Senior Security Operations Specialist

Estimated start date: Monday, 28 September 2026

Initial contract duration: 12 months

Extension term: 12 months

Number of extensions: 2

Experience level: APS6 equivalent

Location of work: QLD, WA, ACT, VIC, NSW, NT, SA, TAS

Working arrangements: Hybrid

Maximum hours: 40 hours per week

Security clearance: Must be able to obtain NV1

Job details

Join our Cyber Security team as a Senior Security Operations Specialist. This is a hands-on technical role focused on monitoring, detecting, and responding to cyber threats using platforms such as Microsoft Sentinel and Defender, while helping strengthen the security posture of our cloud-hosted solutions. Reporting to the Cyber Security Lead, you'll play a key role in both the planning/design and operational phases of our security capability. This role operates on a hybrid basis, requiring a minimum of two (2) days per week in the office, with in-office days to be agreed with your supervising manager.

Key duties and responsibilities

Senior Security Operations Specialist will be required to: 

  • Security Monitoring & Detection Engineering: Configure, manage and optimise security monitoring platforms including development and tuning of analytics rules, dashboards and alerting use cases to detect malicious activity.

  • Incident Response: Lead and support the response to cyber security incidents, including investigation, containment, eradication and recovery. Conduct root cause analysis and implement remediation actions to prevent recurrence.

  • Security Operations & Investigation: Perform detailed analysis of security events, logs and alerts across cloud and enterprise environments. Triage and prioritise incidents based on risk and business impact.

  • Security Automation & Orchestration: Develop and maintain automation playbooks and scripts to improve response times and reduce manual effort in security operations.

  • Vulnerability Management: Identify, assess and prioritise vulnerabilities across systems, applications and infrastructure. Work with DevOps and development teams to ensure timely remediation.

  • Security Tool Management: Configure, maintain and optimise security tools and platforms, identifying opportunities for improvement, integration and automation.

  • Threat Intelligence & Use Case Development: Manage and utilise threat intelligence feeds, incorporating intelligence into detection use cases, analytics rules and threat hunting activities.

  • Collaboration and Continuous Improvement: Work closely with DevOps, developers and security teams to improve detection coverage and feed operational learnings into system design and control implementation.

  • Governance Support & Documentation: Maintain operational documentation, incident records and runbooks. Support alignment with WoAG policies through implementation and evidence collection.

Criteria

The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters.

Essential criteria

  • Please prepare a statement of claims (less than 500 words) addressing the selection criteria. When preparing your statement of claims, please take into consideration the role and duties, and detail instances from your past that demonstrate how you meet the selection criteria.
    - Hands-on cyber security operations, including security monitoring, incident response, threat analysis, and investigation in enterprise or cloud environments.

  • - Working with SIEM/SOAR platforms, preferably Microsoft Sentinel, including development of analytics rules, KQL queries, alert tuning and dashboards.

  • - Incident detection and response, including triaging alerts, investigating security events and performing root cause analysis.

  • - Security automation and scripting, using tools to support orchestration and response activities.

  • - Working in cloud environments (preferably Microsoft Azure), with understanding of logging, monitoring and security controls.

  • - Applying cyber security frameworks and best practices, including familiarity with Whole-of-Australian-Government (WoAG) policies such as ISM and Essential Eight

Additional requirements

"Due to the requirement for immediate access to sensitive information and systems, personnel proposed for this role must hold a current NV1 security clearance at commencement."

Previous
Previous

Senior DevOps Engineer 

Next
Next

Senior Azure Java Stack Software Engineer