Senior Cyber Security Analyst

RGIT Australia

Sydney

On-site

AUD 180,000 - 240,000

Full time

32 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

RGIT Australia is seeking a Senior Cyber Security Analyst to lead security operations across a multi-tenant client base. The role owns the SIEM/XDR platform and coordinates incident response, threat hunts and vulnerability management with end-to-end accountability.

You will work with Wazuh/OpenSearch, Terraform/Ansible, and cloud security in AWS and Azure, balancing engineering with client-facing governance and reporting to executives.

Qualifications

  • A bachelor degree or higher in cyber security or related field.
  • At least five years’ experience in security operations or security engineering in multi-client or multi-tenant environments.
  • Proven SIEM engineering depth with hands-on deployment, tuning and operation (Wazuh/OpenSearch preferred).
  • Demonstrated incident response capability including reconstructing attack chains and communicating findings to executives.
  • Cloud security in AWS (IAM, KMS, Secrets management) and familiarity with Azure Entra ID.
  • Infrastructure as code and automation using Terraform/Ansible; production-grade scripting in Python/Bash.
  • Knowledge of ISO/IEC 27001 and audit cycles; strong documentation discipline.
  • Excellent client-facing communication, written reporting and problem-solving skills.
  • Desirable certifications such as GCIA, GCIH, CISSP, AWS Security – Specialty; MSSP/consultancy experience.

Responsibilities

  • Perform daily client SOC triage, investigate alerts, and escalate across multi-tenant environments.
  • Lead investigations on client security incidents, reconstruct attack chains and advise executives on remediation.
  • Own the SIEM/XDR architecture and multi-tenant data plane with code-driven configuration and RBAC.
  • Drive detection engineering, alert tuning, enrichment, risk-based alerting and threat hunts.
  • Maintain endpoint agent control plane, including dual-credential failover, rollouts and secure signing.
  • Lead SIEM onboarding programs: tenancy creation, agent deployment, log sources, SSO and integrations.
  • Oversee vulnerability management, risk prioritization, patching SLAs and CVE response cycles.
  • Support ISO/IEC 27001 and SOC 2-aligned controls, including access reviews and policy governance.
  • Mentor junior analysts and maintain playbooks for consistent incident response.

Skills

SIEM engineering
Incident response
Cloud security
Infrastructure as code
Automation
Documentation
Client-facing
Threat hunting

Education

Bachelor's degree or higher in cyber security or related field

Tools

Wazuh
OpenSearch
Elastic
Microsoft Sentinel
Splunk
Terraform
Ansible

Job description

Full-time Permanent Mid-level Senior

Posted 15 Sep 2026

Description
Position Purpose

The Senior Cyber Security Analyst is Revio’s principal authority on security operations. The role performs daily triage and investigation across the multi-tenant client base, acts as lead investigator on client security incidents, and owns the architecture, build and operation of the security platform on which those investigations run. The scope is deliberately broad: there is no separation between the people who operate the security operations centre (SOC) and the people who build it, so the same specialist identifies a detection gap and engineers the fix. The role carries end-to-end ownership of a production multi-tenant security platform, with direct access to the Chief Executive Officer and to client executives.

Key Responsibilities
  • Perform daily multi-tenant alert triage, investigation and escalation across live client SOC tenants, analysing alerts and data from security products, web proxies, network security devices and vulnerability scanning and management systems, and operate a console duty rotation with out-of-hours availability for critical escalations.
  • Act as lead investigator on client security incidents, coordinating and investigating breaches to determine root cause, including full attack-chain reconstruction from multi-million-event log sets, cloud forensics covering control-plane audit trails, identity and access management abuse and secrets-manager compromise, and forensic assessment of attacker-supplied artefacts; direct containment, eradication and evidence preservation, and advise client executives on customer-notification sequencing and regulator engagement.
  • Own the architecture, build and operation of the multi-tenant SIEM and XDR platform (Wazuh and OpenSearch), including the multi-tenancy data plane covering document-level security, per-tenant role-based access control, tenant attribution in the ingest pipeline and index-family source routing, maintained entirely as code using Terraform with managed remote state, Ansible provisioning roles and a gated CI/CD pipeline with security scanning and idempotence checks, so that no live change remains uncodified.
  • Drive detection engineering and alert quality, covering noise-source analysis, deduplication and correlation, enrichment, risk-based alerting and dashboard-correctness validation, and conduct proactive threat hunts using frequency-analysis and stack-counting methodology, maintaining knowledge of the current threat landscape and producing formal findings reports.
  • Own the connector and integration estate and the endpoint agent control plane, including dual-credential failover, credential lifecycle and expiry management, integration health monitoring, signed cross-platform agent artefacts for Windows, macOS and Linux, two-tier remote upgrade with rollback, an out-of-band control channel over mutual TLS with signed allow-listed commands, package-signing certificate authority, key rotation and staged rollout with health gates.
  • Lead client SIEM onboarding programs end to end against a standardised template covering tenancy creation, endpoint agent deployment, log-source and syslog integration, single sign-on, perimeter scanning, dark-web and threat-intelligence feeds, high-value-target and file-integrity monitoring, and firewall and XDR integration, acting as the named technical contact for client IT managers, security leads and their third-party integrators and chairing integration governance meetings.
  • Own vulnerability and exposure management and the recurring client reporting cycle, including performing assessments on systems, networks and applications to identify and prioritise security risks, scheduled internal and external scanning, attack-surface discovery, patching service levels with automated enforcement, emergency CVE response, continuous ransomware exposure monitoring, and monthly exposure, missing-patch, detection overview, phishing simulation and cloud posture reports issued across all tenants within one to three days of month end.
  • Operate and evidence the technical controls underpinning Revio’s ISO/IEC 27001 and ISO/IEC 42001 certifications and its SOC 2-aligned control set, including vulnerability scanning cadence, encryption in transit and at rest, release approval and testing, backup recoverability, penetration testing and remediation service levels, quarterly access reviews, and administration of single sign-on, privileged and break-glass accounts, API key and certificate rotation and the internal certificate authority.
  • Own platform reliability and the supporting estate, covering disaster recovery design, resilience auditing, capacity and storage-growth management, backup and restore testing across SaaS platforms and infrastructure, and maintain the platform operations documentation, SOC operating procedures and analyst playbook library to a standard from which a technical reader with no prior context can deploy, operate and repair the platform; mentor junior and graduate analysts.
Skills, Knowledge and Experience
  • Essential: A bachelor degree or higher in cyber security, information technology, computer science or a related discipline; equivalent qualifications and relevant experience will be considered.
  • At least five years’ experience in security operations, security engineering or a hybrid role, including hands-on alert triage, investigation and incident response in a multi-client or multi-tenant environment.
  • Demonstrable SIEM engineering depth, meaning deploying, tuning and operating a SIEM rather than only using one. Wazuh and OpenSearch, or Elastic, are strongly preferred; Microsoft Sentinel or Splunk will be considered where the candidate has performed genuine ingest pipeline and detection engineering work.
  • Proven incident response capability, including reconstructing an attack chain from raw log data, reasoning about evidence gaps, and communicating findings to a non-technical executive audience.
  • Cloud security competence in Amazon Web Services, covering identity and access management and STS, key management and secrets management, logging and audit services, and network architecture, together with familiarity with Microsoft Azure and Entra ID.
  • Infrastructure as code and automation, covering Terraform and Ansible or close equivalents, CI/CD pipelines and Git-based workflow, together with Python and Bash to a standard that supports production automation, API integrations and data pipelines; the candidate must be genuinely comfortable that infrastructure changes are made through code rather than consoles.
  • Working knowledge of ISO/IEC 27001 and experience contributing to a certification or audit cycle, and demonstrated documentation discipline, meaning a verifiable habit of writing to a standard others can operate from.
  • Client-facing capability sufficient to run a technical meeting with a client’s IT manager, write a report an executive will read, and hold a position under pressure, together with excellent written communication, analytical and problem-solving skills.
  • Desirable: Relevant professional certification, such as GCIA, GCIH, OSCP, CISSP, AWS Certified Security – Specialty, SC-200 or AZ-500; experience in an MSSP or consultancy environment; detection engineering at scale; endpoint agent packaging, code signing and fleet management; Fortinet firewall and identity platform administration; ISO/IEC 42001 or AI governance exposure; or experience with self-hosted large language model or retrieval-augmented generation systems.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Governance Risk and Compliance Specialist
Cyber Governance Risk and Compliance Specialist

RGIT Australia • Sydney

On-site
AUD 130,000 - 170,000
Principle Security Architect
Principle Security Architect

Talenza • City of Melbourne

On-site
AUD 180,000 - 240,000
Staff Incident Response Commander
Staff Incident Response Commander

Cox Purtell • Sydney

On-site
AUD 180,000 - 240,000
SOC Detection Specialist
SOC Detection Specialist

Powerdatagroup • Canberra

Hybrid
AUD 140,000 - 190,000
Cyber Security Analyst
Cyber Security Analyst

specialized • City of Melbourne

On-site
AUD 110,000 - 150,000
Senior Security Consultant
Senior Security Consultant

CSO Group • Sydney

On-site
AUD 120,000 - 180,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Placements24 • Newlands

Hybrid
AUD 150,000 - 190,000
Remote work
Competitive salary
Healthcare
+1
Cyber Security Analyst
Cyber Security Analyst

cleared • Canberra

On-site
AUD 90,000 - 130,000
Hybrid work culture
Training opportunities
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
Cyber Security Architect
Cyber Security Architect

Macquarietechnologygroup • Sydney

On-site
AUD 180,000 - 260,000