Skip to main content
AfterDuty

Cyber Hunt and Threat Emulation

Department of Parliamentary Services · Canberra, Australian Capital Territory

Type
Full-time
Posted
12 days ago

Overview

Your investigative mindset and evidence-handling discipline are relevant, but this role demands deep technical offensive security skills beyond typical policing experience.

About this role

*Employment Type:*Ongoing

Classification: Parliamentary Executive Level 1

Contact: Brendon McKinley, (02) 6277 2828, brendon.mckinley@aph.gov.au

The Opportunity*

The Department of Parliamentary Services (DPS) supports the operation of the Australian Parliament by providing secure, reliable and effective ICT services across Australian Parliament House (APH). Within the Information Services Division, the Cyber Security Branch protects DPS and APH systems, information and users from cyber security threats through governance, assurance, engineering, monitoring, detection and response activities.

The role sits within the Cyber Security Operations Section and leads the department’s Cyber Hunt and Threat Emulation (CHATE) capability. CHATE provides specialised offensive security, cyber hunt, penetration testing, red team and threat emulation services that help DPS identify and remediate security weaknesses before they can be exploited.

As the Assistant Director Cyber Hunt and Threat Emulation, you will manage the day-to-day operation of the CHATE function, including work planning, prioritisation, staff guidance, quality assurance and delivery of agreed cyber security outcomes. The role scopes, plans, manages and undertakes cyber hunt, penetration testing, red team, threat emulation and other technical security assurance activities across networks, applications, cloud services, end-user environments and enterprise platforms.

The role works closely with CSOC analysts, cyber engineering, detection engineering, cyber threat intelligence, project delivery teams, system owners, service providers and senior stakeholders. It supports the security accreditation process by identifying suitable candidates for penetration testing and related assurance activities, providing expert technical advice, and recommending practical remediation, mitigation or compensating controls.

This is a unique opportunity to lead and shape a hands-on offensive security and hunt capability in a nationally significant parliamentary environment. The successful candidate will help mature CHATE services, uplift frameworks and methodologies, and directly improve DPS’s ability to find, understand and reduce cyber risk across complex and sensitive technology environments.

Who we are looking for*

We are looking for an experienced, technically credible and practical cyber security professional who can lead offensive security and hunt activities, manage sensitive engagements, and provide clear advice on vulnerabilities, threat actor tradecraft and security control weaknesses. The ideal candidate will be curious, disciplined and collaborative, with the judgement to balance technical depth, operational risk, stakeholder confidence and business impact.

The successful candidate will demonstrate

  • experience leading or managing a technical cyber security function, including work planning, prioritisation, staff guidance, quality assurance and delivery of outcomes in a complex operating environment;
  • demonstrated experience planning, scoping and conducting penetration testing, cyber hunt, red team, threat emulation or similar technical security assurance activities across enterprise technology environments;
  • strong technical knowledge of common vulnerability classes, exploitation methods, operating systems, networks, web applications, cloud services, security controls and the tools and methodologies used to assess them;
  • the ability to analyse threat intelligence, vulnerability information, technical findings and operational context to assess exposure, prioritise activity and provide practical remediation or mitigation advice;
  • well-developed written and verbal communication skills, including the ability to prepare clear technical reports, rules of engagement, permission documentation, briefings and recommendations for technical and non-technical audiences;
  • a continuous improvement mindset, with the ability to develop frameworks, methodologies, procedures, tooling and reporting practices that mature CHATE services and support broader Cyber Security Branch objectives.

A minimum of five years’ relevant cyber security experience, or demonstrated equivalent experience, is required. Relevant industry certifications or equivalent experience is desirable. Tertiary qualifications in information technology, computer science, cyber security or a related discipline are also desirable. Experience with Microsoft Azure, Microsoft 365, hybrid cloud environments, scripting, red team activities, physical security assessment, social engineering, MITRE ATT&CK, the cyber kill chain or the diamond model would be highly regarded.

Job Specific Requirements

  • The successful applicant will be required to obtain and maintain a Negative Vetting 1 (Confidential/Highly Protected/Secret) security clearance.

At DPS, we are committed to building a diverse and inclusive workplace that ensures all our people can contribute to our shared purpose. We encourage applications from Aboriginal and Torres Strait Islander people, people with disability, people with caring responsibilities, people who identify as LGBTQIA+, people from cultural and linguistically diverse backgrounds, people who identify as neurodivergent, and mature aged people.

Duty Statement*

*Classification:*Parliamentary Executive Level 1

*Branch:*Cyber Security

*Section:*Cyber Security Operations

*Immediate supervisor:*Director, Cyber Security Operations

Duty Statement

Under limited/general direction undertake duties in accordance with the agreed standards for the specified classification. The duties will include, but are not limited to, the following:

1. Lead and manage the day-to-day operations of the Cyber Hunt and Threat Emulation function, including work planning, prioritisation, quality assurance, staff guidance and delivery of agreed cyber security outcomes.

2. Plan, scope and deliver cyber hunt, penetration testing, red team, threat emulation and other technical security assurance activities across networks, applications, cloud services, end-user environments and enterprise platforms.

3. Provide expert technical advice to stakeholders on cyber risk, vulnerabilities, threat actor tactics, security control weaknesses and practical remediation or mitigation options.

4. Analyse threat intelligence, vulnerability reporting, incident information and technical telemetry to identify exposure, prioritise activity and support informed cyber security decision-making.

5. Prepare clear, evidence-based technical reports, briefs and recommendations that communicate findings, risks, business impact and remediation priorities to technical and non-technical audiences.

6. Contribute to the uplift of Cyber Hunt and Threat Emulation services by developing frameworks, methodologies, procedures, tooling, reporting practices and capability improvement initiatives aligned to departmental cyber security objectives.

Selection Criteria

1. Demonstrated ability to lead and manage a technical cyber security function, including planning work, setting priorities, supporting staff, assuring quality and delivering outcomes in a complex operating environment.

2. Demonstrated experience planning, scoping and conducting penetration testing, cyber hunt, red team, threat emulation or similar technical security assurance activities across enterprise technology environments.

3. Strong technical knowledge of common vulnerability classes, exploitation methods, operating systems, networks, web applications, cloud services, security controls and the tools and methodologies used to assess them.

4. Ability to analyse threat intelligence, vulnerability information, technical findings and operational context to assess risk, prioritise activity and provide practical remediation or mitigation advice.

5.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Canberra

Why this fits a police background

  • Police experience explicitly valued
  • Intelligence & OSINT
  • Security operations

More cyber security & digital forensics jobs for ex-police

  • GRC and Advisory Consultant

    DXC Technology · Canberra

    Full-time

    Job Description DXC Technology (NYSE: DXC) is a leading enterprise technology and innovation partner delivering software, services, and solutions to global enterprises and public sector organisations — helping them harness AI to drive outcomes at a time of exponential change with speed.

    Posted 5 days ago

  • Senior Cyber Security Governance Analyst

    radk tech pty ltd · Canberra

    Contract

    Your analytical discipline and experience with strict frameworks (e.g., PACE, CPIA) map well to governance and compliance in cyber security.

    Posted 6 days ago

  • Full-time

    Our Mission At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts.

    Posted 7 days ago

  • ICT Security Analyst

    Fujitsu · Canberra

    Full-time

    Your incident response and investigative skills from policing translate directly to managing security incidents and access controls.

    Posted 8 days ago