freehire launches on Product Hunt on 26 August.

Follow →

Cybersecurity SOC Analyst

Summary

Monitor and triage security alerts across SIEM/SOAR tools, investigate threats, and escalate incidents in a government-focused SOC role.

The Cyber Security SOC Monitoring Analyst is responsible for the continuous monitoring, detection, analysis, and triage of security events across enterprise systems, applications, and cloud environments. The role provides expertise in threat detection, incident escalation, vulnerability identification, and secure application practices. Operating within a Distributed Security Operations Centre (DSOC), the position ensures timely response to cyber threats and supports ongoing improvement of the organisation’s security posture.

Key Responsibilities

Monitor, analyse, and triage security events, alerts, and incidents detected through SIEM, SOAR, endpoint protection, and cloud security tools.

• Investigate suspicious activity across applications, networks, identities, and cloud environments to determine severity and potential impact.

• Escalate verified security incidents to senior analysts and incident response teams, providing detailed analysis and recommended actions.

Conduct initial forensic data gathering to support incident investigation and containment activities.

• Monitor application security events and work with application teams to identify vulnerabilities, misconfigurations, and emerging threats.

• Support the development, tuning, and optimisation of detection use cases, SIEM rules, and automation workflows.

• Assist in vulnerability assessment activities by analysing vulnerability reports, validating findings, and tracking remediation progress.

• Contribute to threat intelligence enrichment and ensure relevant threat indicators are incorporated into monitoring platforms.

• Maintain security monitoring documentation, runbooks, dashboards, and incident records.

• Participate in continuous improvement of DSOC processes, detection capabilities, and response maturity.

• Support compliance with security policies, standards, and regulatory requirements.

Required Skills and Experience

Experience in security monitoring, incident triage, or SOC operations in enterprise or government environments.

• Strong understanding of application security concepts, common vulnerabilities (e.g., OWASP Top 10), and secure development practices.

• Hands‑on experience with SIEM tools such as Microsoft Sentinel, Splunk, QRadar, or equivalent.

• Familiarity with SOAR platforms, EDR/XDR technologies, threat intelligence tools, and cloud security controls.

• Ability to analyse logs, alerts, and telemetry across applications, endpoints, networks, and cloud platforms.

• Understanding of security frameworks and standards such as ASD Essential Eight, ISO 27001, and NIST.

• Strong analytical and problem‑solving skills with the ability to make sound judgements during security events.

• Effective communication skills and the ability to collaborate with security, operations, and application teams.

• Required Australian Citizenship and Mandatory AGSVA NV1 Clearance.

• Must be able to work 5 days from client site in Canberra.

WHO WE ARE
Kirra Services is a leading provider of IT services and recruitment personnel, headquartered in Canberra, ACT. Award-winning winners of the Seek SARA 2025 Small Recruitment Company of the Year, we partner closely with a range of Federal Government agencies and are continuously seeking talented professionals to join our growing team.

Kirra Services is proudly SupplyNation Certified and majority Indigenous-owned. We are committed to creating opportunities for all Australians and strongly encourage Aboriginal and Torres Strait Islander candidates to apply for all roles.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available