Cyber Security Analyst

Lifeline Australia

Sydney

On-site

AUD 120,000 - 180,000

Full time

15 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Salary Packaging and not-for-profit*/
Paid Parental Leave – 14 weeks
Flexible working
Employee Assistance Program
Office facilities

Job summary

Lifeline Australia is seeking a practical Cyber Security Analyst to join our Sydney team for a 12-month contract. You will secure enterprise environments, deliver tangible security outcomes, and support ISO 27001:2022 and Essential Eight uplift.

You will assess risks, implement controls, onboard Shadow IT, and work with vendors to remediate issues, driving governance across the organisation.

Qualifications

  • Minimum 5 years' hands-on cyber security experience in security analyst or security consultant roles.
  • Demonstrated experience conducting security assessments and risk reviews.
  • Proven experience implementing security improvements, not just reports.
  • Strong knowledge of ISO/IEC 27001:2022 and practical controls implementation.
  • Experience with ACSC Essential Eight framework.

Responsibilities

  • Conduct security assessments of business applications, cloud platforms, SaaS solutions and third-party suppliers.
  • Identify security risks, control gaps, and remediation actions.
  • Establish and test cyber incident response procedures including tabletop exercises.
  • Lead onboarding of Shadow IT and business-managed systems into formal governance.
  • Review new technologies for compliance with security requirements.
  • Support ISMS maintenance and ISO 27001:2022 audits and compliance.
  • Support Essential Eight uplift initiatives and remediation.
  • Contribute to security awareness and education programs.
  • Prepare risk assessments and security reports for management.

Skills

Security assessments
Risk reviews
ISO 27001:2022
ACSC Essential Eight
Shadow IT onboarding
Vendor engagement
Security controls
Audits & compliance
Incident response
Independent work

Tools

Microsoft Defender
Microsoft Sentinel
Vulnerability management
Cloud security tools
Salesforce reviews

Job description

ORGANISATION

Join Lifeline Australia and you will be helping to support the delivery of critical services ensuring that “no person in Australia has to face their darkest moments alone.”

Lifeline Australia is a national suicide prevention charity providing all Australians experiencing emotional distress with access to 24-hour crisis support and suicide prevention services. They are committed to empowering Australians to be suicide-safe through connection, compassion and hope. This is achieved through a partnership of over 10,000 committed volunteers and their member centres in communities across the nation. Lifeline Australia Ltd (LLA) is located in Sydney, with small teams of dedicated staff employed to lead funding and corporate relations activities, and to provide the design, technical infrastructure and governance of services across Lifeline’s member network. LLA recently embarked on an exciting transformation journey, guided by an ambitious strategic plan. The 2024-2027 Strategic Plan will see enhancements across services, technology and workforce to bring about better outcomes and a more accessible and flexible support system for help-seekers.

THE ROLE

We are seeking a practical, hands-on Cyber Security Analyst who has real-world experience securing enterprise environments and delivering cybersecurity outcomes. This is not a governance-only or policy-writing role. We are looking for someone who has personally assessed systems, identified risks, implemented controls, worked with vendors, and driven remediation activities. The successful candidate will support the Cybersecurity Uplift Program, improve alignment with ISO 27001:2022, increase Essential Eight maturity, and bring business-managed and Shadow IT platforms into formal security governance.

This role suits someone who enjoys rolling up their sleeves and getting things done. We are not looking for a compliance-only resource. We want someone who can assess, advise, implement, and deliver tangible security outcomes for the organisation.

This is a 12-month contract, working full-time hours.

Responsibilities
  • Conduct security assessments of business applications, cloud platforms, SaaS solutions, and third-party suppliers.
  • Identify security risks, control gaps, and remediation actions across technology platforms.
  • Establish, maintain, and test cyber incident response procedures through tabletop exercises, simulations, and post-incident reviews to improve organisational preparedness and response capability.
  • Lead the onboarding of Shadow IT and business-managed systems into formal security governance and support processes.
  • Review new technology solutions and integrations to ensure compliance with organisational security requirements.
  • Support the maintenance and continual improvement of the Information Security Management System (ISMS).
  • Gather and maintain evidence required for ISO 27001:2022 audits and compliance activities.
  • Support Essential Eight uplift initiatives and remediation activities.
  • Contribute to security awareness and education programs.
  • Prepare risk assessments, security reports, and recommendations for management.
About You
Essential Skills and Experience
  • Minimum 5 years' experience in a Cyber Security Analyst, Security Consultant, or similar hands‑on security role.
  • Demonstrated experience conducting security assessments and risk reviews.
  • Proven experience implementing security improvements, not just producing reports and recommendations.
  • Strong knowledge of ISO/IEC 27001:2022 and practical experience implementing and maintaining security controls.
  • Experience working with the Australian Cyber Security Centre (ACSC) Essential Eight framework.
  • Experience assessing and onboarding Shadow IT, SaaS platforms, and business‑managed applications into formal governance processes.
  • Experience conducting supplier security assessments and third‑party risk reviews.
  • Experience supporting audit and compliance activities.
  • Strong stakeholder engagement and communication skills.
  • Ability to work independently and drive outcomes with minimal supervision.
Desirable Experience
  • Experience within a not‑for‑profit, healthcare, or regulated environment.
  • Experience with Microsoft Defender, Microsoft Sentinel, vulnerability management platforms, and security monitoring tools.
  • Experience reviewing Salesforce, cloud‑hosted platforms, integrations, and externally managed applications.
  • Knowledge of privacy legislation, data protection requirements, and supplier assurance frameworks.
  • Experience supporting ISO 27001 audits or certification activities.
Personal Attributes
  • Hands‑on and action‑oriented.
  • Comfortable challenging vendors and stakeholders when security risks are identified.
  • Strong problem‑solving and analytical skills.
  • Pragmatic approach to balancing risk and business requirements.
  • Curious, proactive, and continuously looking for improvement opportunities.
  • Able to build strong working relationships across the organisation.
What Success Looks Like
  • Complete security assessments across key business and technology platforms.
  • Establish and test cyber incident response procedures through exercises and simulations.
  • Successfully onboard Shadow IT platforms into formal governance and support processes.
  • Support and improve compliance with ISO 27001:2022 requirements.
  • Improve Essential Eight maturity across the organisation.
  • Strengthen supplier security assurance processes.
  • Reduce identified cybersecurity risks through practical remediation and control improvements.
  • Contribute to a stronger, more resilient security posture across the organisation.
CULTURE

The team are passionate, supportive and hardworking. They are very driven to reach their goals, so that they can continue to grow and deliver critical support to all Australians at a time when the importance of mental health has never been so prevalent.

Employee Benefits Package
  • Salary Packaging – being a not-for-profit organisation allows us to offer our employees access to some amazing tax savings through salary packaging
  • Paid Primary Carer Parental Leave – (14 weeks at full pay or 28 weeks at half pay)
  • Flexible working – we provide flexibility and support to all employees and encourage work‑life balance
  • Employee Assistance Program – access to free counselling sessions for you and your family
  • Beautiful office facilities in central location – including shower facilities (Head Office roles only, delete if not required)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Business Analyst (CyberSec)
Technical Business Analyst (CyberSec)

tekFinder • Sydney

Hybrid
AUD 95,755 - 125,644
Flexible day rate
Hybrid working arrangement
Opportunity to make real impact
Cyber Security SOC Analyst
Cyber Security SOC Analyst

C4i Solutions • Sydney

On-site
AUD 90,000 - 120,000
Long Service Leave
Health & wellbeing allowance
First year leave (5 days)
+6
Cyber Security Analyst
Cyber Security Analyst

Fitness Passport • City of Melbourne

Hybrid
AUD 90,000 - 130,000
Hybrid & flexible work
Paid parental leave
Mental health support
+3
Senior Service Delivery Manager
Senior Service Delivery Manager

CyberCX • Australia

Hybrid
AUD 140,000 - 190,000
Health & Wellbeing program
Discounts on health insurance and gym
Development planning
+1
Cyber Security Assessor
Cyber Security Assessor

C4i Solutions • Sydney

On-site
AUD 120,000 - 150,000
Long Service Leave
Health & wellbeing allowance
First year leave
+6
Cyber Security Analyst — Hands-On, ISO 27001 Focus
Cyber Security Analyst — Hands-On, ISO 27001 Focus

Lifeline Australia • Sydney

On-site
AUD 120,000 - 180,000
Salary Packaging and not-for-profit*/
Paid Parental Leave – 14 weeks
Flexible working
+2
Cyber Risk Analyst
Cyber Risk Analyst

Anglicare Sydney • Sydney

On-site
AUD 110,000 - 150,000
Flexible work options
Salary packaging benefits
Professional development
+2
AWS Cloud Consultant
AWS Cloud Consultant

CyberCX • Australia

Hybrid
AUD 100,000 - 150,000
Flexible hybrid work
Health & wellbeing program
Salary packaging options
+1
Cyber Engineer
Cyber Engineer

e2 Cyber • Brindabella

On-site
AUD 80,000 - 120,000
Cyber Security SOC Analyst
Cyber Security SOC Analyst

C4I Solutions Pty • Sydney

On-site
AUD 110,000 - 160,000
Long Service Leave
Health & wellbeing allowance
First year leave (5 days)
+6