Investigate and triage complex security alerts using Splunk, Microsoft Sentinel and SentinelOne; perform endpoint containment with CrowdStrike and Microsoft Defender; tune detections with KQL and SPL; conduct MITRE ATT&CK-based threat hunting; produce incident reports; understand DLP; participate in paid on-call roster every three weeks.
Position Title: SOC Analyst
Location: Canberra, ACT - Australia
Role Purpose :
Join our Australian SOC team as a SOC Analyst. In this role, you will be the "engine room" of our security operations, moving beyond basic alert monitoring to lead deep investigations across a diverse range of client environments in Asia Pacific (APAC). You will work with a world-class security stack and have the autonomy to hunt for threats and recommend custom detections.
Key Responsibilities
Summary
- Triage and Investigation: Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs.
- Endpoint Response: Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR.
- Detection Tuning: Optimise detection rules using KQL and SPL to enhance our proactive defence posture.
- Threat Hunting: Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity.
- Reporting & Mentorship: Produce detailed incident reports for technical and executive stakeholders.
- DLP: Understand data-loss prevention in the context of Security Operations.
- On-call: Participate in paid on-call roster every 3 weeks.
Skills, Knowledge & Expertise
What we are looking for in you
- Experience: 2–4 years in a SOC or high-pressure security operations environment.
- Tooling Expertise: Hands-on proficiency in Splunk, Sentinel, CrowdStrike, and Microsoft Defender. Experience with other SIEM and EDR technologies highly regarded.
- Technical Skills: Strong understanding of TCP/IP, Windows/Linux internals, Cloud Security and common attack vectors (Phishing, Ransomware, Living-off-the-Land).
- Certifications: One or more of the following: SC-200, Splunk Core Certified Power User, CompTIA CySA+, or SANS GCIH.
- Communication: Ability to clearly articulate technical risks to non-technical client stakeholders verbally and/or via email and ticketing system.
Job Benefits
Behaviours
- Client-focused with a proactive and solution-oriented mindset.
- High attention to detail and commitment to quality.
- Collaborative and able to work effectively across teams.
- Comfortable managing multiple priorities in a fast-paced environment.
- Curious and eager to learn, with a passion for cybersecurity.
- Professional and confident in client-facing scenarios.
Ways of working
- Focusing on Clients and Customers.
- Working as One NCC.
- Always Learning.
- Being Inclusive and Respectful.
- Delivering Brilliantly.
Our company
At NCC Group, our mission is to create a more secure digital future. That mission underpins everything we do, from our work with our incredible clients to groundbreaking research shaping our industry. Our teams' partner with clients across a multitude of industries, delving into, securing new products, and emerging technologies, as well as solving complex security problems. As global leaders in cyber and escrow, NCC Group is a people-powered business seeking the next group of brilliant minds to join our ranks.
Our colleagues are our greatest asset, and NCC Group is committed to providing an inclusive and supportive work environment that fosters creativity, collaboration, authenticity, and accountability. We want colleagues to put down roots at NCC Group, and we offer a comprehensive benefits package, as well as opportunities for learning and development and career growth. We believe our people are at their brilliant best when they feel bolstered in all aspects of their well-being, and we offer wellness programs and flexible working arrangements to provide that vital support.
Come join us?
About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
Similar Jobs
Information Technology • Cybersecurity
Triage, investigate, respond to, and remediate security alerts and hands-on intrusions. Analyze EDR and SIEM telemetry, logs, forensic artifacts, malware, and activity in Microsoft 365 and Google Workspace. Identify root causes, extract indicators of compromise, tune detections, and provide actionable remediation. Support customer escalations and collaborate with Product and Engineering to improve MDR workflows, while contributing to incident response, threat hunting, and detection engineering.
Top Skills:
Active DirectoryEdrGoogle WorkspaceGroup PolicyLinuxmacOSMicrosoft 365Mitre Att&CkNatPowershellSIEMVlansWindows
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
Sets global cloud architecture standards, serves as the senior technical escalation point for strategic multi-cloud engagements, and advises executive customers. Leads complex architecture workshops, develops reference architectures and automation, mentors architects, influences product roadmaps, and improves professional services scoping and delivery. Requires deep AWS and Azure expertise, strong cloud security, data protection, automation, and enterprise architecture experience, with occasional travel.
Top Skills:
AWSAws CloudformationAzure BicepCi/CdGoogle Cloud Platform (Gcp)KubernetesMicrosoft 365AzurePowershellPythonSalesforceTerraform
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads Pfizer’s global customs governance and compliance framework, including Belgian Authorized Economic Operator status, internal controls, customs valuation reporting, audits, continuous improvement, and stakeholder partnerships. Provides technical expertise in customs law and operations while implementing standardized, automated workflows aligned with GDP, GMP, and local regulations. Oversees talent development, performance standards, budgeting, and strategic customs initiatives across global operations.
Top Skills:
Erp SystemsExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft VisioMicrosoft WordSAP
What you need to know about the Melbourne Tech Scene
Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.



