VOTRE PROCHAIN CHAPITRE
IT Security Analyst - Day Shift
À propos du poste
• Protect a Microsoft-based environment across global operations through security monitoring, incident response, identity and access management, vulnerability management and continuous improvement of cyber security controls.
• Triage and investigate Microsoft Defender alerts and Arctic Wolf SOC escalations, including phishing, malware, suspicious sign-ins and endpoint activity.
• Coordinate containment, eradication and recovery activities with Arctic Wolf and internal IT teams, maintaining incident evidence and escalating major incidents when required.
• Support Microsoft Defender endpoint protection, Microsoft 365 security posture, security hardening and endpoint detection and response.
• Prioritise vulnerabilities based on exploitability, exposure and business criticality, and track remediation through closure.
• Support security baselines and patch compliance using Microsoft management tools and NinjaOne.
• Review and strengthen Active Directory and Microsoft Entra ID security, including MFA, Conditional Access, least-privilege access and periodic access reviews.
• Review privileged accounts, role-based access, service accounts and application permissions, and support identity-related threat response.
• Support improvement of Essential Eight controls, maintain evidence and remediation actions, and verify implementation with control owners.
• Support security risk assessments, policy reviews and audits, translating control gaps into prioritised actions.
• Record and manage security incidents, requests, problems and changes in Freshservice in line with ITSM processes.
• Perform root cause analysis, maintain response playbooks and knowledge articles, and support continuous improvement of recurring security issues.
• Report on incident response, remediation ageing, Defender coverage, identity risks and Essential Eight progress.
• Collaborate with service desk, infrastructure, application and business teams to resolve security issues while supporting operational continuity.
• Provide practical security guidance and contribute to phishing awareness and user education.
• Support incident handovers across time zones and participate in agreed after-hours incident response arrangements when required.
• Perform other position-level duties as they arise.
• At least 3 years’ relevant experience in cyber security operations, incident response, or an IT role with substantial hands-on security responsibilities is essential.
• Practical experience securing Microsoft enterprise environments and investigating threats using Microsoft Defender for Endpoint or equivalent EDR tooling is essential.
• Hands-on experience with Active Directory, Microsoft Entra ID, MFA, Conditional Access and access reviews is essential.
• Experience working with a SIEM and managed SOC or MDR provider is essential; Arctic Wolf experience is highly regarded.
• Working knowledge of Essential Eight implementation or assessment and ITIL-aligned IT service management processes is essential; Freshservice experience is desirable.
• Strong knowledge of Microsoft 365 and Windows security, including Exchange Online, Windows endpoints and Windows Server, is essential.
• Experience with log analysis and threat investigation, including common attack techniques, phishing and ransomware, is essential.
• Sound understanding of networking fundamentals, including TCP/IP, DNS, firewalls and VPNs, is essential.
• PowerShell or Kusto Query Language (KQL) experience for investigation and automation is desirable.
• Exposure to Intune, Defender for Office 365 and Defender for Identity is desirable.
• Experience within global or multi-site operations is desirable.
• Relevant qualifications in cyber security, information technology or a related discipline, or equivalent practical experience, are essential.
• Relevant Microsoft security or identity certifications, CompTIA Security+, ITIL Foundation certification or Essential Eight assessment training are desirable.
• Strong analytical judgement, problem-solving ability and clear written and verbal communication skills are essential.
• Ability to prioritise competing incidents and handle sensitive information with discretion and accountability is essential.
• Work from home
• Mon - Fri: 9:00 AM – 6:00 PM AEST/AEDT (adjustments will be made for daylight saving time)
• HMO with 2 free dependents and medical reimbursements
• Government-mandated benefits
• Opportunities to work with leading companies in Australia and beyond
• Training programmes for career development
• Engaging company outings, team activities and wellness sessions
• Supportive, inclusive culture
• Dedicated managers focused on your growth and success
• Competitive pay and benefits
• Additional entitlements
• Structured career development programs
• People-first culture prioritizing stability, growth and genuine care
• Equal opportunity and inclusive workplace