Principal Cyber Security Analyst
Talenza
Job Description
About the role
Talenza has partnered with the Cyber Defence Centre on their search for a Principal Cyber Security Analyst to join the Cyber Security Unit (CSU) in Brisbane.
You'll play a critical role in protecting Queensland's government and community from cyber harm - working alongside skilled analysts, engaging with agencies and vendors, and helping shape the future of the Government cyber defence capability.
You will:
- Take ownership of Whole of Government SOC service delivery, spanning SIEM, External Attack Surface Management, and Vulnerability Management platforms
- Serve as the go-to technical expert when serious or complex security incidents strike
- Guide incidents from first alert through to full resolution, covering detection, containment, eradication, recovery, and lessons-learned reviews
- Dig into suspected intrusions using forensic analysis, malware reverse engineering, and root cause investigation
- Fine-tune and build out detection logic to sharpen threat catching and cut down on noise from false alerts
- Push the SOC's operational maturity forward and put solid Standard Operating Procedures in place
- Turn data trends and metrics into practical recommendations for strategic improvement
- Coach and grow the skills of SOC analysts across the team
- Formulate threat hunting theories and help track down threat actor activity government-wide
- This role involves participation in a set roster/shift work, including on-call duties
- Willingness to undertake and maintain a Baseline/NV1 National Security Clearance
About you and what we are looking for:
You're an experienced SOC professional with strong technical credibility and a track record of leading incident response and uplifting operational maturity.
- Proven experience working in or supporting a Security Operations Centre (SOC)
- Strong hands-on experience with Microsoft Sentinel, including KQL, Analytic Rules, Workbooks, Playbooks, and Microsoft Defender XDR
- Solid understanding of SOC workflows - threat intel sharing, vulnerability management, incident response and investigation
- Proficiency with frameworks such as NIST, MITRE ATT&CK, and D3FEND
- Demonstrated ability to build SOPs and streamline SOC processes
Highly desirable:
- Ability to construct use cases and SIEM playbooks
- Scripting/programming skills (Python or PowerShell)
- Familiarity with forensic tools such as Autopsy, Wireshark, or SANS SIFT
- Experience across Linux/Unix and Windows environments
- Familiarity with the ASD Information Security Manual, Protective Security Policy Framework, NIST SP800-61r3, ISO27000 series, and Information Standard 18
- Postgraduate qualifications in ICT, Information Systems, or Cyber Security
- Relevant professional cybersecurity certifications
- Microsoft Sentinel (KQL, Analytic Rules, Workbooks, Playbooks) & Microsoft Defender XDR
- SIEM, EASM, and Vulnerability Management operations
- Digital forensics, malware analysis, and root cause investigation
- MITRE ATT&CK, D3FEND, and NIST frameworks
- Python or PowerShell scripting
- SOC incident response leadership and SOP development
- Threat hunting, threat intelligence, and stakeholder engagement