
Team Lead, Threat Analyst
- Australia
- Permanent
- Full-time
- Lead and mentor a team of threat analysts, overseeing their day-to-day tasks and incident response activities.
- Coordinate and manage the investigation of security incidents, determining root causes and ensuring swift resolution.
- Act as a subject matter expert (SME) during cybersecurity incidents, leading response efforts and offering technical guidance.
- Maintain up-to-date knowledge of the latest attacker tactics, techniques, and procedures (TTPs) and generate actionable intelligence for proactive defense.
- Develop and implement incident handling processes and ensure they are executed consistently across all incidents.
- Conduct network and endpoint intrusion analysis, digital forensics, and malware analysis to support incident investigations.
- Communicate findings and incident details effectively to both technical and non-technical stakeholders.
- Collaborate with the wider team to operationalise threat intelligence and produce Indicators of Compromise (IOCs) for future use.
- Engage in threat hunting activities, identifying and mitigating emerging threats.
- Champion continuous improvement efforts to refine incident response and threat detection methodologies.
- Minimum of 5+ years of experience in cybersecurity, preferably with leadership experience in a SOC or similar environment.
- Proven expertise in managing and responding to advanced security incidents and intrusions.
- Bachelor's Degree in Information Technology, Computer Science, or equivalent practical experience.
- Deep understanding of threat detection, incident response, and/or digital forensics.
- Strong knowledge of endpoint and network security technologies (e.g., IDS/IPS, EDR, ATP, malware defenses).
- Familiarity with MITRE ATT&CK and similar frameworks for adversary behavior mapping.
- Strong analytical and troubleshooting skills, with experience in constructing SQL queries and using OSQuery or similar.
- Proficiency in scripting languages such as PowerShell, or Python, with the ability to automate tasks and streamline response procedures.
- Experience administering Windows, macOS, or Linux-based operating systems in an enterprise environment.
- Knowledge of incident response tools and procedures, with certifications like CISSP, GIAC, or OSCP being highly desirable but not required.
- Strong understanding of Windows event log analysis
- A genuine passion for cybersecurity, with an innovative and curious mindset.
- Strong documentation and communication skills
- Strong interpersonal skills and the ability to communicate effectively across different organizational levels.
- A proactive approach to learning new tools, techniques, and processes.
- Excellent documentation skills and an ability to produce detailed reports and technical documentation.