Information Security Analyst
$15,900–$15,900 year
HybridSydney, New South Wales, Australia or Melbourne, Victoria, Australia
Job Summary
Conduct threat monitoring, incident response, and root-cause investigations while tuning detection platforms and creating new detection content. Administer Level 3 support for key security defence platforms across cloud and on-premises environments, including SIEM, EDR, and email security tools. Collaborate with the Security Operations Centre and external partners to execute mitigating containment actions, support audit responses, and enhance security policies and architecture. Perform security risk assessments and vulnerability management, utilizing automation to streamline security tasks. This full-time hybrid role in Sydney or Melbourne requires a Bachelor's degree and 3+ years of hands-on cybersecurity experience.
Required Qualifications
- 3+ years of hands-on experience in cybersecurity operations, such as SOC, blue team operations, incident response, or digital forensics
- Demonstrated ability to triage alerts, conduct root-cause analysis, execute mitigating containment actions, and write clear, technical incident reports for technical teams and leadership
- Experience administering and supporting core security platforms (SIEM, EDR, Email Security, Secure Web Gateway) and collaborating with SOC teams to tune detection rules and eliminate false positives
- Practical knowledge of security risk assessments, vulnerability management, penetration testing coordination, and key standards/frameworks (such as ASD Essential Eight, ISO 27001, and PCI DSS)
- Experience using automation to streamline security tasks, alongside an understanding of secure infrastructure design (including IAM, network, storage, and configuration management)
- Bachelor's degree in Computer Science, Cyber Security, or a related field (or equivalent significant industry experience)
- Must be able to work in a hybrid model which includes two days on-site and three days from home
- Sydney or Melbourne location
Desired Qualifications
- Relevant industry certifications are highly regarded (e.g., Microsoft Security [SC-200/SC-100], CompTIA CySA+/Security+, BTL1, GIAC [GCIH/GCIA], ISO 27001 Implementer/Auditor, or progress towards CISSP/CISM)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.