Intermediate Security Engineer, Security Incident Response Team (SIRT)

Jobgether

Australia

Remote

AUD 110,000 - 160,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote work in Australia
4-day work week
Flexible PTO
Equity compensation

Job summary

Jobgether is representing a partner company in Australia seeking an Intermediate Security Engineer for the Security Incident Response Team (SIRT). The role centers on protecting cloud infrastructure and user data, with a 24/7 global rotation and a compressed four-day schedule.

You will monitor, investigate, and respond to incidents across cloud environments (AWS/GCP), using SIEM and logging tools, and contribute to process improvements and strategic security projects.

Qualifications

  • Experience with security incident response processes and runbooks.
  • Experience using SIEM platforms and security logging tools.
  • Experience with cloud environments (AWS/GCP).
  • Python programming or willingness to develop.
  • Strong documentation skills and clear operational writing.
  • Proactive mindset in identifying threats and improving controls.
  • Interest or experience in cloud-based security investigations.

Responsibilities

  • Lead security incident response activities within a 24/7 global rotation, from detection to containment and recovery.
  • Investigate and analyze security events using monitoring and logging tools.
  • Create and maintain incident response runbooks and SOPs.
  • Perform root cause analysis and post-incident reviews to extract lessons learned.
  • Design and implement automated security processes to reduce manual work.
  • Identify gaps and implement improvements to detection and response capabilities.
  • Collaborate with engineering and other teams on security projects.
  • Identify emerging threats and opportunities to strengthen defensive controls.

Skills

SIEM experience
Cloud (GCP/AWS)
Python
Incident response
Forensic analysis
Technical writing
Collaboration

Tools

SIEM tools
AWS
GCP
Python environment

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Intermediate Security Engineer, Security Incident Response Team (SIRT) based in Australia.

This role places you at the frontline of protecting critical cloud infrastructure and sensitive user data from evolving security threats. You’ll join a globally distributed Security Operations environment responsible for detecting, investigating, and responding to incidents around the clock. Working on a compressed four-day schedule, you’ll gain hands‑on experience managing real‑world security events from detection through recovery. You’ll use security monitoring, logging, and automation tools to strengthen incident response capabilities and operational efficiency. The role also offers opportunities to improve security processes, develop detection capabilities, and contribute to technical projects. With mentorship and cross‑regional collaboration, you’ll build both tactical incident response expertise and strategic security thinking.

Accountabilities

You’ll play an active role in security incident response while helping strengthen the processes, automation, and capabilities that support a resilient security operation.

  • Lead security incident response activities within a 24/7 global rotation, from initial detection through containment and recovery.
  • Investigate and analyze security events using security monitoring, logging, and incident response tools.
  • Create, maintain, and improve incident response documentation, including runbooks and standard operating procedures.
  • Conduct root cause analysis and post‑incident reviews to identify lessons learned and strengthen future response.
  • Design and implement automated security processes that improve operational efficiency and reduce manual intervention.
  • Identify security gaps and implement improvements to detection and response capabilities.
  • Collaborate with engineering and other internal teams on technical projects that enhance security infrastructure and capabilities.
  • Contribute to proactive security measures by identifying emerging threats and opportunities to improve defensive controls.
Requirements

You’ll be well suited to this role if you have a solid foundation in security operations and incident response, combined with curiosity, analytical thinking, and a willingness to deepen your technical expertise.

  • Demonstrated ability to learn and independently lead security incident response processes.
  • Experience working with SIEM platforms and security logging tools.
  • Experience with cloud environments, particularly GCP and/or AWS.
  • Python programming skills or a strong willingness and ability to develop them.
  • Strong technical writing and documentation skills, with a genuine interest in maintaining clear operational documentation.
  • A proactive and investigative mindset when identifying and analyzing security threats.
  • Interest or experience in forensic analysis of compromised or infected hosts.
  • Experience with, or a strong desire to learn, cloud‑based security investigations.
  • Ability to remain calm and analytical in high‑pressure situations while following established procedures and runbooks.
  • Strong collaboration skills and the ability to work effectively across geographically distributed teams.
Benefits
  • Remote work opportunity in Australia.
  • Compressed four-day work schedule, with full-time hours distributed across four longer days.
  • Sunday-Wednesday shifts supporting 24/7/365 security coverage.
  • Flexible paid time off.
  • Benefits designed to support health, finances, and overall well‑being.
  • Equity compensation and employee stock purchase plan.
  • Growth and development fund.
  • Parental leave.
  • Access to team member resource groups and an inclusive, globally distributed working environment.
  • Opportunities for mentorship, continuous learning, and collaboration with security professionals across multiple regions.

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre‑contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIRT Security Engineer - Remote AU, 4-Day Week, Equity
SIRT Security Engineer - Remote AU, 4-Day Week, Equity

Jobgether • Australia

On-site
AUD 110,000 - 160,000
Remote work in Australia
4-day work week
Flexible PTO
+1
Staff Security Operations Engineer
Staff Security Operations Engineer

Jobgether • Australia

Remote
AUD 180,000 - 240,000
Remote-first working environment
Annual learning budget USD 2,000
Global travel opportunities
+2
Assistant Vice President, Security Detection & Response, Global Information Security, Sydney
Assistant Vice President, Security Detection & Response, Global Information Security, Sydney

Bank of America • Sydney

On-site
AUD 90,000 - 120,000
Director - Cyber Operations
Director - Cyber Operations

Jobgether • Australia

Remote
AUD 180,000 - 280,000
Fully remote
Flexible hours
Professional development
+2
Security Engineer, AWS Security Incident Response
Security Engineer, AWS Security Incident Response

Amazon Web Services (AWS) • Council of the City of Sydney

On-site
AUD 120,000 - 180,000
Security Engineer
Security Engineer

Upwind Security • Sydney

On-site
AUD 140,000 - 200,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Australia

On-site
AUD 140,000 - 190,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • City of Melbourne

On-site
AUD 130,000 - 170,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Sydney

On-site
AUD 150,000 - 190,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • City of Brisbane

On-site
AUD 140,000 - 190,000