Skip to content

Open nowPosted 35 days ago

Level 1 Security Analyst

Workable (global search)107,990 open roles

Where
Melbourne, VIC, Australia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowLevel 1 Security AnalystWorkable (global search) · Melbourne, VIC, Australia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 6 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 35 days ago

Workable (global search) median: 6 days open

The posting

About the company

Triskele Labs is one of Australia’s leading sovereign cyber security firms, delivering Managed Detection & Response (MDR), Digital Forensics & Incident Response (DFIR), Offensive Security, and Governance, Risk & Compliance (GRC) services to regulated enterprises, government, and the higher education sector. Built over more than a decade, founder-led and independently owned, we partner with clients operating under some of Australia’s most demanding regulatory regimes.

Our Security Operations Centre runs 24x7x365 and remains completely onshore in Melbourne, and we are the largest CREST Registered Penetration Testing company in the city. Sovereign Australian ownership, deep technical capability, and front-line threat intelligence from one of the most active DFIR practices in the country sit at the centre of how we differentiate.

About the role

We are hiring Level 1 Security Analysts into our Melbourne Security Operations Centre. This is the front line of our MDR service: the first set of eyes on every alert raised across our clients’ environments, at every hour of the day and night.

You will work a rotating roster as part of a team that monitors, triages and responds to security events across a broad client base spanning financial services, government, health and higher education. You will learn the craft properly: real telemetry, real incidents, real clients, with senior analysts, detection engineers, threat hunters and a genuine DFIR team sitting alongside you.

This is a deliberate entry point into defensive security. We hire for aptitude, curiosity and work ethic rather than years on a résumé, and we fund the certifications that take you from L1 to a credible security professional. What we ask in return is that you take the roster seriously, care about the quality of what you hand to the next shift, and want to get better every month.

This is not a Monday-to-Friday role, and it is not a remote role. It is not a detection engineering, penetration testing or GRC role. Analysts who join us wanting to be somewhere else within six months tend not to enjoy it, analysts who want to become genuinely good at investigation and response tend to thrive.

Key Responsibilities

Monitoring and triage

  • Monitor alert queues and triage security events across client environments, identifying potential security incidents and escalating promptly where required.
  • Perform incident prioritisation and triage to determine the severity, scope and likely impact of security issues.
  • Escalate alerts requiring deeper investigation to the appropriate tier within the SOC, with clear, complete handover notes.
  • Perform efficient triage and ticketing of reported phishing emails, taking timely and appropriate action.
  • Conduct dark web monitoring for client exposure and indicators of compromise using established processes.
  • Respond to hotline calls promptly and professionally so that no client call is missed.

Service operations

  • Respond to service desk tickets, resolving them or escalating to the appropriate team as required.
  • Perform daily health checks across client environments to identify and address potential issues before they affect monitoring coverage.
  • Attend and lead shift handover meetings, completing the documentation needed for a clean transition between shifts.
  • Create change request tickets for internal and client queries and see them through to resolution.
  • Manage and configure security monitoring tooling within the change control process, escalating configuration changes as required.
  • Work to individual and tier KPIs aligned to our service commitments.

Reporting and client support

  • Retrieve, assist in producing and issue scheduled weekly and monthly client reports following existing processes.
  • Assist in gathering evidence for monthly reporting and client review meetings, and address client queries arising from them.

Learning and improvement

  • Proactively identify opportunities to tune event detection and reduce false positives, passing what you see to our Detection Engineering team with the context they need to act on it.
  • Actively identify improvements to internal processes and Standard Operating Procedures, particularly around triage and analysis.
  • Continuously develop your skills through formal training and certification, including completing at least one Blue Team Labs Online challenge per month.
  • Work collaboratively with the wider SOC and with our Platform Engineering, DFIR, Security Engineering and Service Delivery teams.

About you

  • Analytical Thinking: Strong analytical skills with the ability to quickly assess and prioritise security events and incidents. Capable of analysing logs, identifying anomalies, and recognising potential security threats.
  • Communication Skills: Excellent written and verbal communication skills. Ability to convey complex technical information to both technical and non-technical stakeholders effectively.
  • Team Player: Capable of working collaboratively in a team-oriented environment, interacting with colleagues at all levels. Ability to support and back up colleagues during high-pressure situations.
  • Flexibility and Adaptability: Willingness to work on a 24x7x365 rotating roster, including nights, weekends and public holidays. Adaptability to changing priorities, emerging threats, and new technologies.
  • Willingness to dive into unknown areas of knowledge and learning and to discover methods (such as practical labs or online resources) to acquire this knowledge.
  • Capability to go the extra mile for customers to deliver on their needs.
  • Understanding of other cultures and belief systems to function as part of a team.

Application Process

A cover letter is optional, but it is read and will put you in high regard. If you write one, tell us about something you have investigated, broken, built or learned in security outside of formal study or employment. Three honest sentences about a home lab or a Blue Team Labs challenge beat a page of generic cover letter.

Requirements

The first six of these are conditions of the role and we cannot move on them. The rest describe where you need to be starting from, not where we expect you to be. Nobody joins us at L1 already able to do this job: you will be trained and mentored into it by the analysts sitting next to you, and we fund the certifications along the way. Bring the curiosity and the attention to detail, and we will build the rest with you.

  • Australian citizenship required. This is a sovereign MDR requirement and sponsorship is not available.
  • Based in Melbourne, or able to relocate to Melbourne at your own cost before your start date.
  • Willing and able to work a 24x7x365 rotating roster, including nights, weekends and public holidays.
  • Willingness to complete CompTIA CySA+ and Blue Team Level 1 (BTL1) as a condition of ongoing employment past probation. Triskele Labs funds both.
  • Clear written English and strong attention to detail. You will write ticket notes and client-facing updates every shift, and the judgement to know when something does not look right is most of the job.
  • Able to satisfy a National Police Check and standard employment screening.
  • Foundational technical knowledge across networking, Windows and Linux, and common security technologies, with a working understanding of what attacks like phishing, credential theft and suspicious sign-in activity look like in logs.
  • Demonstrated hands-on practical learning: Blue Team Labs Online, TryHackMe, Hack The Box, CTFs, a home lab, or prior exposure to security monitoring, service desk or systems administration work.

Highly Regarded

  • Hands-on exposure to a SIEM platform — Microsoft Sentinel, Splunk, Rapid7 InsightIDR, Elastic or Wazuh. Lab or self-directed exposure counts.
  • Hands-on exposure to an EDR platform — Microsoft Defender for Endpoint, CrowdStrike or SentinelOne.
  • Certifications such as CompTIA Security+, Network+, CySA+, Blue Team Level 1 (BTL1), Microsoft SC-200 or AZ-900.
  • A Bachelor of Computer Science (Cyber Security), Master of Cyber Security, or equivalent tertiary study.
  • Any scripting or query language exposure — KQL, SPL, PowerShell or Python.
  • Prior experience in an MSSP, managed services or multi-tenant environment.
  • Prior IT service desk or NOC experience, particularly on a shift roster.

Benefits

A genuine entry point into defensive cyber security with a clearly defined path to L2 and beyond.

Funded certifications; CompTIA CySA+ and BTL1 in your first year, with further certification support after that.

Onshore, Melbourne-based SOC. You will be in the room with the senior analysts, detection engineers and DFIR consultants you are learning from.

Exposure to real incidents across a broad and demanding client base, not a single environment.

Shift loading and a published, predictable roster.

A team that backs each other, with leaders who work the floor rather than manage from a distance.

Team culture is everything to Triskele Labs and it is the reason we exist. We are a forward-thinking company, always looking for ways to strengthen our culture and be a destination employer, and we survey our team regularly to find ways to improve their experience here.

A fantastic office in the heart of the Melbourne CBD.

Frequent events organised by our People & Culture team.

Access to Triskele Labs benefits program.

If you are early in your cyber career but ready to take the next step, we want to hear from you.

Working Arrangements

The role operates on a 24x7x365 rotating roster, including nights, weekends and public holidays and requires on-site attendance at our Melbourne office.

Five weeks of annual leave per year while working the rotating shift roster.

Interview process

Initial informal discussion.

Technical discussion with the SOC Manager or a Level 3 Analyst.

A technical challenge.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.