EndPoint Analyst

XPT Software

Sydney

On-site

AUD 110,000 - 150,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

XPT SoftwareAustralia PTY Ltd in Sydney is seeking a cybersecurity specialist to harden systems, enforce Microsoft Defender MRB blocks, and align controls with ASD Essential Eight ML2. The role requires hands-on experience with Windows event logging, PowerShell security features, and RBAC across user groups.

You will document current processes, perform risk assessments, maintain MRB compliance through continuous monitoring, and coordinate with ITIL-driven change and incident management.

Qualifications

  • Experience in system hardening, security auditing, or compliance.
  • Familiarity with ASD Essential Eight and Microsoft security baselines.
  • Strong understanding of Windows event logging and PowerShell security features.
  • Experience with Intune, Group Policy, or other configuration management tools.

Responsibilities

  • Confirm and identify the use of Internet Explorer 11
  • Document the current state process of PowerShell module logging, script block logging, and transcription events
  • Perform a current state analysis of new controls
  • Ensure command line process creation events are centrally logged
  • Protect event logs from unauthorized modification and deletion
  • Analyze event logs from internet-facing servers in a timely manner to detect cybersecurity events
  • Identify and document all gaps in controls, policies, and configurations
  • Assess potential risks associated with non-compliance and prioritize remediation efforts
  • Review exceptions for use cases where the most restrictive controls are not implemented and validate if compensating controls are adequate
  • Assess and implement MRB across workstations
  • Conduct a Business Impact Assessment on workstations to assess the operational impact of blocking MRB-listed applications
  • Validate the coverage of current LOLBAS blocking against the MRB to ensure that applications already blocked in the environment are aligned with the MRB blocklist
  • Identify and implement compensating controls for applications that cannot be blocked due to operational dependencies
  • Ensure changes made to implement MRB are fully documented, and alignment with updated Essential Eight ML2 requirements, ready for audit purposes
  • Extract application usage data from Microsoft Defender to determine whether applications/executables on the recommended block list
  • Implement continuous monitoring of MRB compliance and update it regularly to address new vulnerabilities
  • Ensure that MRB blocking rules apply correctly to both privileged and standard user groups, considering RBAC for different user types

Skills

System hardening
Security auditing
Compliance
ASD Essential Eight
PowerShell security features
Windows event logging
Documentation
Communication skills
ITIL
Change management

Tools

Intune
Group Policy
Microsoft Defender

Job description

  • XPT SoftwareAustralia PTY Ltd, incorporated in 2016, is a Software Services company
  • XPT works with topclients across Australia in Banking, Insurance, Telecom,Retail, Energy, Mining and Manufacturingdomains.
  • We have 120+technocrats in Australia working at our clientlocations.
  • XPT SoftwareAustralia is part of group companies which has globalpresence across India & Europe.
  • We have served100+ clients globally, fulfilling their onsite-offshoreneeds.
Key Responsibilities:
  • Confirm and identify the use of Internet Explorer 11
  • Document the current state process of PowerShell module logging, script block logging, and transcription events
  • Perform a current state analysis of new controls
  • Ensure command line process creation events are centrally logged
  • Protect event logs from unauthorized modification and deletion
  • Analyze event logs from internet-facing servers in a timely manner to detect cybersecurity events
  • Identify and document all gaps in controls, policies, and configurations
  • Assess potential risks associated with non-compliance and prioritize remediation efforts
  • Review exceptions for use cases where the most restrictive controls are not implemented and validate if compensating controls are adequate
  • Assess and implement MS recommended Blocklist (MRB) across workstations
  • Conduct a Business Impact Assessment on workstations to assess the operational impact of blocking MRB-listed applications
  • Validate the coverage of current ‘LOLBAS’ blocking against the MRB to ensure that applications already blocked in the environment are aligned with the MRB blocklist
  • Identify and implement compensating controls for applications that cannot be blocked due to operational dependencies, ensuring security is maintained in such cases
  • Ensure changes made to implement MRB are fully documented, and that the implementation aligns with updated Essential Eight ML2 requirements, ready for audit purposes
  • Extract application usage data from Microsoft Defender to determine whether applications/executables on the recommended block list
  • Implement continuous monitoring of MRB compliance and update it regularly to address new vulnerabilities, ensuring it remains effective
  • Ensure that MRB blocking rules apply correctly to both privileged and standard user groups, considering role-based access control (RBAC) for different user types and their specific needs
Required Skills and Experience:
  • Proven experience in system hardening, security auditing, or compliance
  • Familiarity with ASD Essential Eight and Microsoft security baselines
  • Strong understanding of Windows event logging and PowerShell security features
  • Experience with Intune, Group Policy, or other configuration management tools
  • Excellent documentation and analytical skills
  • Familiarity with ITIL framework and processes, particularly in change and incident management
  • Excellent verbal and written communication skills
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

EndPoint Analyst
EndPoint Analyst

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 120,000 - 150,000
Endpoint Security & Compliance Specialist
Endpoint Security & Compliance Specialist

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 120,000 - 150,000
Endpoint Security & Compliance Analyst
Endpoint Security & Compliance Analyst

XPT Software • Sydney

On-site
AUD 110,000 - 150,000
Senior SOC & Incident-Response Analyst
Senior SOC & Incident-Response Analyst

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 110,000 - 150,000
SOC Analyst
SOC Analyst

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 110,000 - 150,000
Network and Security Engineer
Network and Security Engineer

XPT Software Australia Pty Ltd • Australia

On-site
AUD 90,000 - 130,000
Desktop Standard Workplace Services Grade 2 Engineer
Desktop Standard Workplace Services Grade 2 Engineer

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 70,000 - 110,000
Security Engineer Microsoft
Security Engineer Microsoft

NTT • Sydney

On-site
AUD 120,000 - 180,000
Security Engineer - Microsoft App Control
Security Engineer - Microsoft App Control

FinXL • North Sydney Council

On-site
AUD 150,000 - 190,000
WDAC Implementation Specialist / Endpoint Security Engineer
WDAC Implementation Specialist / Endpoint Security Engineer

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 110,000 - 170,000