Role Type
Description
🏛️ NDIA (Federal Government) — via WattleCore Technologies
📍 Location: ACT, VIC
⏳ Duration: 18 months
🏢 Work Type: Hybrid (3 days/week onsite)
🎓 Level: Lead — EL1 equivalent
🔐 Clearance: Must be able to obtain NV1 on commencement 🇦🇺 Australian Citizens only
Summary:
We are seeking a Cyber Operations Security Expert as below
- Role/s: EL1 Cyber Operations Security Expert
- The Cyber Operations Security Expert, will undertake technical cyber security activities under
- the leadership of the Director of Cyber Security Operations. The Cyber Operations Security
- Expert,must possess and demonstrate technical competency in areas of cloud security
- (Azure/AWS), endpoint and network security, threat intelligence and hunting, data loss
- prevention, vulnerability management, and incident response. The Cyber Operations Security
- Expert,will be required to support and contribute to the protection of the Agency’s systems,
- users, and data, to support NDIA’s objectives to “build a world-leading National Disability
- Insurance Scheme”.
- As part of the Cyber Security Operations team, the role will help ensure that NDIA has the
- capability to build and protect cyber-resilient information technology platforms and support
- strategic objectives.
Responsibilities:
The role will involve the key responsibilities:
- Lead proactive monitoring, investigation, and mitigation of security incidents within security
- tools (including Sentinel, Microsoft Defender 365 stack, Azure Security Centre, Splunk )
- Analyse security event data and identifying suspicious/malicious activity from networks and systems
- Lead incident response activities including initial and detailed investigation, computer forensics, chain of custody implications
- Respond to events and incidents using established Standard Operating Procedures (SOPs)
- Be a point of escalation for complex incidents and act as a subject matter expert in areas of cloud security, active defence, and threat mitigation
- Develop and manage phishing simulations
- Research new and evolving threats and vulnerabilities to the Agency’s threat landscape
- Conduct log analysis and develop visualisation and reporting within Splunk
- Identify critical data sources required by cyber for ingestion and normalisation into the SIEMs
- Collaborate with Security Operations and IT engineers to implement security controls
- Supervise, mentor and develop junior staff, and identify areas of people, process, and defensive tool improvement
- Produce and disseminate incident response reports, activity reports, and intelligence and threat briefs
Qualifications:
- Demonstrated familiarity with log aggregation and Security Incident and Event Management (SIEM) systems
- Knowledge of the Information Security Manual (ISM) and cyber security concepts.
- Demonstrated experience implementing and using Incident Response Frameworks (NIST SP 800-61 Incident Handling Guide, Mitre Frameworks)
- Formal tertiary qualifications or industry certifications in a cyber security related field (e.g.Azure/AWS, Splunk Certified)
Australia
New Zealand
United Kingdom
Canada
Singapore
Malaysia





