CTIR - Cyber Threat Response Analyst (Adversary Operations)
Summary
The Cyber Threat Response Analyst performs hypothesis-driven threat hunting and threat modeling to identify security gaps and improve defensive posture within a global financial services organization. The role utilizes tools like EDR, SIEM, and threat intelligence frameworks to detect and mitigate adversarial TTPs.
Salary: $200k - $230k plus bonus on top
The OpportunityJoin a diverse, global Cyber Threat and Incident Response team within the Cyber Security function of a global financial services organisation's Technology division. This role is based in Sydney within the Cyber Threat Defense team.
What You'll Do
- Perform hypothesis-driven threat hunting, combining behavioral threat intelligence, controls-based research, and defensive cyber expertise to improve overall cybersecurity posture
- Conduct proactive, intelligence-driven threat hunting across a global environment using attacker TTPs, behavioral analytics, and large-scale telemetry (EDR, SIEM, TIP)
- Perform threat modeling and execute structured, hypothesis-driven hunts to uncover previously undetected threats
- Identify detective and preventative control gaps and translate findings into actionable improvements
- Collaborate closely with Security Operations and Detection Engineering teams
- Apply frameworks such as MITRE ATT&CK and MITRE ATLAS operationally, while maintaining a continuous learning mindset around adversarial techniques and AI-driven tooling
- Experience in aggregate log analysis (Splunk, Google SecOps, or similar) and with an Endpoint Detection and Response platform
- Ability to translate technical findings into actionable insights and communicate clearly with both technical and non-technical stakeholders
- Offensive security/adversarial mindset with strong knowledge of threat actor TTPs
- Experience threat hunting in enterprise infrastructure, including Windows/Linux systems, Active Directory, cloud platforms, and identity systems
- Minimum 4 years' related security or technology experience in enterprise environments, with a focus on threat hunting, security operations, or penetration testing