NCC Group Logo

NCC Group

SOC Analyst (East Coast Australia - Remote)

Reposted 22 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Clarence City, Tasmania
Mid level
In-Office or Remote
Hiring Remotely in Clarence City, Tasmania
Mid level
Investigate and triage complex security alerts using Splunk, Microsoft Sentinel and SentinelOne; perform endpoint containment with CrowdStrike and Microsoft Defender; tune detections with KQL and SPL; conduct MITRE ATT&CK-based threat hunting; produce incident reports; understand DLP; participate in paid on-call roster every three weeks.
The summary above was generated by AI

Position Title: SOC Analyst
Location: Canberra, ACT - Australia 

Role Purpose :
Join our Australian SOC team as a SOC Analyst. In this role, you will be the "engine room" of our security operations, moving beyond basic alert monitoring to lead deep investigations across a diverse range of client environments in Asia Pacific (APAC). You will work with a world-class security stack and have the autonomy to hunt for threats and recommend custom detections.
 

Key Responsibilities
Summary 

  • Triage and Investigation: Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs. 
  • Endpoint Response: Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR. 
  • Detection Tuning: Optimise detection rules using KQL and SPL to enhance our proactive defence posture. 
  • Threat Hunting: Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity. 
  • Reporting & Mentorship: Produce detailed incident reports for technical and executive stakeholders. 
  • DLP: Understand data-loss prevention in the context of Security Operations. 
  • On-call: Participate in paid on-call roster every 3 weeks. 


Skills, Knowledge & Expertise
What we are looking for in you 
  • Experience: 2–4 years in a SOC or high-pressure security operations environment. 
  • Tooling Expertise: Hands-on proficiency in Splunk, Sentinel, CrowdStrike, and Microsoft Defender. Experience with other SIEM and EDR technologies highly regarded. 
  • Technical Skills: Strong understanding of TCP/IP, Windows/Linux internals, Cloud Security and common attack vectors (Phishing, Ransomware, Living-off-the-Land). 
  • Certifications: One or more of the following: SC-200, Splunk Core Certified Power User, CompTIA CySA+, or SANS GCIH. 
  • Communication: Ability to clearly articulate technical risks to non-technical client stakeholders verbally and/or via email and ticketing system. 

Job Benefits

Behaviours
 
  • Client-focused with a proactive and solution-oriented mindset. 
  • High attention to detail and commitment to quality. 
  • Collaborative and able to work effectively across teams. 
  • Comfortable managing multiple priorities in a fast-paced environment. 
  • Curious and eager to learn, with a passion for cybersecurity. 
  • Professional and confident in client-facing scenarios. 
Ways of working 

  • Focusing on Clients and Customers.  
  • Working as One NCC.
  • Always Learning.
  • Being Inclusive and Respectful. 
  • Delivering Brilliantly.  
Our company 

At NCC Group, our mission is to create a more secure digital future. That mission underpins everything we do, from our work with our incredible clients to groundbreaking research shaping our industry. Our teams' partner with clients across a multitude of industries, delving into, securing new products, and emerging technologies, as well as solving complex security problems. As global leaders in cyber and escrow, NCC Group is a people-powered business seeking the next group of brilliant minds to join our ranks.   
Our colleagues are our greatest asset, and NCC Group is committed to providing an inclusive and supportive work environment that fosters creativity, collaboration, authenticity, and accountability. We want colleagues to put down roots at NCC Group, and we offer a comprehensive benefits package, as well as opportunities for learning and development and career growth. We believe our people are at their brilliant best when they feel bolstered in all aspects of their well-being, and we offer wellness programs and flexible working arrangements to provide that vital support. 
Come join us?

About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.

NCC Group Sydney, New South Wales, AUS Office

Level 13 92 Pitt Street Sydney 2000 Australia, Sydney, Australia

Similar Jobs

3 Days Ago
Remote
Australia
Senior level
Senior level
Productivity • Software • App development • Automation
Manage and close enterprise B2B software license opportunities across Australia and New Zealand. Responsibilities include qualifying leads, managing the full sales cycle, identifying customer needs through consultative selling, collaborating with solution engineers, presenting competitive value, researching markets and prospects, and achieving sales quotas. The role requires engaging business and technical executives, including CTOs and product or engineering leaders, while maintaining pipeline activity in a CRM.
Top Skills: CRMDocument Processing SdksmacOSWindows
6 Days Ago
Easy Apply
Remote
Australia
Easy Apply
Junior
Junior
Information Technology • Cybersecurity
Triage, investigate, respond to, and remediate security alerts and hands-on intrusions. Analyze EDR and SIEM telemetry, logs, forensic artifacts, malware, and activity in Microsoft 365 and Google Workspace. Identify root causes, extract indicators of compromise, tune detections, and provide actionable remediation. Support customer escalations and collaborate with Product and Engineering to improve MDR workflows, while contributing to incident response, threat hunting, and detection engineering.
Top Skills: Active DirectoryEdrGoogle WorkspaceGroup PolicyLinuxmacOSMicrosoft 365Mitre Att&CkNatPowershellSIEMVlansWindows
7 Days Ago
Remote
Australia
Expert/Leader
Expert/Leader
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
Sets global cloud architecture standards, serves as the senior technical escalation point for strategic multi-cloud engagements, and advises executive customers. Leads complex architecture workshops, develops reference architectures and automation, mentors architects, influences product roadmaps, and improves professional services scoping and delivery. Requires deep AWS and Azure expertise, strong cloud security, data protection, automation, and enterprise architecture experience, with occasional travel.
Top Skills: AWSAws CloudformationAzure BicepCi/CdGoogle Cloud Platform (Gcp)KubernetesMicrosoft 365AzurePowershellPythonSalesforceTerraform

What you need to know about the Sydney Tech Scene

From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account