SOC Analyst (East Coast Australia - Remote)

NCC Group

Canberra

Remote

AUD 110,000 - 140,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NCC Group is seeking a SOC Analyst in Canberra, ACT, Australia to join our Australian SOC team. You will act as the engine room of security operations, leading investigations, hunting threats, and fine‑tuning detections across APAC client environments.

You will work with a world‑class security stack, including Splunk, Sentinel, CrowdStrike, and Defender, with on‑call duties every three weeks and opportunities to mentor junior staff.

Qualifications

  • 2–4 years in a SOC or high‑pressure security operations environment.
  • Hands‑on proficiency in Splunk, Sentinel, CrowdStrike, and Microsoft Defender.
  • Strong understanding of TCP/IP, Windows/Linux internals, Cloud Security.

Responsibilities

  • Triage and Investigation: Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs.
  • Endpoint Response: Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR.
  • Detection Tuning: Optimise detection rules using KQL and SPL to enhance our proactive defence posture.
  • Threat Hunting: Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity.
  • Reporting & Mentorship: Produce detailed incident reports for technical and executive stakeholders.

Skills

Splunk
Sentinel
CrowdStrike
Microsoft Defender
TCP/IP
Windows/Linux internals
Cloud Security
MITRE ATT&CK
Threat Hunting

Tools

Splunk
Microsoft Sentinel
SentinelOne
CrowdStrike Falcon
Microsoft Defender for Endpoint

Job description

Department: Cyber Services and Capabilities


Location: AUS Sydney Clarence Street


Description

Position Title: SOC Analyst


Location: Canberra, ACT - Australia


Role Purpose

Join our Australian SOC team as a SOC Analyst. In this role, you will be the \"engine room\" of our security operations, moving beyond basic alert monitoring to lead deep investigations across a diverse range of client environments in Asia Pacific (APAC). You will work with a world‑class security stack and have the autonomy to hunt for threats and recommend custom detections.


Key Responsibilities


  • Triage and Investigation: Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs.

  • Endpoint Response: Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR.

  • Detection Tuning: Optimise detection rules using KQL and SPL to enhance our proactive defence posture.

  • Threat Hunting: Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity.

  • Reporting & Mentorship: Produce detailed incident reports for technical and executive stakeholders.

  • DLP: Understand data-loss prevention in the context of Security Operations.

  • On‑call: Participate in paid on‑call roster every 3 weeks.


Skills, Knowledge & Expertise

What we are looking for in you



  • Experience: 2–4 years in a SOC or high‑pressure security operations environment.

  • Tooling Expertise: Hands‑on proficiency in Splunk, Sentinel, CrowdStrike, and Microsoft Defender. Experience with other SIEM and EDR technologies highly regarded.

  • Technical Skills: Strong understanding of TCP/IP, Windows/Linux internals, Cloud Security and common attack vectors (Phishing, Ransomware, Living‑off‑the‑Land).

  • Certifications: One or more of the following: SC‑200, Splunk Core Certified Power User, CompTIA CySA+, or SANS GCIH.

  • Communication: Ability to clearly articulate technical risks to non‑technical client stakeholders verbally and/or via email and ticketing system.


Behaviours


  • Client‑focused with a proactive and solution‑oriented mindset.

  • High attention to detail and commitment to quality.

  • Collaborative and able to work effectively across teams.

  • Comfortable managing multiple priorities in a fast‑paced environment.

  • Curious and eager to learn, with a passion for cybersecurity.

  • Professional and confident in client‑facing scenarios.


Ways of working


  • Focusing on Clients and Customers.

  • Working as One NCC.

  • Always Learning.

  • Being Inclusive and Respectful.

  • Delivering Brilliantly.


Our company

At NCC Group, our mission is to create a more secure digital future. That mission underpins everything we do, from our work with our incredible clients to groundbreaking research shaping our industry. Our teams’ partner with clients across a multitude of industries, delving into, securing new products, and emerging technologies, as well as solving complex security problems. As global leaders in cyber and escrow, NCC Group is a people‑powered business seeking the next group of brilliant minds to join our ranks.

Our colleagues are our greatest asset, and NCC Group is committed to providing an inclusive and supportive work environment that fosters creativity, collaboration, authenticity, and accountability. We want colleagues to put down roots at NCC Group, and we offer a comprehensive benefits package, as well as re‑….
We review every application received and will get in touch if your skills and experience match what we’re looking for. If you don’t hear back from us within 10 days, please don’t be too disappointed – we may keep your CV on our database for any future vacancies and we would encourage you to keep an eye on our career opportunities as there may be other suitable roles.
If you do not want us to retain your details, you can utilise the Manage Your Data tool provided by Pinpoint or contact us directly at: global.ta@nccgroup.com. All personal data is held in accordance with the NCC Group Privacy Notice.
We are committed to diversity and flexibility in the workplace. If you require any reasonable adjustments to support you during the application process, please tell us at any stage.


Please note that this role involves mandatory pre-employment background checks due to the nature of the work NCC Group does. To apply, you must be willing and able to undergo the vetting process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst | Threat Hunting & Incident Response
SOC Analyst | Threat Hunting & Incident Response

NCC Group • Canberra

Remote
AUD 110,000 - 140,000
Cyber Defense SOC Analyst – Onsite Sydney, NV1 Eligible
Cyber Defense SOC Analyst – Onsite Sydney, NV1 Eligible

C4I Solutions Pty • Sydney

On-site
AUD 110,000 - 160,000
Long Service Leave
Health & wellbeing allowance
First year leave (5 days)
+6
Defence Cyber SOC Analyst – Onsite Sydney
Defence Cyber SOC Analyst – Onsite Sydney

C4i Solutions • Sydney

On-site
AUD 90,000 - 120,000
Long Service Leave
Health & wellbeing allowance
First year leave (5 days)
+6
Cyber Senior Solutions Architect
Cyber Senior Solutions Architect

NCC Group • Sydney

On-site
AUD 120,000 - 150,000
Superannuation
Annual leave – 20 days
Sick Leave – 10 days
+1
Soc Analyst | Threat Hunting & Incident Response
Soc Analyst | Threat Hunting & Incident Response

Ncc Group • Townsville City

On-site
AUD 90,000 - 130,000
SOC Threat Hunter & Incident Response Analyst – On-Call APAC
SOC Threat Hunter & Incident Response Analyst – On-Call APAC

Ncc Group • Townsville City

On-site
AUD 90,000 - 130,000
Cyber Security SOC Analyst
Cyber Security SOC Analyst

C4I Solutions Pty • Sydney

On-site
AUD 110,000 - 160,000
Long Service Leave
Health & wellbeing allowance
First year leave (5 days)
+6
Senior Cyber Threat Hunt Specialist
Senior Cyber Threat Hunt Specialist

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1
SOC Analyst - Team Lead
SOC Analyst - Team Lead

Anson McCade • Sydney

Hybrid
AUD 90,000 - 130,000
Senior Threat Hunt & Emulation Lead (SOC, Govt)
Senior Threat Hunt & Emulation Lead (SOC, Govt)

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1