Cyber Security Analyst

Thales

Sydney

Hybrid

AUD 90,000 - 140,000

Full time

44 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

ThalesFlex – Hybrid work environment
Fitness Passport
Employee discounts
Parental Leave
Novated Lease
Training & development
Wellbeing & Support

Job summary

Thales Australia is seeking a Cyber Security Analyst to protect our systems, networks and data. You will operate in the Security Operations Centre (SOC), monitoring, investigating and responding to cyber threats across enterprise, cloud and identity environments.

You’ll work with IT teams to detect, contain and recover from incidents, tune alerts and develop automated workflows. The role requires hands-on experience with Microsoft Sentinel, Defender suites and SIEM tools, plus knowledge of MITRE

Qualifications

  • Experience in a Security Operations Centre (SOC) or similar cyber security environment.
  • Hands-on with Microsoft Sentinel for monitoring, investigations, hunting, alert tuning, and dashboards.
  • Strong knowledge of Defender technologies including Defender for Endpoint, Defender for Identity, Defender for Cloud, Defender for Office 365.
  • Experience with Microsoft Purview for data security, insider risk, or compliance investigations.
  • Knowledge of MITRE ATT&CK and threat detection methodologies.
  • Experience with SIEM and log analytics across endpoint, identity, network, cloud, and email environments.
  • Experience investigating endpoint-based security incidents using EDR/XDR technologies.
  • IAM concepts including privileged access, account compromise, and lateral movement.

Responsibilities

  • Monitor, triage, and investigate security alerts across enterprise, cloud, identity, endpoint, and data environments.
  • Identify, analyse, and respond to cyber security incidents in line with policy.
  • Conduct threat hunting and investigative activities to identify anomalous or malicious behaviour.
  • Support containment, remediation, and recovery activities with IT and business stakeholders.
  • Operate and support SOC tooling including SIEM, EDR/XDR, monitoring and incident response technologies.
  • Develop automated investigation and response workflows.
  • Investigate identity-related security events and support data protection investigations.
  • Improve detection through alert tuning and new telemetry sources.
  • Produce clear incident documentation for technical and non-technical stakeholders.

Skills

SOC experience
Threat detection
Analytical thinking
Team collaboration

Tools

Microsoft Sentinel
Defender for Endpoint
Defender for Identity
Defender for Cloud
Defender for Office 365
Microsoft Purview
SIEM
EDR/XDR

Job description

At Thales, we know technology has the ability to make our world more secure, sustainable, and inclusive – and that it’s all driven by human intelligence.

Because it takes human intelligence to build and power the systems and solutions that people depend on every day. So we stay curious and make space for diverse points of view. We share what we know and we challenge what’s possible.

From manufacturing and engineering to cybersecurity and space, we’re driving progress in some of the world’s most important industries – and working together to build a future we can all trust.

Our Benefits
  • Competitive remuneration (Insert WAGE EA) + Super + Profit Share
  • ThalesFlex – Hybrid work environment
  • Fitness Passport Discount – Access to a network of Gyms across AUS as cheap as $14.95 P/W
  • Employee discounts with a number of affiliates (Travel, Car hire, Tech, Medical Insurance)
  • Modernised Paid Parental Leave
  • Veterans Leave
  • Novated Lease options
  • Personal & professional training development opportunities
  • Sonder – Wellbeing & Support Partner
The Team

This role is part of our corporate team, a central hub for Thales Australia. It’s where our shared services – think finance, legal, HR, procurement – come together to make sure all teams across Australia have access to the business services they need. Cross-functional collaboration helps us build out Thales’ capabilities – and helps us open up new career opportunities for employees all across the business.

Your Role

As a Cyber Security Analyst, you will play a key role in protecting Thales Australia’s systems, networks, data, and users through proactive monitoring, investigation, and response to cyber security threats. Operating within the Security Operations Centre (SOC), you will contribute to the ongoing enhancement of detection, monitoring, incident response, and cyber resilience capabilities across enterprise, cloud, identity, endpoint, and data environments.

You will work closely with internal IT teams and stakeholders to identify, investigate, and respond to cyber security incidents while continuously improving detection capabilities and operational effectiveness across the security landscape.

  • Monitor, triage, and investigate security alerts across enterprise, cloud, identity, endpoint, and data environments
  • Identify, analyse, and respond to cyber security incidents in line with established policies and procedures
  • Conduct threat hunting and investigative activities to identify anomalous or malicious behaviour
  • Support containment, remediation, and recovery activities alongside IT and business stakeholders
  • Operate and support SOC tooling including SIEM, EDR/XDR, monitoring, and incident response technologies
  • Contribute to the development and optimisation of automated investigation and response workflows
  • Investigate identity-related security events including account compromise, privilege misuse, and unauthorised accessSupport data protection and compliance-driven investigations using security and governance tooling
  • Improve detection effectiveness through alert tuning, use-case refinement, and onboarding of new telemetry sources
  • Produce clear and accurate incident documentation and communicate findings to both technical and non-technical stakeholders
Your Experience
  • Experience working within a Security Operations Centre (SOC) or similar operational cyber security environment
  • Hands-on experience with Microsoft Sentinel for monitoring, investigations, hunting, alert tuning, and dashboard development
  • Strong knowledge of Microsoft Defender technologies including Defender for Endpoint, Defender for Identity, Defender for Cloud, and Defender for Office 365
  • Experience leveraging Microsoft Purview for data security, insider risk, or compliance-related investigations
  • Strong understanding of threat detection and response methodologies, including MITRE ATT&CK
  • Experience with SIEM and log analytics platforms across endpoint, identity, network, cloud, and email environments
  • Experience investigating endpoint-based security incidents using EDR/XDR technologies
  • Practical understanding of IAM concepts including privileged access, account compromise, and lateral movement scenarios
  • Strong analytical, investigative, and problem-solving capability with high attention to detail
  • Ability to work collaboratively within a geographically dispersed SOC environment

A Defence security clearance is required for this role, applicants must be Australian citizens and eligible to obtain and maintain an appropriate clearance.

Additional information with regards to clearances is available from the Australian Government Security Vetting Agency website http://www.defence.gov.au/AGSVA/. In some cases, individuals who hold a current clearance from a foreign government may be eligible to have this clearance recognised by the Australian Government and be eligible for this role. The Australian Defence Trade Controls Act (DTCA) is applicable and as such, your nationality may be a factor in determining your suitability for this role.

It’s easy to dismiss the perfect opportunity if you don’t see yourself as the perfect fit. If this role feels right – no matter your background or personal circumstances – please introduce yourself or join our community. We’re committed to supporting a diverse workplace, and that starts here.

We’re proud to be endorsed by WORK180 as an Employer for All Women, but we know there’s always more we can do. We’ll continue to foster industry partnerships, employee resource groups (ERGs) and development opportunities to make Thales a genuinely equitable employer, for everyone.

Read more about our WORK180 endorsement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Service Delivery Manager
Service Delivery Manager

Thales • Sydney

On-site
AUD 120,000 - 150,000
Hybrid and flexible working options
Paid parental leave
Day off on your birthday
+3
Internal Controller
Internal Controller

Thales • City of Melbourne

Hybrid
AUD 100,000 - 150,000
Competitive remuneration
ThalesFlex – Hybrid work
Fitness Passport Discount
+6
Systems Administrator
Systems Administrator

Thales • City of Melbourne

Hybrid
AUD 90,000 - 130,000
Hybrid work environment
Profit sharing
Gym discount
+6
Senior Consultant – Offensive Security
Senior Consultant – Offensive Security

Thales • Council of the City of Sydney

Hybrid
AUD 140,000 - 200,000
Hybrid work options
Paid parental leave
Birthday day off
+2
Internal Controller
Internal Controller

Thales Group • City of Melbourne

On-site
AUD 120,000 - 160,000
Hybrid work environment
Fitness Passport Discount
Employee discounts with affiliates
+4
Managing Consultant Offensive Security
Managing Consultant Offensive Security

Thales • City of Melbourne

Hybrid
AUD 180,000 - 240,000
Hybrid work options
Birthday day off
Novated lease options
+3
Service Delivery Manager
Service Delivery Manager

Thales Group • Sydney

Hybrid
AUD 120,000 - 170,000
Competitive remuneration structure
Hybrid and flexible working Options
Paid parental leave and family support
+4
Client Executive - Federal Government
Client Executive - Federal Government

Thales • Canberra

On-site
AUD 140,000 - 200,000
Hybrid working options
Paid parental leave
Birthday leave
+4
Client Executive - Power Utilities North
Client Executive - Power Utilities North

Thales Group • Council of the City of Sydney

Hybrid
AUD 120,000 - 160,000
Hybrid work options
Paid parental leave
Birthday day off
+4
Client Executive - Government Cyber Workforce Solutions
Client Executive - Government Cyber Workforce Solutions

Thales Group • Canberra

Hybrid
AUD 90,000 - 130,000
Hybrid and flexible working options
Paid parental leave and family support
The day off on your birthday
+2