Skip to main content

Information Security Operations Lead

On-siteFull timeSenior

Sydney, New South Wales, Australia · Posted 3 days ago

  • Lead a team of subject matter experts and analysts to ensure Information Security is managed and continuously improved in line with Bank policy and procedure.
  • Supporting the development and progression of the Information Security Analyst team from both a technical and professional perspective.
  • Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include:
    • Cloud Infrastructure/Security.
    • Endpoint Detection and Response.
    • Perimeter detection tooling.
  • Conduct Quality Assurance for Triage case handling, mitigation actions and shift handover, collating lessons learned and implementing improvements where required.
  • Interpret logs from a variety of sources (e.g. cloud, endpoint, network) to identify root cause and determine next steps for containment, eradication and recovery as part of incident response activities.
  • Work together with other teams in the organisation to analyse, contain, eradicate and recover from cyber security incidents
  • Continuous development and maintaining of incident handling, response and readiness processes.
  • Support the wider SecOps team with detection engineering - creating and optimising analytic triggers to enhance alert efficacy - and threat hunting based on threat intelligence.
  • Documentation of incidents and investigations, including analysis findings, containment steps and root cause.
  • Plan and participate in Tabletop Exercises.
  • Present investigation findings to technical and non-technical audiences.

Requirements

  • 5+ years experience in an in-house SOC role and team, including cyber incident response and digital forensics function.
  • Experience in a similar role leading, developing and motivating a team of subject matter experts and other managers in Information & Cyber Security.
  • Understanding of AWS Security Solutions (or other Public Cloud Solutions)
  • Analysis and Incident Response experience with Cloud systems (GCP, AWS)
  • Experience working and supporting analytics/SIEM platforms.
  • Experience supporting and conducting Incident Response engagements.
  • Experience in endpoint based investigations.
  • Experience in cloud based investigations.
  • Experience with Incident Command and conducting Tabletop Exercises.
  • Experience in acting as both Commander and SME during incidents and investigations.
  • Be a Self Starter with the ability to lead, inspire and drive change through an organisation.
  • Excellent communication skills (both verbal and written), ability to communicate technical concepts to both technical and non-technical audiences.
  • Demonstrated teamwork and collaboration skills as part of a multi-functional team
  • Time management, problem-solving and interpersonal skills.
  • Eagerness to learn and apply knowledge to new security challenges.
  • Willingness to share knowledge with the team and mentor colleagues.
  • - A high level understanding of mobile, network and operating system security controls.
  • Preferred
  • Experience in forensics: cloud (GCP, AWS); endpoint/server (Windows, MacOS, Linux); and/or network.
  • Any experience of programming in Python, Go and/or Java.
  • A Cyber/Information Security related degree and/or relevant cyber security qualification(s) would be desired but not required
  • Understanding of malware analysis techniques

Core Competencies

Demonstrates expertise in Incident Response, Cyber Security, and Team Leadership, with a strong focus on developing and mentoring teams while managing security incidents effectively. Proficient in utilizing Cloud Security Solutions and analytics platforms to enhance security posture and incident handling processes.

Highest-signal resume keywords

  • Incident Response Management
  • Cloud Security Solutions (AWS, GCP)
  • Team Leadership and Development
  • Analytic/SIEM Platform Support
  • Digital Forensics Expertise

ATS Optimization Keywords

Hard Skills

  • Incident Triage
  • Cloud Systems Analysis
  • Endpoint Investigation
  • Malware Analysis Techniques
  • Programming (Python, Go, Java)

Soft Skills

  • Excellent Communication Skills
  • Teamwork and Collaboration
  • Time Management
  • Problem-Solving
  • Interpersonal Skills

Certifications & Qualifications

  • Cyber/Information Security Degree
  • Relevant Cyber Security Qualifications

Industry Keywords

  • Information Security
  • Cyber Security
  • Digital Forensics
  • Incident Command
  • Tabletop Exercises

Tools & Technologies

  • Cloud Infrastructure Security
  • Endpoint Detection and Response
  • Perimeter Detection Tooling
  • SIEM Platforms
  • Incident Command Systems
#J-18808-Ljbffr
Locations
Sydney, New South Wales, Australia
Experience
5+ years

Categories

Skills

We use cookies

We use cookies to understand how this board is used and to improve it. Analytics run only if you accept. Cookie Policy