Point your AI agent at freehire and let it find you a job.

Get the CLI →

Australian Secret Intelligence Service

NewBe an early applicant

Cyber Security Operations Technical Lead EL1

Posted 1 view
Discussion

Summary

A senior (EL1) role leading cyber incident response, technical investigations, and threat hunting for ASIS's ICT environment, including building detection engineering and SIEM capabilities and mentoring cyber operations staff. Core technologies include SIEM platforms, data analytics, and query/coding languages such as SQL, SPL, Python, and PowerShell.

Salary: $150,072 - $175,338 plus 15.4% Superannuation

In this senior position, you will lead cyber incident response activities and technical investigations, driving efforts to quickly identify, contain, and eradicate threats to ASIS. From directing complex incident response operations to implementing detection engineering and intelligence capabilities, your work will directly shape our ability to protect the confidentiality, integrity, and availability of ASIS's systems and sensitive data.

Role responsibilities

  • Lead the monitoring, detection, and response to cyber activity impacting ASIS's ICT environment, ensuring the confidentiality, integrity, and availability of critical systems and data
  • Lead technical investigations including analysis of security event logs, network traffic and system activity to identify, understand, respond and prevent cyber security incidents
  • Drive the development and implementation of detection engineering and intelligence capabilities, designing advanced dashboards, use cases, and threat detection mechanisms to uplift ASIS’s cyber security
  • Lead proactive cyber threat hunting activities using SIEM platforms, data analytics, and intelligence to proactively detect malicious activity on ASIS’s ICT systems
  • Proactively identify capability and coverage gaps across the ICT environment, managing strategic remediation activities and leveraging data holdings to provide actionable insights and support complex investigations
  • Provide technical leadership, mentorship, and coaching to cyber operations staff, managing workflows, setting operational priorities, and driving continuous improvement in tradecraft and incident response methodologies

Core skills

We encourage applicants with the following skills and attributes to apply:

  • Extensive experience in leading complex incident response, technical investigations, and risk management
  • Applied understanding of Australian Government cyber security frameworks, including the Protective Security Policy Framework (PSPF) and Information Security Manual (ISM), with the ability to translate these into technical security controls and operational strategies.
  • Advanced expertise in cyber security capabilities and tooling, including architecting and optimizing SIEM platforms, leading detection engineering efforts, and leveraging query/coding languages (e.g., SQL, SPL, Python, PowerShell) to automate and enhance threat detection.
  • Broad and deep technical knowledge across multiple technology domains (such as infrastructure, virtualisation, cloud, data analytics, or software development) to understand complex enterprise architectures and identify systemic threats.
  • Proven technical leadership capabilities, demonstrating high-level judgment, strategic thinking, and the ability to work autonomously to solve complex problems, manage operational workflows, and uplift team capabilities.
  • Exceptional communication and stakeholder engagement skills, with the ability to provide authoritative technical advice, brief senior stakeholders, articulate cyber best practices, and manage highly sensitive operational issues.

Education and qualification requirements

The following education, qualifications and/or experience will be highly regarded:

  • Extensive experience leading cyber security operations, including the monitoring, detection, and response to sophisticated malicious cyber activity
  • Advanced expertise in Security Information and Event Management (SIEM) software, data analytics platforms, and query/coding languages (e.g., SPL, SQL, Python, PowerShell) to drive detection engineering and automation
  • Proven experience leading technical components of complex incident response activities, which might also include digital forensics or malware analysis.
  • Professional certifications along with demonstrated application of knowledge are highly regarded
  • Bachelor's degree in Cyber Security, Computer Science, or Information Technology (not essential)
  • 5+ years of experience in a cyber security operations or analyst role, with demonstrated technical leadership experience preferably within an enterprise or government environment

To be eligible for a role you must:

  • Be an Australian citizen
  • Be assessed as suitable to hold and maintain a TOP SECRET-Privileged Access security clearance
  • For more information on eligibility please see the Protective Security Policy Framework which is publicly accessible at protectivesecurity.gov.au, section 12 provides information on Eligibility and suitability

Skills

What Lead Security jobs ask for — and how much of it you have →
Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available