Intermediate Security Engineer, Security Incident Response Team (SIRT)
Summary
An Intermediate Security Engineer joins a globally distributed Security Operations (SIRT) team to detect, investigate, and respond to security incidents in a 24/7 rotation, using SIEM, logging, and automation tooling across GCP/AWS cloud environments. The role is remote within Australia on a compressed four-day, Sunday-Wednesday schedule.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Intermediate Security Engineer, Security Incident Response Team (SIRT) based in Australia.
This role places you at the frontline of protecting critical cloud infrastructure and sensitive user data from evolving security threats. You’ll join a globally distributed Security Operations environment responsible for detecting, investigating, and responding to incidents around the clock. Working on a compressed four-day schedule, you’ll gain hands-on experience managing real-world security events from detection through recovery. You’ll use security monitoring, logging, and automation tools to strengthen incident response capabilities and operational efficiency. The role also offers opportunities to improve security processes, develop detection capabilities, and contribute to technical projects. With mentorship and cross-regional collaboration, you’ll build both tactical incident response expertise and strategic security thinking.
Accountabilities:
You’ll play an active role in security incident response while helping strengthen the processes, automation, and capabilities that support a resilient security operation.
- Lead security incident response activities within a 24/7 global rotation, from initial detection through containment and recovery.
- Investigate and analyze security events using security monitoring, logging, and incident response tools.
- Create, maintain, and improve incident response documentation, including runbooks and standard operating procedures.
- Conduct root cause analysis and post-incident reviews to identify lessons learned and strengthen future response.
- Design and implement automated security processes that improve operational efficiency and reduce manual intervention.
- Identify security gaps and implement improvements to detection and response capabilities.
- Collaborate with engineering and other internal teams on technical projects that enhance security infrastructure and capabilities.
- Contribute to proactive security measures by identifying emerging threats and opportunities to improve defensive controls.
- Demonstrated ability to learn and independently lead security incident response processes.
- Experience working with SIEM platforms and security logging tools.
- Experience with cloud environments, particularly GCP and/or AWS.
- Python programming skills or a strong willingness and ability to develop them.
- Strong technical writing and documentation skills, with a genuine interest in maintaining clear operational documentation.
- A proactive and investigative mindset when identifying and analyzing security threats.
- Interest or experience in forensic analysis of compromised or infected hosts.
- Experience with, or a strong desire to learn, cloud-based security investigations.
- Ability to remain calm and analytical in high-pressure situations while following established procedures and runbooks.
- Strong collaboration skills and the ability to work effectively across geographically distributed teams.
- Remote work opportunity in Australia.
- Compressed four-day work schedule, with full-time hours distributed across four longer days.
- Sunday–Wednesday shifts supporting 24/7/365 security coverage.
- Flexible paid time off.
- Benefits designed to support health, finances, and overall well-being.
- Equity compensation and employee stock purchase plan.
- Growth and development fund.
- Parental leave.
- Access to team member resource groups and an inclusive, globally distributed working environment.
- Opportunities for mentorship, continuous learning, and collaboration with security professionals across multiple regions.
Requirements:
You’ll be well suited to this role if you have a solid foundation in security operations and incident response, combined with curiosity, analytical thinking, and a willingness to deepen your technical expertise.
Benefits:
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company
