Skip to content

Open nowPosted 77 days ago

Senior Cybersecurity Incident Responder

Workable (global search)108,016 open roles

Where
Sydney, NSW, Australia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Cybersecurity Incident ResponderWorkable (global search) · Sydney, NSW, Australia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 77 days ago

Workable (global search) median: 7 days open

The posting

About us

At Datacom, we combine technology, expertise, and talented people to help organisations thrive in a rapidly changing world. As one of Australasia's leading technology providers, we work with customers across industries to solve real-world problems and deliver meaningful outcomes.

Whether we're supporting governments, enterprise organisations, or growing businesses, we're committed to creating meaningful outcomes for our customers, communities, and each other.

Our CDOC Team

Datacom’s Cybersecurity Defence Operations Centre (CDOC) operates across Australia & New Zealand where we provide a full stack of cybersecurity services including managed SOC/SIEM/EDR/XDR, threat intelligence, and digital forensics & incident response (DFIR). Our Cybersecurity Defence Operations Centre is a well-established team made up of Cybersecurity Analysts, Platforms Engineers, Automation Specialists, Solutions Delivery Engineers, Threat Intel Analysts, Threat Hunters, & Incident Responders who have been managing customers, both commercial and government, for over 10+ years.

We partner with industry leaders to provide our services and to provide you with a broad technical skillset, certifications, and experience.

About The Role

We are currently looking for a highly skilled and motivated individual to join our Cybersecurity Incident Response Team (CSIRT) as a Senior Cybersecurity Incident Responder. CSIRT provide proactive and reactive expertise to help organisations respond to major cybersecurity incidents.

In this role you will be responsible for the delivery of digital forensics & incident response (DFIR) engagements, and proactive advisory engagements such as the delivery of tabletop exercises, compromise assessments & threat hunting, breach readiness assessments, threat intelligence briefings, & threat modelling. You will be expected to lead DFIR engagements across either Australia or New Zealand.

We are seeking a candidate who has extensive experience investigating and responding to major cybersecurity incidents, and possesses excellent communication, analytical, and problem-solving skills.

What You’ll Do

As a Senior Cybersecurity Incident Responder, you will:

  • Conduct thorough investigations into major security incidents, determining root causes, impact, and mitigation strategies. Providing expertise and support to contain, eradicate, and recover from such security incidents.
  • Conduct analysis of affected systems utilising forensic techniques to thoroughly examine system events and adversary activities.
  • Utilise security tooling such as EDR, SIEM, XDR, & Identity technologies to assist your investigation of confirmed or suspected compromises.
  • Undertake log & correlation analysis and construct a timeline of adversary activities.
  • Identify intrusion vectors & root causes and develop recommendation actions to prevent similar incidents.
  • Collect digital forensics evidence from affected systems in accordance with industry standards for image acquisition and preservation of digital evidence.
  • Produce comprehensive, detailed DFIR reports outlining the investigative steps undertaken, your findings, and recommendations.
  • Support the coordination of containment, eradication and recovery efforts based on available information and established processes.
  • Analysis of incident response effort, with feedback from the customer and third parties as part of Post Incident Reviews (PIRs) and Lessons Learned.
  • Deliver proactive incident response services which include tabletop exercises, threat hunting, compromise assessments, breach readiness assessments, threat intelligence briefings, and threat modelling.
  • Communicate with senior stakeholders within Datacom and our customers.
  • Work with other members of the CSIRT team, to develop the technical capabilities of the CSIRT - including improving the processes and technology to deliver successful outcomes to customers and stakeholders.
  • Participate in an on-call roster for major incident response.
  • Occasional planned or last-minute/urgent travel to customer sites will be required for certain customer facing engagements. This may include a customer site in your home city, or travel to other customer sites within Australia and New Zealand.

What you’ll bring

  • Confidence in communicating with a variety of senior stakeholders, including Senior Leadership teams in difficult / tense situations.
  • Proven experience in responding to high-profile cybersecurity incidents that have had significant operational or privacy impacts to the affected organisation such as ransomware & data breaches.
  • Experience in digital forensics & incident response (DFIR) with an understanding of key system & digital forensic artifacts and how they are useful in a cybersecurity investigation.
  • Experience using DFIR tools such as EnCase, X-Ways, Magnet Axiom, Velociraptor, KAPE, & THOR.
  • Proven knowledge and experience of efficiently searching large datasets across multiple log sources and underlying platforms including XDR/EDR and SIEM products such as CrowdStrike, Microsoft Defender, Splunk, or Sentinel.
  • A strong understanding of current and emerging attacker behaviours, tools, tactics, and techniques.
  • An understanding of various security frameworks and methodologies such as NIST CSF, MITRE ATT&CK and D3FEND, Unified Kill Chain and OWASP Top 10.
  • Basic scripting or automation skills are desirable (for example PowerShell, Bash, Python, or Ruby).
  • SANS GCFA, GCFE, GCIH, or relevant DFIR certifications are desirable.

Benefits

Culture and benefits

Join a team where you'll be supported to grow your career, prioritise your wellbeing, and make a genuine impact. From industry-leading learning and development opportunities to parental leave, wellbeing support, and employee benefits, we're committed to helping our people thrive both professionally and personally

We're passionate about creating a workplace where people feel supported, empowered, and inspired to do their best work. Whether you're developing new skills, tackling complex challenges, or collaborating with some of the best minds in the industry, you'll be part of a team that values curiosity, innovation, inclusion, and making a genuine difference.

Why you will love working here

  • Paid parental leave
  • 24/7 Employee Assistance Programme (DataCare)
  • Ongoing learning, certifications, and career development opportunities
  • Access to industry-leading learning platforms and future skills training
  • Recognition programmes that celebrate great work
  • Great employee discounts and financial wellbeing benefits
  • Meaningful work that makes a real impact

Eligibility criteria and conditions may apply to some benefits.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.