Senior Cybersecurity Incident Responder

Datacom

Australia

Hybrid

AUD 100,000 - 130,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Social events
Chill-out spaces
Remote working
Flexi-hours
Professional development courses

Job summary

Datacom is seeking a Senior Cybersecurity Incident Responder for their Cybersecurity Incident Response Team (CSIRT) based in Australia. This role involves leading digital forensics and incident response engagements, delivering proactive advisory services, and communicating with senior stakeholders.

The ideal candidate brings substantial experience in handling significant cybersecurity incidents and proficiency with various DFIR tools. A supportive environment with benefits like flexible hours and professional development is offered.

Qualifications

  • Proven experience in responding to significant cybersecurity incidents.
  • Ability to communicate with various senior stakeholders in tense situations.
  • Experience using DFIR tools and methodologies.

Responsibilities

  • Conduct investigations into major security incidents.
  • Deliver DFIR engagements and advisory services.
  • Produce comprehensive reports on findings and recommendations.
  • Participate in project coordination and communicate with stakeholders.

Skills

Digital forensics & incident response (DFIR)
Communication with senior stakeholders
Incident response services
Forensic techniques
Scripting or automation skills

Education

SANS GCFA, GCFE, GCIH, or relevant DFIR certifications

Tools

EnCase
X-Ways
Magnet Axiom
CrowdStrike
Splunk

Job description

We are currently looking for a highly skilled and motivated individual to join our Cybersecurity Incident Response Team (CSIRT) as a Senior Cybersecurity Incident Responder. CSIRT provides proactive and reactive expertise to help organisations respond to major cybersecurity incidents.

In this role you will be responsible for the delivery of digital forensics & incident response (DFIR) engagements, and proactive advisory engagements such as tabletop exercises, compromise assessments, threat hunting, breach readiness assessments, threat intelligence briefings, and threat modelling. You will be expected to lead DFIR engagements across either Australia or New Zealand.

What You’ll Do
  • Conduct thorough investigations into major security incidents, determining root causes, impact, and mitigation strategies, and provide expertise and support to contain, eradicate, and recover from such incidents.
  • Conduct analysis of affected systems utilising forensic techniques to thoroughly examine system events and adversary activities.
  • Utilise security tooling such as EDR, SIEM, XDR, and identity technologies to assist your investigation of confirmed or suspected compromises.
  • Undertake log and correlation analysis and construct a timeline of adversary activities.
  • Identify intrusion vectors and root causes and develop recommendation actions to prevent similar incidents.
  • Collect digital forensics evidence from affected systems in accordance with industry standards for image acquisition and preservation of digital evidence.
  • Produce comprehensive, detailed DFIR reports outlining the investigative steps undertaken, your findings, and recommendations.
  • Support the coordination of containment, eradication, and recovery efforts based on available information and established processes.
  • Analyse incident response effort, with feedback from the customer and third parties as part of Post Incident Reviews (PIRs) and Lessons Learned.
  • Deliver proactive incident response services which include tabletop exercises, threat hunting, compromise assessments, breach readiness assessments, threat intelligence briefings, and threat modelling.
  • Communicate with senior stakeholders within Datacom and our customers.
  • Work with other members of the CSIRT team to develop the technical capabilities of the CSIRT, including improving the processes and technology to deliver successful outcomes to customers and stakeholders.
  • Participate in an on‑call roster for major incident response.
  • Occasional planned or last‑minute/urgent travel to customer sites will be required for certain customer‑facing engagements, including travel within Australia and New Zealand.
What You’ll Bring
  • Confidence in communicating with a variety of senior stakeholders, including senior leadership teams in difficult or tense situations.
  • Proven experience in responding to high‑profile cybersecurity incidents that have had significant operational or privacy impacts to the affected organisation such as ransomware and data breaches.
  • Experience in digital forensics & incident response (DFIR) with an understanding of key system and digital forensic artifacts and how they are useful in a cybersecurity investigation.
  • Experience using DFIR tools such as EnCase, X‑Ways, Magnet Axiom, Velociraptor, KAPE, and THOR.
  • Proven knowledge and experience of efficiently searching large datasets across multiple log sources and underlying platforms, including XDR/EDR and SIEM products such as CrowdStrike, Microsoft Defender, Splunk, or Sentinel.
  • A strong understanding of current and emerging attacker behaviours, tools, tactics, and techniques.
  • An understanding of various security frameworks and methodologies such as NIST CSF, MITRE ATT&CK, D3FEND, Unified Kill Chain and OWASP Top 10.
  • Basic scripting or automation skills are desirable (for example PowerShell, Bash, Python, or Ruby).
  • SANS GCFA, GCFE, GCIH, or relevant DFIR certifications are desirable.
Benefits
  • Social events
  • Chill‑out spaces
  • Remote working
  • Flexi‑hours
  • Professional development courses
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Incident Responder
Senior Cybersecurity Incident Responder

Datacom • Sydney

On-site
AUD 140,000 - 190,000
Social events
Remote working
Flexi-hours
+1
Remote Senior Cybersecurity Incident Responder: DFIR Leader
Remote Senior Cybersecurity Incident Responder: DFIR Leader

Datacom • Sydney

On-site
AUD 140,000 - 190,000
Social events
Remote working
Flexi-hours
+1
Senior DFIR Lead - Remote, Flexible Hours, Growth
Senior DFIR Lead - Remote, Flexible Hours, Growth

Datacom • Australia

Hybrid
AUD 100,000 - 130,000
Social events
Chill-out spaces
Remote working
+2
Senior Incident Responder – Digital Forensics & CSIRT
Senior Incident Responder – Digital Forensics & CSIRT

Forensic Focus Limited • City of Melbourne

Hybrid
AUD 95,000 - 129,000
Cyber Detection and Response Analyst, Asia Pacific
Cyber Detection and Response Analyst, Asia Pacific

Control Risks • Council of the City of Sydney

On-site
AUD 90,000 - 140,000
Digital Forensics & Incident Response Specialist (DFIR)
Digital Forensics & Incident Response Specialist (DFIR)

Talenza • Sydney

Hybrid
AUD 140,000 - 190,000
Hybrid working environment
Ongoing professional development
Career progression opportunities
Senior Cyber Threat Hunt Specialist
Senior Cyber Threat Hunt Specialist

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1
Senior DFIR Lead & Investigations Strategist
Senior DFIR Lead & Investigations Strategist

Infotrust • Sydney

Hybrid
AUD 180,000 - 240,000
Cybersecurity Consultant: Incident Response & Pentesting
Cybersecurity Consultant: Incident Response & Pentesting

Fti Consulting • Sydney

On-site
AUD 120,000 - 160,000
Cybersecurity Consultant: Incident Response & Pentesting
Cybersecurity Consultant: Incident Response & Pentesting

FTI Consulting • Sydney

On-site
AUD 80,500 - 104,000
Discretionary bonuses
Flexible working arrangements
Paid professional development
+2