Monitor, triage, investigate, and respond to security alerts across endpoint, network, cloud, and identity. Execute incident response playbooks, perform threat hunting, leverage threat intelligence, and collaborate with Security Engineering to improve detections. Produce incident reports, support root cause analysis, and participate in 24/7 on-call rotations and shift coverage.
The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands-on technical role focused on identifying, analyzing, and responding to cyber threats across the client’s environment, working closely with Security Engineering and broader security stakeholders.
This role will be a part of a global 24/7 team and will cover one of two shifts: Sunday-Thursday 08:00-16:00 or Tuesday-Saturday 08:00-16:00. This role will likely commence employment in October 2026.
Responsibilities:
- Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems.
- Support incident response activities including analysis, containment, remediation, and documentation.
- Execute established incident response playbooks and contribute to their continuous improvement.
- Perform threat hunting activities to identify potential compromises and gaps in detection coverage.
- Leverage threat intelligence to inform investigations and detection tuning.
- Collaborate with Security Engineering to tune detection logic and improve security controls.
- Produce clear, concise incident reports and support root cause analysis and remediation efforts.
- Support on-call rotations and escalation processes as part of a 24/7 detection and response capability.
Requirements
- 3–5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense.
- Hands-on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike).
- Practical understanding of incident response methodologies and frameworks such as MITRE ATT&CK and NIST.
- Familiarity with threat hunting, malware analysis, or forensic investigation techniques.
- Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred.
- Strong analytical and problem-solving skills, with the ability to communicate technical findings clearly.
- Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus.
- Candidates will need to be be based in Australia and hold permanent work rights.
Similar Jobs
Information Technology • Software • Financial Services • Quantitative Trading
Software Engineers at Citadel develop, maintain, and support high-performance trading platforms, focusing on custom software solutions and system stability.
Top Skills:
C++
Cloud • Information Technology • Security • Software • Cybersecurity
Act as a quota-bearing technical trusted advisor for enterprise customers: lead technical discovery, design bespoke architectures, deliver demos/PoCs across security, networking, Zero Trust and developer platforms, drive adoption/expansion, run technical QBRs, and leverage AI-augmented workflows to automate routine tasks.
Top Skills:
AuthenticationAWSAzureBashBgpCdnCloudflare Ai GatewayCloudflare Workers AiDdos MitigationDlpDnsEssential EightFirewallsForward ProxyGCPGdprGoGreHipaaHTTPIdentity ManagementIpv4Ipv6IrapIso/IecJavaScriptLlmMplsPci DssPrompt EngineeringPythonRagReverse ProxySaseSd-WanSecure Web GatewayServerlessSoc-2TcpTlsTraffic ManagementUdpVpnWafZtna
HR Tech • Information Technology • Professional Services • Sales • Software
Manage the full sales cycle for APJ: prospect and build pipeline, qualify multi-stakeholder mid-market opportunities, deliver product demos, engage CPOs and People leaders, use MEDDIC/MEDDPICC, maintain Salesforce CRM, forecast and hit targets, and close six-figure deals. Represent the company at events and build partner relationships.
Top Skills:
MeddicMeddpiccSalesforce
What you need to know about the Sydney Tech Scene
From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.



