About the Role
We are seeking a motivated and detail-oriented Cyber Security SOC Analyst to join our Cyber Security team. In this role, you will be responsible for monitoring, analysing and responding to cyber security events across customer environments, helping to identify threats, investigate incidents and support the ongoing protection of critical ICT systems. Working within a collaborative Security Operations Centre, you will play a key role in maintaining the confidentiality, integrity and availability of customer information and services.
Responsibilities
- Monitor, analyse and investigate complex security events, alerts and incidents across customer environments using SIEM, EDR, SOAR and other security monitoring platforms.
- Lead the triage, investigation and response to cyber security incidents, undertaking detailed analysis to determine root cause, impact and appropriate remediation activities.
- Conduct proactive threat hunting activities to identify advanced threats, indicators of compromise (IOCs) and malicious behaviours that may not be detected through automated monitoring.
- Analyse network traffic, endpoint telemetry, system logs and forensic artefacts to identify attack vectors, persistence mechanisms and lateral movement.
- Develop, refine and optimise detection use cases, SIEM correlation rules, dashboards and alerting logic to improve detection capability and reduce false positives.
- Collaborate with customers, technical teams and incident response personnel to coordinate containment, eradication and recovery activities during security incidents.
- Produce high-quality incident reports, technical assessments and post-incident reviews, including recommendations to improve security controls and operational resilience.
- Provide technical guidance and mentoring to junior SOC Analysts, supporting capability development and knowledge sharing across the Security Operations Centre.
- Contribute to the development and maintenance of SOC playbooks, standard operating procedures and incident response processes to improve operational effectiveness.
- Maintain awareness of emerging cyber threats, threat actor tactics, techniques and procedures (TTPs), and incorporate threat intelligence into monitoring and detection activities.
- Support vulnerability management, security assessments and continuous improvement initiatives by identifying control gaps and recommending risk-based remediation strategies.
- Participate in on-call or after-hours incident response activities as required, ensuring the timely resolution of critical security events and maintaining agreed service levels.
Requirements
- Australian citizen (required for Defence projects) with a min AGSVA NV1 clearance.
- The ability to obtain a Negative Vetting 2 (NV2) security clearance is preferred.
- Experience working in complex Defence project settings.
- 3–5+ years' experience in a Security Operations Centre (SOC), Cyber Security Operations, Incident Response or a similar cyber security role, with demonstrated experience investigating and responding to security incidents.
- Experience with enterprise security technologies, including SIEM, EDR/XDR, SOAR, vulnerability management and threat intelligence platforms (e.g. Microsoft Sentinel, Splunk, Microsoft Defender, CrowdStrike, Palo Alto, Tenable or similar).
- Strong understanding of cyber security principles, including network security, Windows and Linux operating systems, identity and access management, common attack techniques, and security frameworks such as the MITRE ATT&CK framework, NIST Cybersecurity Framework or the ASD Information Security Manual (ISM).
- Communicates clearly and confidently, both written and verbal.
- Adapts easily to change and works well in a team environment.
Skills
- SIEM
- EDR
- SOAR
- Threat Hunting
- Network Security
- Windows Operating Systems
- Linux Operating Systems
- Identity and Access Management
- MITRE ATT&CK framework
- NIST Cybersecurity Framework
- ASD Information Security Manual (ISM)
Location
- Sydney, CBD
Work Type
- Onsite
Experience Level
- 3-5+ years
Education Level
- CompTIA Security+
- CompTIA CySA+
- GIAC Certified Incident Handler (GCIH)
- Microsoft Security Operations Analyst (SC-200)
- Splunk Core Certified Power User
Benefits
- Long Service Leave @ 7 years
- Health & wellbeing allowance ($250)
- First year leave (5 days)
- Birthday leave
- Higher Education Subsidy ($2500 annually)
- Veteran Career Development Program
- Service Awards
- Employee Recognition
- Donate for a Cause (matched up to $200)
About the Company
- C4i Solutions is a leading Technology, ICT, and Digital Solutions company, delivering real outcomes for our Defence, Government, and Industry partners.
- As a Veteran-owned and operated company, we value your service.
- We are a close-knit team of veterans, problem-solvers, tech heads, dads, mums, soccer coaches, and weekend adventurers who love what we do, like to have a bit of fun, and don't take ourselves too seriously.
- What brings us together is a passion for doing great work that makes a real difference to those who serve.
