Job Description
Remote is seeking a Lead Cyber Security Threat Analyst to join the team at ASD. The role will take a threat-driven approach to assessing system security, analysing system-specific threat intelligence and monitoring security events for potential incidents.
The Lead Cyber Security Threat Analyst will develop incident response plans and playbooks, assess vulnerabilities and security controls, and recommend practical remediation. The role will also establish security monitoring and analysis procedures, support test and evaluation activities for deliverable systems and products, and provide support to the Technical Leadership team as required. ( LH-07848)
Role Description
Key duties and responsibilities
-
Perform analysis of system security based on a threat-driven approach.
-
Analyse threat intelligence for system specific threats.
-
Monitor security events and information for security incidents.
-
Develop and use incident response plans and playbooks.
-
Analyse security vulnerabilities and propose solutions.
-
Review current system security controls for vulnerabilities.
-
Develop procedures to monitor and analyse security information and events.
-
Support, plan and conduct test and evaluation activities for deliverable systems and products.
-
Support the Technical Leadership team as required.
Essential criteria
-
Demonstrated experience working in a SOC as a Security Analyst.
-
Demonstrated experience in using Splunk Enterprise Security.
-
Experience with Endpoint Detection and Response (EDR) and network Detection and Response (NDR) platform.
-
Experience with Network Detection and Response (NDR) platform.
-
Experience with a Security Orchestration and Automated Response (SOAR) platform.
Desirable criteria
-
Demonstrated experience with or knowledge of Australian Government information security policies, the ASD Information Security Manual and Essential Eight.