Cyber Security Operations Technical Lead
Join us as a Cyber Security Operations Technical Lead and play a pivotal role in safeguarding ASIS's global ICT environment. In this senior position, you will lead cyber incident response activities and technical investigations, driving efforts to quickly identify, contain, and eradicate threats to ASIS.
Key Duties
- Lead the monitoring, detection, and response to cyber activity impacting ASIS's ICT environment, ensuring the confidentiality, integrity, and availability of critical systems and data
- Lead technical investigations including analysis of security event logs, network traffic and system activity to identify, understand, respond and prevent cyber security incidents
- Drive the development and implementation of detection engineering and intelligence capabilities, designing advanced dashboards, use cases, and threat detection mechanisms to uplift ASIS’s cyber security
- Lead proactive cyber threat hunting activities using SIEM platforms, data analytics, and intelligence to proactively detect malicious activity on ASIS’s ICT systems
- Proactively identify capability and coverage gaps across the ICT environment, managing strategic remediation activities and leveraging data holdings to provide actionable insights and support complex investigations
- Provide technical leadership, mentorship, and coaching to cyber operations staff, managing workflows, setting operational priorities, and driving continuous improvement in tradecraft and incident response methodologies
Core Skills
- Extensive experience in leading complex incident response, technical investigations, and risk management
- Applied understanding of Australian Government cyber security frameworks, including the Protective Security Policy Framework (PSPF) and Information Security Manual (ISM), with the ability to translate these into technical security controls and operational strategies.
- Advanced expertise in cyber security capabilities and tooling, including architecting and optimizing SIEM platforms, leading detection engineering efforts, and leveraging query/coding languages (e.g., SQL, SPL, Python, PowerShell) to automate and enhance threat detection.
- Broad and deep technical knowledge across multiple technology domains (such as infrastructure, virtualisation, cloud, data analytics, or software development) to understand complex enterprise architectures and identify systemic threats.
- Proven technical leadership capabilities, demonstrating high-level judgment, strategic thinking, and the ability to work autonomously to solve complex problems, manage operational workflows, and uplift team capabilities.
- Exceptional communication and stakeholder engagement skills, with the ability to provide authoritative technical advice, brief senior stakeholders, articulate cyber best practices, and manage highly sensitive operational issues.
Education and Qualification Requirements
The following education, qualifications and/or experience will be highly regarded:
- Extensive experience leading cyber security operations, including the monitoring, detection, and response to sophisticated malicious cyber activity
- Advanced expertise in Security Information and Event Management (SIEM) software, data analytics platforms, and query/coding languages (e.g., SPL, SQL, Python, PowerShell) to drive detection engineering and automation
- Proven experience leading technical components of complex incident response activities, which might also include digital forensics or malware analysis.
- Professional certifications along with demonstrated application of knowledge are highly regarded
- Bachelor's degree in Cyber Security, Computer Science, or Information Technology (not essential)
- 5+ years of experience in a cyber security operations or analyst role, with demonstrated technical leadership experience preferably within an enterprise or government environment
Eligibility
To be eligible for a role you must:
- Be an Australian citizen
- Be assessed as suitable to hold and maintain a TOP SECRET-Privileged Access security clearance
- For more information on eligibility please see the Protective Security Policy Framework which is publicly accessible at https://protectivesecurity.gov.au, section 12 provides information on Eligibility and suitability.
- The position is Canberra based, with conditions similar to those in the Australian Public service including superannuation.
Notes
ASIS values workplace diversity and is committed to providing a supportive, inclusive and respective work environment. We encourage applications from Aboriginal and Torres Strait Islander people, Women, people with disabilities, people that identify as LGBTIQ+ and people from culturally and linguistically diverse backgrounds.
ASIS is committed to fostering a diverse and inclusive environment for candidates to participate in all stages of the selection process. Please let us know if you require any additional assistance or reasonable adjustments during any stage of the recruitment process and we will work with you to manage this throughout. If you are successful in gaining employment, reasonable adjustments can also be made available to you in performing your role.
Please note: ASIS does not provide feedback to unsuccessful applicants
Applications close: please refer to website
Getting to know the Australian Secret Intelligence Service
ASIS is Australia’s overseas secret intelligence collection agency. Its mission is to protect and promote Australia’s vital interests through the provision of intelligence services as directed by the Government. Its work can involve collecting intelligence relating to national security, international relations and economic issues. It also contributes to Australia’s coordinated national efforts against terrorism, proliferation of weapons of mass destruction, and trans-national issues such as people smuggling.