XPT Software Australia Pty Ltd Logo

XPT Software Australia Pty Ltd

SOC Analyst

Posted Yesterday
Be an Early Applicant
In-Office
Melbourne, Victoria, AUS
Senior level
In-Office
Melbourne, Victoria, AUS
Senior level
Supports NIST assessments, penetration-test finding triage, vulnerability remediation, security control hardening, and audit evidence preparation. Reviews endpoint, infrastructure, network, firewall, SIEM, and monitoring controls; validates remediation effectiveness and telemetry; and supports SOC investigations, incident reviews, root-cause analysis, and structured change processes. Works with architects, platform owners, network teams, application teams, and governance stakeholders in regulated or government environments.
The summary above was generated by AI

Role Summary

The Cyber Security Engineer is responsible for supporting NIST CSF / NIST 800 assessments, triaging penetration test findings, and driving remediation activities across application, infrastructure, network security, and monitoring platforms.

The role is hands-on and delivery focused, working closely with architects, platform owners, SOC, and infrastructure/application teams to translate security findings into actionable fixes, validate control effectiveness, and support audit‑ready evidence for regulated/government environments.

Key Responsibilities

NIST Assessment Support (CSF / NIST 800 Series)

  • Support NIST CSF / NIST 800‑53 / 800‑61 / 800‑92 assessments through:
    • Control evidence collection
    • Gap analysis support
    • Mapping tooling controls to NIST requirements
  • Assist architects and governance teams in preparing:
    • Control implementation summaries
    • Tool capability mapping
    • Evidence packs for audits and client reviews
  • Track and manage security gaps, risks, and remediation actions in line with agreed timelines
  • Support continuous improvement initiatives driven by assessment outcomes

Penetration Test Findings & Remediation

  • Triage and analyse application, infrastructure, and network penetration test findings
  • Work with platform and application teams to:
    • Validate findings (true positive vs false positive)
    • Prioritise remediation based on risk and exploitability
  • Execute or support remediation actions such as:
    • Configuration hardening
    • Policy tuning
    • Control enablement or enhancement
  • Track remediation status and provide clear closure evidence for governance and audit forums

Hands‑on engineering support across:

  • Endpoint & Infrastructure Security
  • Vulnerability & Exposure Management
  • Activities include:
    • Policy tuning and baseline hardening
    • Coverage and health checks
    • Supporting remediation of vulnerabilities and misconfigurations
    • Validating fixes post‑remediation

Support security controls across:

  • Cisco security platforms
  • Imperva
  • Microsoft GSA / related network security controls

Responsibilities include:

  • Supporting firewall / network security rule reviews and clean‑ups
  • Assisting with remediation of network‑related pen test findings
  • Supporting change validation and post‑implementation checks
  • Working with network teams to ensure security controls align with NIST and secure‑by‑design principles
  • Support SIEM and monitoring platforms:
    • Splunk
    • Microsoft Sentinel
  • Assist with:
    • Log source onboarding validation
    • Detection coverage checks related to NIST and pen test scenarios
    • Validation that remediated controls generate expected telemetry
  • Support SOC teams with investigation data where required
  • Maintain accurate documentation for:
    • Remediation actions
    • Control changes
    • Evidence required for audits and MSSR / governance reviews
  • Participate in:
    • Incident and problem reviews (P1 / P2 support)
    • Root cause analysis where control gaps are identified
  • Follow structured change and release processes (CAB, validation, rollback awareness)

 

Skills & Experience

  • 5 years experience in security engineering / SecOps / blue team roles
  • Exposure to NIST CSF or NIST 800 frameworks
  • Hands‑on experience supporting remediation across:
    • Endpoint / infrastructure security tools
    • Vulnerability management platforms
    • Network security controls
  • Experience working with penetration test reports and remediation tracking
  • Familiarity with SIEM platforms (Splunk and/or Sentinel)
  • Strong documentation and evidence‑driven mindset (audit readiness)

 



Similar Jobs

2 Hours Ago
In-Office
Melbourne, Victoria, AUS
Senior level
Senior level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Own the full outbound sales cycle for mid-market merchants, including prospecting, pipeline development, discovery, demos, negotiation, and closing. Build tailored multi-product solutions, acquire net-new business, manage complex multi-stakeholder deals, forecast accurately in Salesforce, and consistently exceed revenue targets. Collaborate with business development, product, marketing, implementation, and operations teams while serving as a trusted consultative advisor.
Top Skills: Salesforce
Yesterday
In-Office
Melbourne, Victoria, AUS
Expert/Leader
Expert/Leader
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Lead sales enablement and end-to-end professional services for Mission Critical Networks (MCN). Act as single point of contact for commercial submissions, align integration and division of responsibility with SIs and partners, manage CoE systems and PoCs, develop E2E portfolio readiness, support CFRs on scope, timelines, and approvals, and provide early visibility of customer and SI requirements to inform roadmap and readiness.
Top Skills: 5GAutomationLteMission Critical Networks (Mcn)
Yesterday
In-Office or Remote
Victoria, AUS
Expert/Leader
Expert/Leader
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Lead regional EHS for Network Operations across MOAI: set strategy, prevent serious injuries, govern psychosocial risks, manage workers' compensation, ensure environmental compliance, strengthen contractor governance, and develop a specialist team while influencing senior stakeholders and embedding EHS into commercial decisions.

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account