Information Security Analyst

North Sydney, New South Wales 2060, Australia • Full-time
AI Job Summary
  • Experience in information security operations/cyber risk/IT security, including triaging alerts/events and coordinating.
  • Practical experience managing vulnerabilities from identification through remediation, residual risk review, and escal.
  • Experience investigating DLP incidents/alerts and supporting improvements to DLP and information classification controls

Role Type

Permanent • Full-time • Associate

Description

Excite Cyber is looking for an Information Security Analyst to join our Cybersecurity team in a unique hybrid role, working across both a key customer environment and Excite Cyber.

This is a hands-on opportunity for someone who enjoys the operational side of cybersecurity while also building experience across risk, governance, vulnerability management and client delivery.

The role will typically involve three days per week working within the customer environment and two days per week with Excite Cyber, giving you exposure to different security environments, technologies and stakeholders.

About the role

As an Information Security Analyst, you’ll help keep security risks, incidents, vulnerabilities and technology lifecycle issues visible and moving towards resolution.

You’ll work closely with IT teams, business stakeholders, vendors and cybersecurity specialists to investigate security matters, coordinate remediation activities, maintain accurate security records and translate technical findings into practical business actions.

Your responsibilities will include:

  • Triage security enquiries, alerts and events and coordinate investigation, response and escalation.
  • Monitor and manage vulnerabilities from identification through to remediation, residual risk review and escalation.
  • Review vulnerability intelligence, security scans, penetration testing findings and vendor advisories.
  • Investigate data loss prevention (DLP) incidents and alerts and support the ongoing improvement of DLP and information classification controls.
  • Support security monitoring and tooling across areas such as email security, audit monitoring and threat intelligence.
  • Maintain vulnerability, asset and security risk registers with accurate ownership, status and supporting evidence.
  • Monitor technology assets for end-of-support and lifecycle risks and coordinate action with relevant stakeholders.
  • Prepare clear security reporting for operational and executive audiences.
  • Support Excite Cyber’s internal security activities and contribute to client cybersecurity engagements.
  • Identify opportunities to improve security processes, control coverage, reporting and operational efficiency.

About you

You’ll be comfortable working across both technical and business-facing security activities and able to take ownership of actions through to completion.

We’re looking for someone with:

  • Experience in information security operations, cyber risk, IT security or a related role.
  • Practical experience reviewing security alerts, vulnerabilities, scan results or security control evidence.
  • Working knowledge of vulnerability management, DLP, information classification, security monitoring and technology lifecycle risk.
  • Strong analytical and problem-solving skills.
  • Excellent attention to detail and the ability to maintain accurate, traceable records.
  • Strong written and verbal communication skills, with the ability to explain technical findings to both technical and non-technical stakeholders.
  • The ability to manage competing priorities and work effectively across different teams and environments.
  • A proactive approach to identifying risks, following up on actions, and improving security processes.

Desirable experience

Experience with any of the following platforms would be highly regarded:

  • Forcepoint
  • Netwrix Auditor
  • Proofpoint
  • Recorded Future
  • BitSight
  • Qualys
  • Microsoft security technologies or comparable cybersecurity platforms

Exposure to cybersecurity governance, assurance, compliance, consulting or managed security services would also be advantageous.

Relevant tertiary qualifications or industry certifications such as Security+, SSCP, GSEC or ISO 27001 Foundation/Practitioner are desirable but not essential.

Why join Excite Cyber?

This role offers the opportunity to work across both an embedded customer environment and Excite Cyber’s broader cybersecurity practice, giving you exposure to a diverse range of security challenges and stakeholders.

You’ll have the opportunity to develop your capability across security operations, vulnerability management, data protection, cyber risk, governance and client delivery, while contributing to practical improvements that strengthen security outcomes.

If you’re looking for a hands-on cybersecurity role where you can take ownership, broaden your experience and work across both operational and advisory security activities, we’d love to hear from you.