Staff Incident Response Commander

Cox Purtell

Sydney

On-site

AUD 180,000 - 240,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cox Purtell is seeking a senior incident commander for a 12-month Sydney contract with a global software company. You will lead the most complex security incidents from first alert to closure while performing the forensic investigation yourself across web applications, APIs, containers and multi-cloud infrastructure.

Join a cyber defence centre that values sound judgement, technical depth and mentoring, and help shape incident response processes, tooling and exercises while briefing senior

Qualifications

  • Extensive front-line incident response and digital forensics experience across many major incidents.
  • Hands-on investigation of web applications, APIs, cloud and container compromises.
  • Experience with cloud-native forensics across Kubernetes, AWS and GCP.
  • Willingness to join on-call rotation and respond to critical events.

Responsibilities

  • Command complex security incidents across the full response lifecycle with coordination of internal and external teams.
  • Personally investigate web apps, APIs, cloud and container compromises and credential/data-exposure scenarios.
  • Collect, preserve and analyse forensic evidence across hosts, networks and cloud platforms.
  • Brief senior leadership under pressure and drive remediation across teams and organisations.
  • Build tooling for evidence collection at scale and lead training and mentoring for responders.

Skills

Incident response
Digital forensics
Leadership
Cloud incident response

Tools

Kubernetes
AWS
GCP
CrowdStrike Falcon

Job description


  • 12-month Sydney contract with a global software company

  • Hands-on forensics across Kubernetes, AWS and GCP

  • Senior IC role shaping process, tooling and mentoring


About the client

Our client is a global software and digital media company whose products are used by individuals and enterprises around the world. It’s cyber defence centre protects the company’s products, platforms and customers, working closely with engineering, product and partner teams. The incident response team handles serious, high-visibility security events across modern cloud and application environments. It is a team that values sound judgement, composure and genuine technical depth.


About the role

This is one of the most senior incident command roles in the team, and it stays hands-on. You will lead the most complex security incidents from first alert to closure while doing the forensic investigation yourself, across web applications, APIs, containers and multi-cloud infrastructure. You will bring order to incidents that span many internal teams and external partners, and move comfortably between deep technical analysis and clear briefings for senior leadership. Beyond live incidents, you will help shape how the team responds through better process, tooling, exercises and mentoring.


Duties


  • Command complex security incidents across the full response lifecycle, coordinating internal teams, external partners and their security operations centres.

  • Personally investigate web application, API, cloud and container compromises, including credential and data-exposure scenarios.

  • Collect, preserve and analyse forensic evidence across hosts, networks, cloud platforms and large log sources, keeping defensible records throughout.

  • Brief senior leadership clearly under pressure, and assign and drive remediation across multiple teams and organisations.

  • Build tooling for evidence collection at scale, and lead retrospectives, tabletop exercises, training and mentoring for responders and commanders.


Requirements


  • Extensive front-line incident response and digital forensics experience across many major incidents, with proven command of the full incident lifecycle.

  • Hands-on investigation of web application and API compromises, such as broken access control, authentication and authorisation bypass, IDOR, API abuse and CMS exploitation.

  • Cloud-native and container forensics, including Kubernetes and ephemer infrastructure, with strong AWS and GCP experience across logging, identity and authorisation models.

  • Deep host and network forensics, including Linux internals and Windows and macOS artefacts.

  • EDR at scale (for example CrowdStrike Falcon), complex SIEM analytics, and log and data analysis across large platforms and data warehouses.

  • Scripting in Bash and at least one interpreted language, such as Python.

  • Working knowledge of ISO 27001, SOC 2, HIPAA, GDPR and PCI.

  • Willingness to join an on‑call rotation and respond to critical events.

  • Highly regarded: Azure, malware triage and reverse engineering, GCFA, GCIH, GNFA or cloud security certifications, and a government or law‑enforcement investigation background.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Global Security Operations Manager
Global Security Operations Manager

Interface Agency Australia • Sydney

Hybrid
AUD 180,000 - 280,000
Lead Incident Response Commander (Cloud & Forensics)
Lead Incident Response Commander (Cloud & Forensics)

Cox Purtell • Sydney

On-site
AUD 180,000 - 240,000
Digital Forensics (DFIR) / Incident Response Analyst
Digital Forensics (DFIR) / Incident Response Analyst

Check Point Software Technologies • Sydney

On-site
AUD 140,000 - 190,000
Intermediate Security Engineer, Security Incident Response Team (SIRT)
Intermediate Security Engineer, Security Incident Response Team (SIRT)

Jobgether • Australia

On-site
AUD 110,000 - 160,000
Remote work in Australia
4-day work week
Flexible PTO
+1
Senior Cyber Security Analyst
Senior Cyber Security Analyst

RGIT Australia • Sydney

On-site
AUD 180,000 - 240,000
Digital Forensic and Incident Response Investigator
Digital Forensic and Incident Response Investigator

Forensic Focus Limited • City of Melbourne

On-site
AUD 90,000 - 130,000
Senior Cybersecurity Incident Coordinator
Senior Cybersecurity Incident Coordinator

Everi Pty • Sydney

On-site
AUD 180,000 - 240,000
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
Incident Response Sr. Consultant
Incident Response Sr. Consultant

Forensic Focus Limited • Sydney

On-site
AUD 140,000 - 200,000
Senior Incident Commander & Digital Forensics Lead
Senior Incident Commander & Digital Forensics Lead

Forensic Focus Limited • Sydney

On-site
AUD 140,000 - 170,000