Senior Cyber Security Incident Handler

eHealth NSW

Willoughby City Council

Hybrid

AUD 138,000 - 156,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid working
Annual leave loading
Salary packaging

Job summary

eHealth NSW is recruiting a Senior Cyber Security Incident Handler to protect NSW Health’s digital systems. You will investigate cyber security events, coordinate incident response and support secure healthcare services. The role is permanent full-time with hybrid flexibility across Chatswood, St Leonards or Charlestown.

Salary from AUD 137,525 to AUD 156,231 plus 12% Super and 17.5% annual leave loading. You will work across incident response, security operations and digital forensics to

Qualifications

  • Demonstrated experience in cyber incident handling or incident response in a regulated environment.
  • Experience analyzing security alerts and threats using SOC/SIEM tools.
  • Strong analytical skills to translate findings into actionable recommendations.

Responsibilities

  • Lead and coordinate cyber security incident triage, investigation and response across a large digital environment.
  • Analyze security alerts, logs and technical evidence using SOC/SIEM tools.
  • Investigate cyber threats including phishing, unauthorized access and malware.
  • Collect, preserve and analyze digital evidence and artefacts using forensic practices.
  • Coordinate incident response activities with stakeholders and vendors.
  • Translate complex technical information into clear guidance for technical and non-technical audiences.

Skills

Cyber incident handling
Incident response
Security operations
Analytical skills
Stakeholder communication
Risk assessment

Education

ICT or cyber security qualification
Industry certifications

Tools

Microsoft Defender
Splunk
SIEM

Job description

Senior Cyber Security Incident Handler (Health Manager Level 3)

Protect NSW Health’s critical digital systems by investigating cyber threats, coordinating incident response and supporting secure healthcare services across NSW.

  • Permanent Full-Time | Hybrid flexibility for work-life balance | Chatswood, St Leonards or Charlestown
  • Attractive salary from $137,525 to $156,231 + 12% Super + 17.5% annual leave loading
  • Opportunity to work across cyber incident response, security operations and digital forensics

Applications Close: 11:59pm, Monday 12 October 2026

Join the Cyber Security Investigations Team

In this senior role, you will help protect the systems, services and data that support healthcare across NSW. You will investigate cyber security events and incidents, work across incident response, digital forensics, phishing investigations and malware analysis, and help coordinate practical action when threats emerge.

The Cyber Security Investigations team provides specialist digital forensic services, incident response coordination, phishing investigation and malware analysis. Analysts collect evidence and digital artefacts from IT systems, complete objective analysis and produce accurate reporting. The team also triages cyber security incidents using multiple information sources and coordinates the involvement of staff, stakeholders, vendors and technical specialists.

Working closely with technical teams, ICT administrators, vendors and stakeholders, you will investigate potentially compromised systems, identify relevant evidence and provide practical advice throughout the incident lifecycle. This includes supporting containment, remediation and recovery activities in line with the NIST 800-61 Cyber Security Incident Response framework.

In this role, you will:

  • Lead and coordinate cyber security incident triage, investigation and response across a large and complex digital environment, helping teams assess risk, contain threats and restore confidence in affected systems.
  • Analyse security alerts, logs and technical evidence using SOC, SIEM and cyber analytical tools to identify suspicious activity, confirm incident scope and support timely containment and response.
  • Investigate cyber threats including phishing, unauthorised access, unusual login activity, malware and potentially compromised systems.
  • Collect, preserve and analyse digital evidence and artefacts using appropriate forensic practices, then produce clear, objective findings and reports to support incident response decisions.
  • Research, configure and maintain tools used for cyber event logging, analysis and investigation.
  • Coordinate incident response activities, including war rooms, stakeholder updates, technical resources, vendor engagement, issue escalation and risk management.
  • Translate complex technical information into clear advice, incident reporting, analysis and recommendations for technical and senior stakeholders.
  • Improve incident handling practices by contributing to operational methods, procedures, policies and risk-based approaches that strengthen detection and response services.
  • Maintain current knowledge of emerging cyber security threats, vulnerabilities, technologies and investigative techniques.

View the position description here

About You

You will thrive in this role if you enjoy working through complex cyber incidents, following the evidence, making sound decisions under pressure and collaborating with others to protect critical digital services.

We are looking for someone who has:
  • Demonstrated experience in cyber incident handling, incident response or security operations, ideally within a large, complex or highly regulated organisation where incidents require structured triage, clear escalation and coordinated response.
  • Hands-on experience investigating security alerts and cyber threats using SOC or SIEM technologies, such as Microsoft Defender, Splunk or comparable security monitoring and analytical platforms.
  • Strong analytical and investigative skills, including the ability to correlate information from multiple sources, exercise sound judgement and translate technical findings into practical response actions.
  • Experience coordinating complex cyber incidents, including containment and remediation activities, technical teams, stakeholders, risks, issues and reporting.
  • Knowledge of digital forensics and evidence handling, with experience collecting or analysing digital artefacts highly regarded.
  • Strong written and verbal communication skills, including the ability to explain complex cyber security matters clearly to technical and non-technical audiences.
  • Confidence building collaborative relationships with ICT teams, customers, hospitals, agencies, vendors and senior stakeholders to support coordinated incident response and practical problem solving.
  • The ability to remain organised and responsive in a high-volume environment where priorities and technologies can change quickly.
  • Relevant qualifications in ICT or cyber security, or equivalent industry experience. Internationally recognised cyber security or digital forensic certifications will be highly regarded, particularly where they have been applied in practical incident response or forensic investigation settings.
Why work at eHealth NSW

At eHealth NSW, our benefits are designed to provide you with the flexibility, growth and support when you need it. We provide:

  • Hybrid and flexible working options to support balance and productivity
  • Allocated day off per month in addition to annual leave
  • Salary packaging to maximise your take-home pay
Learn More About Us
  • How we hire
  • Diversity and inclusion commitment

For questions around the role or recruitment process, including adjustments, please contact our Talent Advisor or Hiring Manager, Craig and quote REQ692890.

  • To be eligible for this role you must have current Australian work rights (Australian citizen, permanent resident, New Zealand citizen with a current passport, or hold a valid visa with permission to work in Australia).
  • If you currently reside outside NSW, please indicate in your application whether you are willing to relocate if successful.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Security Incident Handler
Senior Cyber Security Incident Handler

NSW Health • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid flexibility
Salary packaging
Allocated day off per month
Senior Cyber Incident Lead - Response, Forensics & SIEM
Senior Cyber Incident Lead - Response, Forensics & SIEM

eHealth NSW • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid working
Annual leave loading
Salary packaging
Senior Cyber Incident Response Lead | Hybrid
Senior Cyber Incident Response Lead | Hybrid

NSW Health • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid flexibility
Salary packaging
Allocated day off per month
Senior Cyber Intelligence Analyst
Senior Cyber Intelligence Analyst

NSW Department of Customer Service • Sydney

Hybrid
AUD 133,000 - 147,000
Flexible working
Career development
Work-life balance
+3
Senior ICT Investment Analyst
Senior ICT Investment Analyst

NSW Health • Willoughby City Council

Hybrid
AUD 154,000 - 183,000
Hybrid flexibility
Salary + super + leave loading
Senior Systems Officer - State-wide Network Services
Senior Systems Officer - State-wide Network Services

NSW Health • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid working options
Salary packaging to maximise take-home
Senior ICT Investment Analyst
Senior ICT Investment Analyst

eHealth NSW • Willoughby City Council

Hybrid
AUD 150,000 - 180,000
Hybrid work options
Extra day off monthly
Salary packaging
+3
Senior Integration Analyst
Senior Integration Analyst

eHealth NSW • Sydney

Hybrid
AUD 154,000 - 183,000
Hybrid work flexibility
One allocated day off per month plus 4
Salary packaging
Senior Cyber Security Analyst
Senior Cyber Security Analyst

NSW Department of Customer Service • Bathurst

On-site
AUD 133,000 - 147,000
Flexible working arrangements
Career development opportunities
Wellbeing support and ERGs
Senior Business Analyst - Investment Prioritisation
Senior Business Analyst - Investment Prioritisation

NSW Health • Willoughby City Council

Hybrid
AUD 138,000 - 156,000
Hybrid work
Superannuation
Leave loading