Senior Cybersecurity Incident Responder
Brisbane, Queensland, Australia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Datacom
Datacom is a leading technology provider in Australasia, combining cutting-edge technology, expert knowledge, and skilled professionals to enable organisations to succeed in a dynamic environment. Serving government bodies, enterprises, and emerging businesses, Datacom is dedicated to delivering impactful solutions for customers, communities, and employees.
Team Overview
The Cybersecurity Defence Operations Centre (CDOC) at Datacom operates throughout Australia and New Zealand. It offers comprehensive cybersecurity services including managed SOC, SIEM, EDR, XDR, threat intelligence, and digital forensics & incident response (DFIR). The team comprises analysts, engineers, specialists, intelligence analysts, hunters, and responders with over a decade of experience serving commercial and government clients. Datacom partners with leading industry providers to offer broad technical expertise, certifications, and practical experience.
Role Summary
The Senior Cybersecurity Incident Responder will join the Cybersecurity Incident Response Team (CSIRT) to provide both reactive and proactive incident expertise. The role involves leading DFIR engagements across Australia and New Zealand and delivering advisory services including tabletop exercises, compromise assessments, threat hunting, breach readiness evaluations, intelligence briefings, and threat modeling.
Key Responsibilities
- Conduct comprehensive investigations into significant security incidents, identifying causes, impact, and mitigation measures.
- Analyze affected systems using forensic methods to review system event logs and attacker activity.
- Use security tools such as EDR, SIEM, XDR, and identity management technologies to support incident investigations.
- Perform log correlation and create timelines tracing adversary behavior.
- Identify points of intrusion and root causes, then recommend preventative actions.
- Gather digital forensic evidence following industry best practices for image acquisition and evidence preservation.
- Prepare detailed DFIR reports documenting findings, investigative steps, and recommendations.
- Support coordination of containment, eradication, and recovery processes.
- Analyze response efforts with feedback during Post Incident Reviews to facilitate continuous improvement.
- Deliver proactive services like tabletop exercises, threat hunting, compromise assessments, and threat intelligence briefings.
- Engage effectively with senior stakeholders within Datacom and client organisations.
- Collaborate with CSIRT colleagues to enhance team capabilities, processes, and technology.
- Participate in an on-call rotation for responding to major incidents.
- Be willing to travel occasionally for customer engagements across Australia and New Zealand, including urgent site visits.
Candidate Profile
- Ability to communicate confidently with senior leadership, especially during high-pressure situations.
- Proven success handling high-profile cybersecurity incidents with serious operational or privacy consequences, including ransomware and data breaches.
- Experience in digital forensics and incident response, familiarity with key system and forensic artifacts relevant to investigations.
- Proficient with DFIR tools such as EnCase, X-Ways, Magnet Axiom, Velociraptor, KAPE, and THOR.
- Strong expertise in analyzing large datasets across diverse log sources and platforms including XDR/EDR and SIEM products like CrowdStrike, Microsoft Defender, Splunk, or Sentinel.
- Deep understanding of attacker techniques, tools, tactics, and emerging threat trends.
- Knowledge of security frameworks and methodologies such as NIST CSF, MITRE ATT&CK, D3FEND, Unified Kill Chain, and OWASP Top 10.
- Basic scripting or automation abilities in languages like PowerShell, Bash, Python, or Ruby are advantageous.
- Certifications such as SANS GCFA, GCFE, GCIH, or other relevant DFIR qualifications are desirable.
Culture & Benefits
Datacom is committed to fostering a supportive environment that enables career growth and well-being. Employees benefit from extensive learning opportunities, parental leave, wellness support, and various perks that encourage both professional and personal success. Team members enjoy access to top-tier training platforms, recognition programs, employee discounts, and the chance to engage in meaningful work that makes a difference.
Additional Information
Eligibility criteria may apply to some benefits. The role requires occasional travel and participation in an on-call roster.