Senior Cybersecurity Incident Responder

Datacom

Australia

Hybrid

AUD 140,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote work
Flexi-hours
Professional development

Job summary

Datacom is seeking a Senior Cybersecurity Incident Responder to lead DFIR engagements and proactive advisory work across Australia and New Zealand. You will investigate major incidents, determine root causes, and guide containment, eradication and recovery with strong stakeholder communication.

You’ll conduct forensic analyses, produce comprehensive reports, and deliver tabletop exercises, threat hunting, and breach readiness assessments as part of the CSIRT team.

Qualifications

  • Experience responding to high-profile cybersecurity incidents with operational or privacy impact.
  • Proficient in digital forensics and incident response (DFIR) with artifact knowledge.
  • Experience with DFIR tools such as EnCase, X-Ways, Magnet Axiom, Velociraptor, KAPE, THOR.
  • Able to search large datasets across log sources and EDR/SIEM platforms.

Responsibilities

  • Lead DFIR engagements across Australia or New Zealand.
  • Conduct thorough investigations to determine root causes, impact and mitigation.
  • Produce detailed DFIR reports with findings and recommendations.
  • Coordinate containment, eradication and recovery efforts.
  • Deliver proactive IR services including tabletop exercises and threat modelling.
  • Communicate with senior stakeholders and customers.

Skills

Executive communication
Cybersecurity incident response
DFIR tooling
Threat hunting
Scripting basics
Stakeholder management
DFIR certifications

Tools

EnCase
X-Ways
Magnet AXIOM
Velociraptor
KAPE
THOR
CrowdStrike
Microsoft Defender
Splunk
Sentinel

Job description

Our Purpose

Here at Datacom we connect people and technology in order to solve challenges, create opportunities and discover new possibilities for the communities we live in.

Our Team

Datacom’s Cybersecurity Defence Operations Centre (CDOC) operates across Australia & New Zealand where we provide a full stack of cybersecurity services including managed SOC/SIEM/EDR/XDR, threat intelligence, and digital forensics & incident response (DFIR).Our Cybersecurity Defence Operations Centre is a well-established team made up of Cybersecurity Analysts, Platforms Engineers, Automation Specialists, Solutions Delivery Engineers, Threat Intel Analysts, Threat Hunters, & Incident Responders who have been managing customers, both commercial and government, for over 10+ years.

We partner with industry leaders to provide our services and to provide you with a broad technical skillset, certifications, and experience.

About The Role

We are currently looking for a highly skilled and motivated individual to join our Cybersecurity Incident Response Team (CSIRT) as a Senior Cybersecurity Incident Responder. CSIRT provide proactive and reactive expertise to help organisations respond to major cybersecurity incidents.

In this role you will be responsible for the delivery of digital forensics & incident response (DFIR) engagements, and proactive advisory engagements such as the delivery of tabletop exercises, compromise assessments & threat hunting, breach readiness assessments, threat intelligence briefings, & threat modelling.You will be expected to lead DFIR engagements across either Australia or New Zealand.

We are seeking a candidate who has extensive experience investigating and responding to major cybersecurity incidents, and possesses excellent communication, analytical, and problem-solving skills.

What You’ll Do

As a Senior Cybersecurity Incident Responder, you will:

  • Conduct thorough investigations into major security incidents, determining root causes, impact, and mitigation strategies. Providing expertise and support to contain, eradicate, and recover from such security incidents.
  • Conduct analysis of affected systems utilising forensic techniques to thoroughly examine system events and adversary activities.
  • Utilise security tooling such as EDR, SIEM, XDR, & Identity technologies to assist your investigation of confirmed or suspected compromises.
  • Undertake log & correlation analysis and construct a timeline of adversary activities.
  • Identify intrusion vectors & root causes and develop recommendation actions to prevent similar incidents.
  • Collect digital forensics evidence from affected systems in accordance with industry standards for image acquisition and preservation of digital evidence.
  • Produce comprehensive, detailed DFIR reports outlining the investigative steps undertaken, your findings, and recommendations.
  • Support the coordination of containment, eradication and recovery efforts based on available information and established processes.
  • Analysis of incident response effort, with feedback from the customer and third parties as part of Post Incident Reviews (PIRs) and Lessons Learned.
  • Deliver proactive incident response services which include tabletop exercises, threat hunting, compromise assessments, breach readiness assessments, threat intelligence briefings, and threat modelling.
  • Communicate with senior stakeholders within Datacom and our customers.
  • Work with other members of the CSIRT team, to develop the technical capabilities of the CSIRT - including improving the processes and technology to deliver successful outcomes to customers and stakeholders.
  • Participate in an on-call roster for major incident response.
  • Occasional planned or last-minute/urgent travel to customer sites will be required for certain customer facing engagements. This may include a customer site in your home city, or travel to other customer sites within Australia and New Zealand.
What you’ll bring
  • Confidence in communicating with a variety of senior stakeholders, including Senior Leadership teams in difficult / tense situations.
  • Proven experience in responding to high-profile cybersecurity incidents that have had significant operational or privacy impacts to the affected organisation such as ransomware & data breaches.
  • Experience in digital forensics & incident response (DFIR) with an understanding of key system & digital forensic artifacts and how they are useful in a cybersecurity investigation.
  • Experience using DFIR tools such as EnCase, X-Ways, Magnet Axiom, Velociraptor, KAPE, & THOR.
  • Proven knowledge and experience of efficiently searching large datasets across multiple log sources and underlying platforms including XDR/EDR and SIEM products such as CrowdStrike, Microsoft Defender, Splunk, or Sentinel.
  • A strong understanding of current and emerging attacker behaviours, tools, tactics, and techniques.
  • An understanding of various security frameworks and methodologies such as NIST CSF, MITRE ATT&CK and D3FEND, Unified Kill Chain and OWASP Top 10.
  • Basic scripting or automation skills are desirable (for example PowerShell, Bash, Python, or Ruby).
  • SANS GCFA, GCFE, GCIH, or relevant DFIR certifications are desirable.
Why join us here at Datacom?

Datacom is one of Australia and New Zealand’s largest suppliers of Information Technology professional services. We have managed to maintain a dynamic, agile, small business feel that is often diluted in larger organisations of our size. It’s our people that give Datacom its unique culture and energy that you can feel from the moment you meet with us.

  • We care about our people and provide a range of perks such as social events, chill-out spaces, remote working, flexi-hours and professional development courses to name a few.

You’ll have the opportunity to learn, develop your career, connect and bring your true self to work. You will be recognised and valued for your contributions and be able to do your work in a collegial, flat-structured environment.

We operate at the forefront of technology to help Australia and New Zealand’s largest enterprise organisations explore possibilities and solve their greatest challenges, so you will never run out of interesting new challenges and opportunities.

We want Datacom to be an inclusive and welcoming workplace for everyone and take pride in the steps we have taken and continue to take to make our environment fun and friendly, and our people feel supported.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Incident Responder
Senior Cybersecurity Incident Responder

Datacom • Sydney

On-site
AUD 140,000 - 190,000
Social events
Remote working
Flexi-hours
+1
Senior Cybersecurity Incident Responder | Remote & Flexible Hours
Senior Cybersecurity Incident Responder | Remote & Flexible Hours

Datacom • Australia

Hybrid
AUD 140,000 - 190,000
Remote work
Flexi-hours
Professional development
Remote Senior Cybersecurity Incident Responder: DFIR Leader
Remote Senior Cybersecurity Incident Responder: DFIR Leader

Datacom • Sydney

On-site
AUD 140,000 - 190,000
Social events
Remote working
Flexi-hours
+1
Senior Cybersecurity Engineer - Fixed Term
Senior Cybersecurity Engineer - Fixed Term

Datacom • Adelaide

On-site
AUD 120,000 - 170,000
Paid parental leave
Employee Assistance Programme (DataCar
Learning & development opportunities
+1
Senior Cybersecurity Engineer - Fixed Term
Senior Cybersecurity Engineer - Fixed Term

Datacom • City of Brisbane

On-site
AUD 120,000 - 180,000
Senior Cybersecurity Engineer - Fixed Term
Senior Cybersecurity Engineer - Fixed Term

Datacom • Sydney

On-site
AUD 120,000 - 170,000
Paid parental leave
DataCare EAP
Learning & development
+2
Technical Delivery Manager
Technical Delivery Manager

Datacom • Canberra

On-site
AUD 140,000 - 190,000
Social events
Chill‑out spaces
Remote working
+2
Senior Infrastructure Consultant
Senior Infrastructure Consultant

Datacom • Canberra

On-site
AUD 100,000 - 130,000
Social events
Remote working
Flexi-hours
+1
Endpoint Engineering Specialist
Endpoint Engineering Specialist

Datacom • City of Brisbane

Hybrid
AUD 100,000 - 140,000
Social events
Remote working
Flexi-hours
+1
Senior Incident Responder
Senior Incident Responder

Singtel Group • Sydney

Hybrid
AUD 150,000 - 210,000
Competitive remuneration
Flexible hybrid/work arrangement
On-site campus facilities
+2