Start Your Search Here

Job Search

JS Careers Pty

Australia / Global

Incident Management Specialist

Job Description

Cyber Defence & Incident Response Specialist

Incident Response | Threat Detection | SOC | Web & API Security | AWS / GCP

Sydney | Permanent

We are partnering with a leading Australian bank to appoint an Incident Response Specialist to join its cyber defence function.

This is a hands-on role focused on investigating and responding to advanced cyber threats, coordinating remediation across technology and security teams, and helping strengthen detection and response capability across customer-facing banking services.

You will work across Security Operations, Fraud, Cloud, Applications, Infrastructure and broader Technology teams, while also supporting a 24/7 SOC through a rotational on-call schedule.

What you'll be responsible for

Investigate and respond to complex cyber security incidents

Coordinate containment, remediation and recovery across multiple technology teams

Lead incident activity involving phishing, credential compromise, account takeover and fraud-related threats

Support major incident response and escalation

Threat Detection & Security Operations

Analyse attack trends, threat activity and emerging risks

Investigate alerts and suspicious behaviour across enterprise environments

Improve detection logic, monitoring and proactive security controls

Work closely with SOC, Threat Intelligence and Engineering teams

Support a rotational on-call model

Web & API Security

Investigate security incidents involving web applications and APIs

Apply knowledge of common application vulnerabilities and the OWASP Top 10

Support remediation of vulnerabilities affecting customer-facing digital services

Work with application and engineering teams to reduce recurring security risks

Hands-on experience across technologies such as:

AWS and Google Cloud Platform

Splunk

Google SecOps / Chronicle

Sumo Logic CloudSIEM or similar SIEM platforms

Cloud security and threat detection tooling

What we're looking for

Around 5 years' experience across security operations, incident response or cyber defence

Experience working within a large enterprise environment

Strong hands-on incident investigation capability

Experience coordinating remediation across multiple teams

Knowledge of web application and API security

Experience with phishing, fraud, credential compromise or account takeover incidents

Banking or financial services experience would be highly regarded

Strong communication and stakeholder management skills

Why consider this opportunity? This is an opportunity to move beyond traditional SOC monitoring into a role with ownership of cyber incidents, working across threat detection, incident response, cloud, web security and fraud-related cyber activity within a complex banking environment.

#J-18808-Ljbffr
Apply Now

Similar Opportunities

View all jobs