Cyber Operations Security Expert

Melbourne, Victoria 3000, Australia • Full-time

Role Type

Anywhere • Permanent • Full-time • Entry Level

Description

🏛️ NDIA (Federal Government) — via WattleCore Technologies

 

📍 Location: ACT, VIC

 

⏳ Duration: 18 months

 

🏢 Work Type: Hybrid (3 days/week onsite)

 

🎓 Level: Lead — EL1 equivalent

 

🔐 Clearance: Must be able to obtain NV1 on commencement 🇦🇺 Australian Citizens only

Summary:

We are seeking a Cyber Operations Security Expert as below

  • Role/s: EL1 Cyber Operations Security Expert
  • The Cyber Operations Security Expert, will undertake technical cyber security activities under
  • the leadership of the Director of Cyber Security Operations. The Cyber Operations Security
  • Expert,must possess and demonstrate technical competency in areas of cloud security
  • (Azure/AWS), endpoint and network security, threat intelligence and hunting, data loss
  • prevention, vulnerability management, and incident response. The Cyber Operations Security
  • Expert,will be required to support and contribute to the protection of the Agency’s systems,
  • users, and data, to support NDIA’s objectives to “build a world-leading National Disability
  • Insurance Scheme”.
  • As part of the Cyber Security Operations team, the role will help ensure that NDIA has the
  • capability to build and protect cyber-resilient information technology platforms and support
  • strategic objectives.

Responsibilities:

The role will involve the key responsibilities:

  • Lead proactive monitoring, investigation, and mitigation of security incidents within security
  • tools (including Sentinel, Microsoft Defender 365 stack, Azure Security Centre, Splunk )
  • Analyse security event data and identifying suspicious/malicious activity from networks and systems
  • Lead incident response activities including initial and detailed investigation, computer forensics, chain of custody implications
  • Respond to events and incidents using established Standard Operating Procedures (SOPs)
  • Be a point of escalation for complex incidents and act as a subject matter expert in areas of cloud security, active defence, and threat mitigation
  • Develop and manage phishing simulations
  • Research new and evolving threats and vulnerabilities to the Agency’s threat landscape
  • Conduct log analysis and develop visualisation and reporting within Splunk
  • Identify critical data sources required by cyber for ingestion and normalisation into the SIEMs
  • Collaborate with Security Operations and IT engineers to implement security controls
  • Supervise, mentor and develop junior staff, and identify areas of people, process, and defensive tool improvement
  • Produce and disseminate incident response reports, activity reports, and intelligence and threat briefs

Qualifications:

  • Demonstrated familiarity with log aggregation and Security Incident and Event Management (SIEM) systems
  • Knowledge of the Information Security Manual (ISM) and cyber security concepts.
  • Demonstrated experience implementing and using Incident Response Frameworks (NIST SP 800-61 Incident Handling Guide, Mitre Frameworks)
  • Formal tertiary qualifications or industry certifications in a cyber security related field (e.g.Azure/AWS, Splunk Certified)