Level 1 Security Analyst

Triskele Labs

City of Melbourne

On-site

AUD 60,000 - 78,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Triskele Labs in Melbourne is hiring Level 1 Security Analysts for our 24x7 on-site Security Operations Centre. You will monitor, triage and respond to security events across a broad client base, learning from senior analysts and DFIR specialists while you rotate shifts.

We value aptitude, curiosity and work ethic over years of experience and we will fund your certifications to advance from L1 to a credible security professional.

Qualifications

  • Analytical thinking with the ability to assess and prioritise security events.
  • Excellent written and verbal communication skills.
  • Team player who collaborates in a team-oriented environment.

Responsibilities

  • Monitor alert queues and triage security events across client environments, identifying potential security incidents and escalating promptly where required.
  • Perform incident prioritisation and triage to determine the severity, scope and likely impact of security issues.
  • Escalate alerts requiring deeper investigation to the appropriate tier within the SOC, with clear, complete handover notes.
  • Perform efficient triage and ticketing of reported phishing emails, taking timely and appropriate action.
  • Conduct dark web monitoring for client exposure and indicators of compromise using established processes.
  • Respond to hotline calls promptly and professionally so that no client call is missed.
  • Respond to service desk tickets, resolving them or escalating to the appropriate team as required.
  • Perform daily health checks across client environments to identify and address potential issues before they affect monitoring coverage.
  • Attend and lead shift handover meetings, completing the documentation needed for a clean transition between shifts.
  • Create change request tickets for internal and client queries and see them through to resolution.
  • Manage and configure security monitoring tooling within the change control process, escalating configuration changes as required.
  • Work to individual and tier KPIs aligned to our service commitments.
  • Retrieve, assist in producing and issue scheduled weekly and monthly client reports following existing processes.
  • Assist in gathering evidence for monthly reporting and client review meetings, and address client queries arising from them.
  • Proactively identify opportunities to tune event detection and reduce false positives, passing what you see to our Detection Engineering team with the context they need to act on it.
  • Actively identify improvements to internal processes and Standard Operating Procedures, particularly around triage and analysis.
  • Continuously develop your skills through formal training and certification, including completing at least one Blue Team Labs Online challenge per month.
  • Work collaboratively with the wider SOC and with our Platform Engineering, DFIR, Security Engineering and Service Delivery teams.

Skills

Analytical thinking
Communication skills
Team player

Job description

About the company

Triskele Labs is one of Australia's leading sovereign cyber security firms, delivering Managed Detection & Response (MDR), Digital Forensics & Incident Response (DFIR), Offensive Security, and Governance, Risk & Compliance (GRC) services to regulated enterprises, government, and the higher education sector. Built over more than a decade, founder-led and independently owned, we partner with clients operating under some of Australia's most demanding regulatory regimes. Our Security Operations Centre runs 24x7x365 and remains completely onshore in Melbourne, and we are the largest CREST Registered Penetration Testing company in the city. Sovereign Australian ownership, deep technical capability, and front-line threat intelligence from one of the most active DFIR practices in the country sit at the centre of how we differentiate.

About the role

We are hiring Level 1 Security Analysts into our Melbourne Security Operations Centre. This is the front line of our MDR service: the first set of eyes on every alert raised across our clients' environments, at every hour of the day and night. You will work a rotating roster as part of a team that monitors, triages and responds to security events across a broad client base spanning financial services, government, health and higher education. You will learn the craft properly: real telemetry, real incidents, real clients, with senior analysts, detection engineers, threat hunters and a genuine DFIR team sitting alongside you. This is a deliberate entry point into defensive security. We hire for aptitude, curiosity and work ethic rather than years on a résumé, and we fund the certifications that take you from L1 to a credible security professional. What we ask in return is that you take the roster seriously, care about the quality of what you hand to the next shift, and want to get better every month. This is not a Monday-to-Friday role, and it is not a remote role. It is not a detection engineering, penetration testing or GRC role. Analysts who join us wanting to be somewhere else within six months tend not to enjoy it, analysts who want to become genuinely good at investigation and response tend to thrive.

Key Responsibilities

Monitoring and triage

  • Monitor alert queues and triage security events across client environments, identifying potential security incidents and escalating promptly where required.
  • Perform incident prioritisation and triage to determine the severity, scope and likely impact of security issues.
  • Escalate alerts requiring deeper investigation to the appropriate tier within the SOC, with clear, complete handover notes.
  • Perform efficient triage and ticketing of reported phishing emails, taking timely and appropriate action.
  • Conduct dark web monitoring for client exposure and indicators of compromise using established processes.
  • Respond to hotline calls promptly and professionally so that no client call is missed.

Service operations

  • Respond to service desk tickets, resolving them or escalating to the appropriate team as required.
  • Perform daily health checks across client environments to identify and address potential issues before they affect monitoring coverage.
  • Attend and lead shift handover meetings, completing the documentation needed for a clean transition between shifts.
  • Create change request tickets for internal and client queries and see them through to resolution.
  • Manage and configure security monitoring tooling within the change control process, escalating configuration changes as required.
  • Work to individual and tier KPIs aligned to our service commitments.

Reporting and client support

  • Retrieve, assist in producing and issue scheduled weekly and monthly client reports following existing processes.
  • Assist in gathering evidence for monthly reporting and client review meetings, and address client queries arising from them.
Learning and improvement
  • Proactively identify opportunities to tune event detection and reduce false positives, passing what you see to our Detection Engineering team with the context they need to act on it.
  • Actively identify improvements to internal processes and Standard Operating Procedures, particularly around triage and analysis.
  • Continuously develop your skills through formal training and certification, including completing at least one Blue Team Labs Online challenge per month.
  • Work collaboratively with the wider SOC and with our Platform Engineering, DFIR, Security Engineering and Service Delivery teams.
About you

Analytical Thinking: Strong analytical skills with the ability to quickly assess and prioritise security events and incidents. Capable of analysing logs, identifying anomalies, and recognising potential security threats. Communication Skills: Excellent written and verbal communication skills. Ability to convey complex technical information to both technical and non-technical stakeholders effectively. Team Player: Capable of working collaboratively in a team-oriented environment, interacting with

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Security Analyst - MDR/DFIR Frontline
Junior Security Analyst - MDR/DFIR Frontline

Triskele Labs • City of Melbourne

On-site
AUD 60,000 - 78,000
Assistant Vice President, Security Detection & Response, Global Information Security, Sydney
Assistant Vice President, Security Detection & Response, Global Information Security, Sydney

Bank of America • Sydney

On-site
AUD 90,000 - 120,000
Security Operations Centre (SOC) Manager
Security Operations Centre (SOC) Manager

Triskele Labs • City of Melbourne

On-site
AUD 180,000 - 230,000
Security Engineer at Triskele Labs Australia
Security Engineer at Triskele Labs Australia

Triskele Labs • Australia

On-site
AUD 90,000 - 120,000
Collaborate with C-Suite executives
Career advancement opportunities
Modern office in Melbourne CBD
+1
Senior Technical Customer Success Manager
Senior Technical Customer Success Manager

Triskele Labs • City of Melbourne

On-site
AUD 120,000 - 160,000
SOC Analyst - Team Lead
SOC Analyst - Team Lead

Anson McCade • Sydney

Hybrid
AUD 90,000 - 130,000
Vice President, Security Detection & Response, Global Information Security
Vice President, Security Detection & Response, Global Information Security

Bank of America • Sydney

On-site
AUD 180,000 - 240,000
Cyber Security Analyst
Cyber Security Analyst

Aplus Agency • Adelaide

On-site
AUD 90,000 - 120,000
Cyber Security Analyst
Cyber Security Analyst

Teamified • City of Brisbane

On-site
AUD 90,000 - 130,000
Associate Detection & Response Analyst - MDR
Associate Detection & Response Analyst - MDR

Divvy Cloud Corp. • City of Melbourne

On-site
AUD 90,000 - 120,000