Cyber Security Operations Analyst L5 - L6
In this dynamic position, you will monitor, detect, and respond to malicious cyber activity, working to protect the confidentiality, integrity, and availability of our systems and sensitive data. From analysing log data through Security Information and Event Management (SIEM) platforms to conducting proactive threat hunting, your work will directly impact our ability to identify, contain, and eradicate threats to ASIS.
Role responsibilities
- Monitor, detect, and respond to malicious cyber activity targeting ASIS's ICT environment to protect the confidentiality, integrity, and availability of systems and data
- Analyse log data from applications, hosts, and network traffic using SIEM software and conduct proactive cyber threat hunting activities
- Prepare for and manage cyber incident response activities, working to quickly identify, contain, and eradicate threats
- Develop dashboards, use cases, and threat detection capabilities to improve cyber security, and proactively identify and remediate capability and coverage gaps across the ICT environment
- Leverage advanced technologies, intelligence analysis, and data holdings to provide actionable insights and support other business areas
- Mentor and coach team members on cyber security operations best practices
Core skills
We encourage applicants with the following skills and attributes to apply:
- Familiarity with risk management, incident response, and investigative best practices, including experience in security analytics and developing reporting for various customers.
- Demonstrated understanding of Australian Government cyber security frameworks, including the Protective Security Policy Framework (PSPF) and Information Security Manual (ISM).
- Strong background in cyber security capabilities and tools, including SIEM, data analytics platforms, and query/coding languages such as SQL, SPL, Python, and PowerShell.
- Demonstrated understanding of at least one technology domain, such as infrastructure, virtualisation, databases, software development, data analytics or machine learning.
- Proven ability to work under limited direction with reasonable autonomy, demonstrating initiative, judgment, and strategic thinking to solve complex problems and manage workflows.
- Excellent communication and stakeholder engagement skills, with the ability to provide detailed technical and policy advice, articulate cyber best practices, and manage sensitive issues.
Education and qualification requirements
The following education, qualifications and/or experience will be highly regarded:
- Proven experience in cyber security operations, including monitoring, detecting, and responding to malicious cyber activity
- Proficiency in Security Information and Event Management (SIEM) software, data analytics platforms, and query/coding languages (e.g., SPL, SQL, Python, PowerShell) is highly desirable
- Previous incident response experience, such as digital forensics, malware analysis and incident investigations will be highly valued
- Professional certifications along with demonstrated application of knowledge will be highly regarded
- Bachelor's degree in Cyber Security, Computer Science, or Information Technology (not essential)
- 3+ years of experience in a cyber security operations or analyst role, preferably within an enterprise or government environment
To be eligible for a role you must:
- Be an Australian citizen
- Be assessed as suitable to hold and maintain a TOP SECRET-Privileged Access security clearance
- For more information on eligibility please see the Protective Security Policy Framework which is publicly accessible at protectivesecurity.gov.au, section 12 provides information on Eligibility and suitability