Senior Cyber Security Analyst

Sydney CBD, New South Wales 2000, Australia • Full-time
AI Job Summary
  • Bachelor degree in cyber security/IT/CS or related, or equivalent qualifications and relevant experience.
  • At least five years in security operations/engineering/hybrid, with hands-on triage, investigation, and incident reps.
  • Deploy, tune, and operate a SIEM (Wazuh & OpenSearch preferred; Elastic OK; Sentinel/Splunk if true ingest/detection).

Role Type

On-site • Permanent • Full-time • Mid-level Senior

Description

Position Purpose

The Senior Cyber Security Analyst is Revio’s principal authority on security operations. The role performs daily triage and investigation across the multi-tenant client base, acts as lead investigator on client security incidents, and owns the architecture, build and operation of the security platform on which those investigations run. The scope is deliberately broad: there is no separation between the people who operate the security operations centre (SOC) and the people who build it, so the same specialist identifies a detection gap and engineers the fix. The role carries end-to-end ownership of a production multi-tenant security platform, with direct access to the Chief Executive Officer and to client executives.

Key Responsibilities

Reporting to the Chief Executive Officer, the Senior Cyber Security Analyst will be responsible for:

  • Perform daily multi-tenant alert triage, investigation and escalation across live client SOC tenants, analysing alerts and data from security products, web proxies, network security devices and vulnerability scanning and management systems, and operate a console duty rotation with out-of-hours availability for critical escalations.
  • Act as lead investigator on client security incidents, coordinating and investigating breaches to determine root cause, including full attack-chain reconstruction from multi-million-event log sets, cloud forensics covering control-plane audit trails, identity and access management abuse and secrets-manager compromise, and forensic assessment of attacker-supplied artefacts; direct containment, eradication and evidence preservation, and advise client executives on customer-notification sequencing and regulator engagement.
  • Own the architecture, build and operation of the multi-tenant SIEM and XDR platform (Wazuh and OpenSearch), including the multi-tenancy data plane covering document-level security, per-tenant role-based access control, tenant attribution in the ingest pipeline and index-family source routing, maintained entirely as code using Terraform with managed remote state, Ansible provisioning roles and a gated CI/CD pipeline with security scanning and idempotence checks, so that no live change remains uncodified.
  • Drive detection engineering and alert quality, covering noise-source analysis, deduplication and correlation, enrichment, risk-based alerting and dashboard-correctness validation, and conduct proactive threat hunts using frequency-analysis and stack-counting methodology, maintaining knowledge of the current threat landscape and producing formal findings reports.
  • Own the connector and integration estate and the endpoint agent control plane, including dual-credential failover, credential lifecycle and expiry management, integration health monitoring, signed cross-platform agent artefacts for Windows, macOS and Linux, two-tier remote upgrade with rollback, an out-of-band control channel over mutual TLS with signed allow-listed commands, package-signing certificate authority, key rotation and staged rollout with health gates.
  • Lead client SIEM onboarding programs end to end against a standardised template covering tenancy creation, endpoint agent deployment, log-source and syslog integration, single sign-on, perimeter scanning, dark-web and threat-intelligence feeds, high-value-target and file-integrity monitoring, and firewall and XDR integration, acting as the named technical contact for client IT managers, security leads and their third-party integrators and chairing integration governance meetings.
  • Own vulnerability and exposure management and the recurring client reporting cycle, including performing assessments on systems, networks and applications to identify and prioritise security risks, scheduled internal and external scanning, attack-surface discovery, patching service levels with automated enforcement, emergency CVE response, continuous ransomware exposure monitoring, and monthly exposure, missing-patch, detection overview, phishing simulation and cloud posture reports issued across all tenants within one to three days of month end.
  • Operate and evidence the technical controls underpinning Revio’s ISO/IEC 27001 and ISO/IEC 42001 certifications and its SOC 2-aligned control set, including vulnerability scanning cadence, encryption in transit and at rest, release approval and testing, backup recoverability, penetration testing and remediation service levels, quarterly access reviews, and administration of single sign-on, privileged and break-glass accounts, API key and certificate rotation and the internal certificate authority.
  • Own platform reliability and the supporting estate, covering disaster recovery design, resilience auditing, capacity and storage-growth management, backup and restore testing across SaaS platforms and infrastructure, and maintain the platform operations documentation, SOC operating procedures and analyst playbook library to a standard from which a technical reader with no prior context can deploy, operate and repair the platform; mentor junior and graduate analysts.

Skills, Knowledge and Experience

  • Essential: A bachelor degree or higher in cyber security, information technology, computer science or a related discipline; equivalent qualifications and relevant experience will be considered.
  • At least five years’ experience in security operations, security engineering or a hybrid role, including hands-on alert triage, investigation and incident response in a multi-client or multi-tenant environment.
  • Demonstrable SIEM engineering depth, meaning deploying, tuning and operating a SIEM rather than only using one. Wazuh and OpenSearch, or Elastic, are strongly preferred; Microsoft Sentinel or Splunk will be considered where the candidate has performed genuine ingest pipeline and detection engineering work.
  • Proven incident response capability, including reconstructing an attack chain from raw log data, reasoning about evidence gaps, and communicating findings to a non-technical executive audience.
  • Cloud security competence in Amazon Web Services, covering identity and access management and STS, key management and secrets management, logging and audit services, and network architecture, together with familiarity with Microsoft Azure and Entra ID.
  • Infrastructure as code and automation, covering Terraform and Ansible or close equivalents, CI/CD pipelines and Git-based workflow, together with Python and Bash to a standard that supports production automation, API integrations and data pipelines; the candidate must be genuinely comfortable that infrastructure changes are made through code rather than consoles.
  • Working knowledge of ISO/IEC 27001 and experience contributing to a certification or audit cycle, and demonstrated documentation discipline, meaning a verifiable habit of writing to a standard others can operate from.
  • Client-facing capability sufficient to run a technical meeting with a client’s IT manager, write a report an executive will read, and hold a position under pressure, together with excellent written communication, analytical and problem-solving skills.
  • Desirable: Relevant professional certification, such as GCIA, GCIH, OSCP, CISSP, AWS Certified Security – Specialty, SC-200 or AZ-500; experience in an MSSP or consultancy environment; detection engineering at scale; endpoint agent packaging, code signing and fleet management; Fortinet firewall and identity platform administration; ISO/IEC 42001 or AI governance exposure; or experience with self-hosted large language model or retrieval-augmented generation systems.