SOC Analyst Canberra (Remote)
Position Title: SOC Analyst
Role Purpose :
- Triage and Investigation: Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs.
- Endpoint Response: Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR.
- Detection Tuning: Optimise detection rules using KQL and SPL to enhance our proactive defence posture.
- Threat Hunting: Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity.
- Reporting & Mentorship: Produce detailed incident reports for technical and executive stakeholders.
- DLP: Understand data-loss prevention in the context of Security Operations.
- On-call: Participate in paid on-call roster every 3 weeks.
- Experience: 2–4 years in a SOC or high-pressure security operations environment.
- Tooling Expertise: Hands-on proficiency in Splunk, Sentinel, CrowdStrike, and Microsoft Defender. Experience with other SIEM and EDR technologies highly regarded.
- Technical Skills: Strong understanding of TCP/IP, Windows/Linux internals, Cloud Security and common attack vectors (Phishing, Ransomware, Living-off-the-Land).
- Certifications: One or more of the following: SC-200, Splunk Core Certified Power User, CompTIA CySA+, or SANS GCIH.
- Communication: Ability to clearly articulate technical risks to non-technical client stakeholders verbally and/or via email and ticketing system.
Behaviours
- Client-focused with a proactive and solution-oriented mindset.
- High attention to detail and commitment to quality.
- Collaborative and able to work effectively across teams.
- Comfortable managing multiple priorities in a fast-paced environment.
- Curious and eager to learn, with a passion for cybersecurity.
- Professional and confident in client-facing scenarios.
- Focusing on Clients and Customers.
- Working as One NCC.
- Always Learning.
- Being Inclusive and Respectful.
- Delivering Brilliantly.