,260 - $173,138 Occupation: IT and Telecommunications Reference: 6EB6K **Join Our Team as a Team Lead - Cyber Defence** Are you a dedicated and passionate professional looking to lead in the dynamic field of Cyber Defence? At Cenitex, we're not just an...


  • Melbourne, Australia Bupa Full time

    At Bupa, you’ll find an inclusive environment where you can be yourself and where everyone is driven by the same purpose - helping people live longer, healthier, happier lives and making a better world. The primary goal of this role is to support and accelerate progress towards shifting Left our Cyber Defences through implementing automations to enhance...

  • Cyber Security Trainer

    6 months ago


    Melbourne, Australia Edith Cowan University Full time

    Competitive Renumeration Casual position, Melbourne location Cyber Security Trainer Edith Cowan University (ECU) Melbourne Information & Communication Technology Security Competitive remuneration About us Edith Cowan University is recognised as a leader in cyber security research & education. In 2017 ECU was recognised by the Australian Federal Government...


  • Melbourne, Victoria, Australia Splunk Inc Full time

    Splunk Inc is a leading technology company that offers innovative solutions to make machine data accessible, usable and valuable to everyone.About the RoleWe are seeking an experienced Senior Advanced Response Analyst to join our Advanced Response Team (ART). The ideal candidate will have a strong background in IT or IT Security, with at least 5 years of...


  • Melbourne, Victoria, Australia Asahi Beverages Full time

    About Asahi BeveragesWe are a leading beverage company with a strong commitment to innovation and customer satisfaction.Job DescriptionAs Cyber Security Specialist - Incident Response Expert, you will be responsible for actively monitoring security alerts and managing day-to-day incident response activities. You will conduct thorough analyses of security...


  • Melbourne, Victoria, Australia Commonwealth Bank Full time

    Cloud Security Incident Response ManagerThis is an exceptional opportunity to join the Commonwealth Bank as a Cloud Security Incident Response Manager, where you will lead solutions, services, and project initiatives across Azure.About the RoleIn this key role, you will be responsible for managing, mentoring, and developing a team of cybersecurity analysts,...


  • Melbourne, Australia Department of Education Full time

    Location: Melbourne | CBD Job type: Full time Organisation: Department of Education **Salary**: $76,817 - $93,275 Occupation: IT and Telecommunications Reference: VG/DE/FPIS/1834872 **About the Department** The role of the Department of Education is to support Victorians to build prosperous, socially engaged, happy and healthy lives. It does this by...


  • Melbourne, Australia Department of Transport and Planning Full time

    Location: Melbourne | Parkville Job type: Ongoing - Full Time Organisation: Department of Transport and Planning **Salary**: $77,594 - $94,405 Occupation: Emergency Management Reference: 6126 **About the Role** **MULTIPLE OPPORTUNITIES AVAILABLE** The Incident Response Services team provides on road, effective management at transport incidents,...


  • Melbourne, Victoria, Australia Ntt Full time

    About the RoleNTT DATA is seeking a seasoned Cyber Security Operations Manager to lead our Melbourne/Sydney team in delivering exceptional managed security services. As a key member of our operations team, you will be responsible for driving service delivery excellence, ensuring client satisfaction, and fostering a culture of innovation and continuous...


  • Melbourne, Victoria, Australia Rapid7 Full time

    Incident Response Services at Rapid7Rapid7's Detection & Response Services team is committed to helping organizations improve their ability to detect and respond to security threats. As a Cybersecurity Incident Response Specialist, you will play a critical role in supporting our customers during times of crisis.About the RoleIn this position, you will lead...


  • Melbourne, Victoria, Australia Northbridge Recruitment Full time

    Cyber Security Architecture RoleThis is a highly influential Enterprise Cyber Security role, operating across the entire business. As a Lead Cyber Security Architect, you will be responsible for delivering tools and managing ecosystems to uplift Cyber Security Capability for the organization.You will be the go-to person for anything Cyber Security related,...


  • Melbourne, Victoria, Australia Rapid7 Full time

    As a key member of Rapid7's Detection & Response Services team, you will play a vital role in helping organizations respond to and mitigate cyber threats.About the TeamRapid7's team offers the opportunity to work on real-world incident response cases, uncovering previously unidentified breaches and simulating full-scale incidents with clients. Our Incident...

  • Cybersecurity Expert

    2 weeks ago


    Melbourne, Victoria, Australia Ayan Infotech Full time

    Ayan InfoTech is seeking a seasoned Cybersecurity Expert to join their team as an Incident Response Specialist in Melbourne. This exciting opportunity offers the chance to contribute to a well-structured and mature environment, working on sophisticated projects.Key Responsibilities:Implement incident response methodologies and techniquesDetect and mitigate...