The global specialist risk consultancy - Helping organisations succeed in a volatile world
Cyber Detection and Response Analyst
Location
Australia
Posted
7 days ago
Salary
0
Seniority
Mid Level
Job Description
Cyber Detection and Response Analyst
Control Risks
Role Description The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands-on technical role focused on identifying, analyzing, and responding to cyber threats across the client’s environment, working closely with Security Engineering and broader security stakeholders. This role will be a part of a global 24/7 team and will cover one of two shifts: Sunday-Thursday 08:00-16:00 or Tuesday-Saturday 08:00-16:00. This role will likely commence employment in October 2026. - Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems. - Support incident response activities including analysis, containment, remediation, and documentation. - Execute established incident response playbooks and contribute to their continuous improvement. - Perform threat hunting activities to identify potential compromises and gaps in detection coverage. - Leverage threat intelligence to inform investigations and detection tuning. - Collaborate with Security Engineering to tune detection logic and improve security controls. - Produce clear, concise incident reports and support root cause analysis and remediation efforts. - Support on-call rotations and escalation processes as part of a 24/7 detection and response capability. Qualifications - 3–5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense. - Hands-on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike). - Practical understanding of incident response methodologies and frameworks such as MITRE ATT&CK and NIST. - Familiarity with threat hunting, malware analysis, or forensic investigation techniques. - Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred. - Strong analytical and problem-solving skills, with the ability to communicate technical findings clearly. - Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus. - Candidates will need to be based in Australia and hold permanent work rights.
Related Guides
Related Categories
Related Job Pages
More Incident Response Analyst Jobs
Fraud Incident Response Lead
TalentgratorAn international company operating in the iGaming industry, focused on building scalable operational processes and supporting business growth across multiple markets. The company works with high-volume financial flows, payment infrastructure, and partner operations, ensuring stability, security, and efficiency across all internal processes. With a strong focus on risk control, fraud prevention, and operational optimization, the team continuously improves internal systems and business processes.
Role Description Основная задача роли — обеспечить эффективное управление fraud-инцидентами от момента обнаружения до полного закрытия. Помимо координации расследований, специалист будет анализировать причины возникновения инцидентов, улучшать процессы реагирования, внедрять новые процедуры и снижать вероятность повторения подобных случаев. - Координировать расследование fraud-инцидентов от обнаружения до полного закрытия. - Организовывать работу Product, Development, Payments, Risk, Compliance, Support, Account Management, Legal и других команд. - Определять приоритет и критичность инцидентов. - Проводить первичный анализ и контролировать ход расследований. - Выполнять Root Cause Analysis (RCA) и разрабатывать корректирующие мероприятия (CAPA). - Развивать процессы, регламенты и playbook'и реагирования на fraud-инциденты. - Анализировать новые мошеннические схемы и предлагать меры защиты. - Контролировать соблюдение SLA и готовить регулярную отчетность для руководства. Qualifications - Опыт работы в Fraud, Risk, Incident Management, Payments или Compliance от 3 лет. - Опыт координации сложных кросс-функциональных расследований. - Понимание современных схем онлайн-мошенничества и методов их предотвращения. - Опыт проведения Root Cause Analysis и внедрения улучшений. - Сильные аналитические навыки и умение принимать решения в условиях высокой неопределенности. - Английский язык от Upper-Intermediate. Requirements - Опыт работы в iGaming, FinTech, платежных системах или других high-risk индустриях. - Знание процессов KYC, AML, Chargeback и платежной инфраструктуры. Benefits - Конкурентное вознаграждение. - Полностью удаленный формат работы. - Возможность выстроить новое стратегически важное направление. - Работу в международной продуктовой компании. - Влияние на ключевые бизнес-процессы и принятие решений. - Возможности профессионального роста и развития.
• Investigate and respond to complex security incidents throughout the entire incident lifecycle • Perform digital forensic investigations, malware analysis, and evidence collection to determine the scope and root cause of security incidents • Analyze attack techniques, correlate security events, and reconstruct attack timelines • Develop and improve SIEM detections, correlation rules, and incident response playbooks • Conduct threat hunting activities and reduce false positives through detection tuning • Automate repetitive SOC activities using scripting where appropriate • Collaborate with Infrastructure, Development, IT, and Security teams during incident response • Mentor L1 analysts by providing technical guidance and feedback
• Serve as the lead responder during critical incidents. • Unify analysts, infrastructure, application owners, legal, and third-party partners. • Be a trusted voice during high-severity events. • Lead advanced investigations into malware, identity compromise, and ransomware. • Help modernize SOC with automation and AI-assisted tooling. • Raise the standard of team responses through meaningful after-action reviews.
Principal Incident Response Analyst
Centene CorporationTransforming the health of the communities we serve, one person at a time.
• Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security • Partners with business units to accomplish enterprise-wide remediation • Develops and delivers presentations to senior leadership team • Keeps abreast of security breaches and ensures incident and response management processes are initiated • Implements security service audit schedules, reviews access authorization, and performs access controls testing • Collaborates with Information Security Architects and software or hardware stakeholders • Ties third party attack monitoring services into internal CIRT communications systems



