Senior Cyber Security Incident Handler

NSW Health

Willoughby City Council

Hybrid

AUD 138,000 - 156,000

Full time

5 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid flexibility
Salary packaging
Allocated day off per month

Job summary

eHealth NSW is seeking a Senior Cyber Security Incident Handler to lead triage, investigation and response across a large digital environment supporting NSW Health. You will work with incident response, digital forensics, phishing investigations and malware analysis to protect healthcare data and services.

You will coordinate containment and remediation, analyse alerts and evidence, and communicate outcomes to technical and senior stakeholders while applying the NIST 800-61 framework and

Qualifications

  • Demonstrated experience in cyber incident handling and response.
  • Experience in security operations within large/regulated environments.
  • Ability to translate findings for technical and non-technical audiences.

Responsibilities

  • Lead and coordinate cyber security incident triage, investigation and response.
  • Analyse security alerts, logs and evidence to define incident scope.
  • Investigate threats including phishing, access anomalies and malware.
  • Collect, preserve and analyse digital evidence and artefacts.
  • Research, configure and maintain tools for event logging and analysis.
  • Coordinate incident response with war rooms, updates and vendor engagement.
  • Translate complex information into clear incident reports and recommendations.
  • Improve incident handling practices through procedures and risk-based improvements.
  • Maintain current knowledge of emerging threats and techniques.

Skills

Cyber incident handling
Incident response
Security operations
Analytical skills
Stakeholder management
Communication skills

Education

ICT or cyber security qualifications

Tools

Microsoft Defender
Splunk
SOC / SIEM platforms

Job description

Senior Cyber Security Incident Handler (Health Manager Level 3)

Protect NSW Health’s critical digital systems by investigating cyber threats, coordinating incident response and supporting secure healthcare services across NSW.

  • Permanent Full-Time | Hybrid flexibility for work‑life balance | Chatswood, St Leonards or Charlestown
  • Attractive salary from $137,525 to $156,231 + 12% Super + 17.5% annual leave loading
  • Opportunity to work across cyber incident response, security operations and digital forensics


Applications Close: 11:59pm, Monday 12 October 2026

Join the Cyber Security Investigations Team

In this senior role, you will help protect the systems, services and data that support healthcare across NSW. You will investigate cyber security events and incidents, work across incident response, digital forensics, phishing investigations and malware analysis, and help coordinate practical action when threats emerge.

The Cyber Security Investigations team provides specialist digital forensic services, incident response coordination, phishing investigation and malware analysis. Analysts collect evidence and digital artefacts from IT systems, complete objective analysis and produce accurate reporting. The team also triages cyber security incidents using multiple information sources and coordinates the involvement of staff, stakeholders, vendors and technical specialists.

Working closely with technical teams, ICT administrators, vendors and stakeholders, you will investigate potentially compromised systems, identify relevant evidence and provide practical advice throughout the incident lifecycle. This includes supporting containment, remediation and recovery activities in line with the NIST 800-61 Cyber Security Incident Response framework.

In this role, you will:

  • Lead and coordinate cyber security incident triage, investigation and response across a large and complex digital environment, helping teams assess risk, contain threats and restore confidence in affected systems.
  • Analyse security alerts, logs and technical evidence using SOC, SIEM and cyber analytical tools to identify suspicious activity, confirm incident scope and support timely containment and response.
  • Investigate cyber threats including phishing, unauthorised access, unusual login activity, malware and potentially compromised systems.
  • Collect, preserve and analyse digital evidence and artefacts using appropriate forensic practices, then produce clear, objective findings and reports to support incident response decisions.
  • Research, configure and maintain tools used for cyber event logging, analysis and investigation.
  • Coordinate incident response activities, including war rooms, stakeholder updates, technical resources, vendor engagement, issue escalation and risk management.
  • Translate complex technical information into clear advice, incident reporting, analysis and recommendations for technical and senior stakeholders.
  • Improve incident handling practices by contributing to operational methods, procedures, policies and risk‑based approaches that strengthen detection and response services.
  • Maintain current knowledge of emerging cyber security threats, vulnerabilities, technologies and investigative techniques.

You will thrive in this role if you enjoy working through complex cyber incidents, following the evidence, making sound decisions under pressure and collaborating with others to protect critical digital services.

We are looking for someone who has:

  • Demonstrated experience in cyber incident handling, incident response or security operations, ideally within a large, complex or highly regulated organisation where incidents require structured triage, clear escalation and coordinated response.
  • Hands‑on experience investigating security alerts and cyber threats using SOC or SIEM technologies, such as Microsoft Defender, Splunk or comparable security monitoring and analytical platforms.
  • Strong analytical and investigative skills, including the ability to correlate information from multiple sources, exercise sound judgement and translate technical findings into practical response actions.
  • Experience coordinating complex cyber incidents, including containment and remediation activities, technical teams, stakeholders, risks, issues and reporting.
  • Knowledge of digital forensics and evidence handling, with experience collecting or analysing digital artefacts highly regarded.
  • Strong written and verbal communication skills, including the ability to explain complex cyber security matters clearly to technical and non‑technical audiences.
  • Confidence building collaborative relationships with ICT teams, customers, hospitals, agencies, vendors and senior stakeholders to support coordinated incident response and practical problem solving.
  • The ability to remain organised and responsive in a high‑volume environment where priorities and technologies can change quickly.
  • Relevant qualifications in ICT or cyber security, or equivalent industry experience. Internationally recognised cyber security or digital forensic certifications will be highly regarded, particularly where they have been applied in practical incident response or forensic investigation settings.
Why work at eHealth NSW

At eHealth NSW, our benefits are designed to provide you with the flexibility, growth and support when you need it. We provide:

  • Hybrid and flexible working options to support balance and productivity
  • Allocated day off per month in addition to annual leave

Salary packaging to maximise your take‑home pay

Hear about how our team benefits from working at eHealth

As the digital centre of excellence for NSW Health, we design and deliver secure, scalable technology that supports patient care across the state, helping clinicians provide better healthcare, now and into the future.

Join eHealth NSW to create real‑world impact, drive meaningful outcomes and support the health of millions every day. Learn more about us at eHealth NSW

NSW Health acknowledges the people of the many traditional countries and language groups of New South Wales. It acknowledges the wisdom of Elders past and present, and pays respect to all Aboriginal communities of today.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Security Incident Handler
Senior Cyber Security Incident Handler

eHealth NSW • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid working
Annual leave loading
Salary packaging
Senior Cyber Incident Lead - Response, Forensics & SIEM
Senior Cyber Incident Lead - Response, Forensics & SIEM

eHealth NSW • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid working
Annual leave loading
Salary packaging
Senior ICT Investment Analyst
Senior ICT Investment Analyst

NSW Health • Willoughby City Council

Hybrid
AUD 154,000 - 183,000
Hybrid flexibility
Salary + super + leave loading
Senior Systems Officer - State-wide Network Services
Senior Systems Officer - State-wide Network Services

NSW Health • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid working options
Salary packaging to maximise take-home
Senior Cyber Incident Response Lead | Hybrid
Senior Cyber Incident Response Lead | Hybrid

NSW Health • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid flexibility
Salary packaging
Allocated day off per month
Senior ICT Investment Analyst
Senior ICT Investment Analyst

eHealth NSW • Willoughby City Council

Hybrid
AUD 150,000 - 180,000
Hybrid work options
Extra day off monthly
Salary packaging
+3
Senior Cyber Intelligence Analyst
Senior Cyber Intelligence Analyst

NSW Department of Customer Service • Sydney

Hybrid
AUD 133,000 - 147,000
Flexible working
Career development
Work-life balance
+3
Senior Integration Analyst
Senior Integration Analyst

eHealth NSW • Sydney

Hybrid
AUD 154,000 - 183,000
Hybrid work flexibility
One allocated day off per month plus 4
Salary packaging
Senior Business Analyst - Investment Prioritisation
Senior Business Analyst - Investment Prioritisation

NSW Health • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid work
Superannuation
Leave loading
Cloud Engineer
Cloud Engineer

United States Digital Space LLC • Willoughby City Council

Hybrid
AUD 135,199 - 165,244
Hybrid working options
Allocation day off per month
Salary packaging
+2