About the Role
This role supports cybersecurity operations across threat detection, investigation, response, and continuous service improvement. You should be an experienced security practitioner capable of operating within the end-to-end detection and response lifecycle, combining broad analytical capability with an engineering mindset to rapidly identify, investigate, and contain threats.
Responsibilities
- Operate within the end-to-end detection and response lifecycle (detect → investigate → respond → improve), including analyzing logs and telemetry from multiple sources to establish attack scope, impact, and root cause
- Build, validate, tune, and optimize detection logic and coverage, leveraging attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK to improve accuracy and reduce false positives
- Execute and coordinate security event response activities, including containment, isolation, escalation, and remediation, applying sound judgment during active engagements
- Maintain and improve automation and orchestration capabilities, including SOAR workflows, automated playbooks, scripted response actions, and AI-driven enhancements to reduce manual effort and improve detection and response outcomes
- Document and communicate security event findings, including timelines and lessons learned, while providing clear updates to stakeholders and driving continuous improvement in detection and response processes
- Identify gaps in monitoring and detection coverage, contributing to operational maturity through continuous improvement initiatives, metrics, and enhancements to detection, response, and automation capabilities
- Support integration of partner use cases into detection and monitoring workflows
- Guide and instruct junior members of the team to support the achievement of professional goals
Requirements
- Experience in security operations, incident response, detection engineering, or related cybersecurity functions within a production environment
- Experience in security detection, investigation, and response across multiple domains, with the ability to pivot across data sources and independently manage end-to-end investigations from initial triage through post-incident improvement
- Ability to build, validate, and tune detections and response workflows, including reducing false positives
- Considerable proficiency in log analysis, telemetry interpretation, and cross-system data correlation, including the ability to query, manipulate, and optimize data using KQL, SPL, SQL, or similar languages for investigative and detection use cases
- Practical experience with containment, response actions, and automation, including developing or maintaining SOAR workflows, API integrations, and scripted response actions using sound judgment
- Experience with security platforms and technologies, including SIEM, EDR/XDR, identity security, and cloud security
- Working knowledge of identity and access systems and common attack paths, including credential theft, privilege escalation, and session/token abuse
- Considerable understanding of attacker tactics, techniques, and procedures (TTPs), including MITRE ATT&CK
- Record of improving operational effectiveness, including reducing alert noise, improving detection coverage, and decreasing mean time to detect and respond
- Great analytical, decision-making, and communication skills, including the ability to clearly articulate findings, provide timely incident updates to both technical and non-technical stakeholders, and operate effectively in high-pressure scenarios
- Ability to operate with minimal supervision and make risk-informed decisions quickly
Skills
- Exceptional communication and executive presence, with the ability to influence at all organizational levels
- Process discipline
- Leadership competency in geographically diverse matrixed environment
- Relevant Cyber Security Certificate
- Worked in SOC environment before
- Familiarity with Cyber Security and Information Technology
- Strong problem-solving and critical thinking skills
- Effective communication and interpersonal skills
Location
- Sydney
Work Type
- Full-time
- 38 hours per week
- Standard working hours of 9:00AM to 7:30PM AEST 4 days per week (Wednesday to Saturday)
- Flexibility may occasionally be required
Experience Level
- Experienced
Benefits
- Affordable, competitive and flexible benefits
About the Company
- At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.
- We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
- Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth.
- We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success.
- We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences.
- These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
- Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development.
- Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
- At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact.
