Skip to main content
AfterDuty

Cyber Security Analyst

Thales · Sydney, New South Wales

Type
Full-time
Posted
6 days ago

Overview

Your investigative mindset, evidence-handling discipline, and experience following strict protocols from policing translate directly into triaging and documenting security incidents. The role's emphasis on methodical analysis, threat hunting, and clear reporting mirrors the structured approach you used in casework and incident command. However, the technical requirements for specific SOC tools and platforms mean you would need significant retraining to be competitive for this role.

About this role

At Thales, we know technology has the ability to make our world more secure, sustainable, and inclusive – and that it’s all driven by human intelligence.

Because it takes human intelligence to build and power the systems and solutions that people depend on every day. So we stay curious and make space for diverse points of view. We share what we know and we challenge what’s possible.

From manufacturing and engineering to cybersecurity and space, we’re driving progress in some of the world’s most important industries – and working together to build a future we can all trust.

Our Benefits

In addition to interesting, engaging opportunities that impact at scale, and ongoing personal and professional development opportunities, Thales can offer you:

  • Competitive remuneration (Insert WAGE EA) + Super + Profit Share
  • ThalesFlex – Hybrid work environment
  • Fitness Passport Discount – Access to a network of Gyms across AUS as cheap as $14.95 P/W
  • Employee discounts with a number of affiliates (Travel, Car hire, Tech, Medical Insurance)
  • Modernised Paid Parental Leave
  • Veterans Leave
  • Novated Lease options
  • Personal & professional training development opportunities
  • Sonder – Wellbeing & Support Partner

The Team

This role is part of our corporate team, a central hub for Thales Australia. It’s where our shared services – think finance, legal, HR, procurement – come together to make sure all teams across Australia have access to the business services they need. Cross-functional collaboration helps us build out Thales’ capabilities – and helps us open up new career opportunities for employees all across the business.

Your Role*

As a Cyber Security Analyst, you will play a key role in protecting Thales Australia’s systems, networks, data, and users through proactive monitoring, investigation, and response to cyber security threats. Operating within the Security Operations Centre (SOC), you will contribute to the ongoing enhancement of detection, monitoring, incident response, and cyber resilience capabilities across enterprise, cloud, identity, endpoint, and data environments.

You will work closely with internal IT teams and stakeholders to identify, investigate, and respond to cyber security incidents while continuously improving detection capabilities and operational effectiveness across the security landscape.

  • Monitor, triage, and investigate security alerts across enterprise, cloud, identity, endpoint, and data environments
  • Identify, analyse, and respond to cyber security incidents in line with established policies and procedures
  • Conduct threat hunting and investigative activities to identify anomalous or malicious behaviour
  • Support containment, remediation, and recovery activities alongside IT and business stakeholders
  • Operate and support SOC tooling including SIEM, EDR/XDR, monitoring, and incident response technologies
  • Contribute to the development and optimisation of automated investigation and response workflows
  • Investigate identity-related security events including account compromise, privilege misuse, and unauthorised access
  • Support data protection and compliance-driven investigations using security and governance tooling
  • Improve detection effectiveness through alert tuning, use-case refinement, and onboarding of new telemetry sources
  • Produce clear and accurate incident documentation and communicate findings to both technical and non-technical stakeholders

Your Experience

  • Experience working within a Security Operations Centre (SOC) or similar operational cyber security environment
  • Hands-on experience with Microsoft Sentinel for monitoring, investigations, hunting, alert tuning, and dashboard development
  • Strong knowledge of Microsoft Defender technologies including Defender for Endpoint, Defender for Identity, Defender for Cloud, and Defender for Office 365
  • Experience leveraging Microsoft Purview for data security, insider risk, or compliance-related investigations
  • Strong understanding of threat detection and response methodologies, including MITRE ATT&CK
  • Experience with SIEM and log analytics platforms across endpoint, identity, network, cloud, and email environments
  • Experience investigating endpoint-based security incidents using EDR/XDR technologies
  • Practical understanding of IAM concepts including privileged access, account compromise, and lateral movement scenarios
  • Strong analytical, investigative, and problem-solving capability with high attention to detail
  • Ability to work collaboratively within a geographically dispersed SOC environment

A Defence security clearance is required for this role, applicants must be Australian citizens and eligible to obtain and maintain an appropriate clearance.

Additional information with regards to clearances is available from the Australian Government Security Vetting Agency website http://www.defence.gov.au/AGSVA/. In some cases, individuals who hold a current clearance from a foreign government may be eligible to have this clearance recognised by the Australian Government and be eligible for this role. The Australian Defence Trade Controls Act (DTCA) is applicable and as such, your nationality may be a factor in determining your suitability for this role.

It’s easy to dismiss the perfect opportunity if you don’t see yourself as the perfect fit. If this role feels right – no matter your background or personal circumstances – please introduce yourself or join our community. We’re committed to supporting a diverse workplace, and that starts here.

We’re proud to be endorsed by WORK180 as an Employer for All Women, but we know there’s always more we can do. We’ll continue to foster industry partnerships, employee resource groups (ERGs) and development opportunities to make Thales a genuinely equitable employer, for everyone.

Read more about our WORK180 endorsement.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Sydney

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Investigative casework
  • Working to legislation & regulation
  • Security operations

More cyber security & digital forensics jobs for ex-police

  • Your background running operational units and coordinating multi-agency responses maps directly onto leading national support functions and ensuring consistent, secure operations across multiple sites. You're used to setting clear accountabilities, managing risk, and driving continuous improvement, which is exactly what this role requires. Your experience with compliance and governance, from PACE to internal procedures, means you can bring structure and discipline from day one.

    Posted 2 days ago

  • Full-time

    Your experience working to strict regulatory frameworks like PACE and CPIA gives you a natural grounding in compliance and assurance, which is exactly what this cyber security GRC role demands. You've spent years maintaining accurate records, managing risk registers, and engaging with diverse stakeholders under pressure, so coordinating audits and driving adherence to standards like ISO 27001 will feel familiar. The role is a development opportunity, so your proven attention to detail and process-oriented mindset will let you build the specific cyber security knowledge on the job.

    Posted 5 days ago

  • Integrity and Security Analyst

    NSW Government · Sydney

    Full-time

    A$133,348 – A$146,945Estimated

    This role directly leverages your operational intelligence experience from policing — you'll produce intelligence products that identify security risks and inform frontline decisions, just as you did under the National Intelligence Model. Your ability to assess threats, manage multi-agency coordination, and apply legislative frameworks like PACE or RIPA is exactly what the NSW Electoral Commission needs to safeguard election integrity. The requirement for 10+ years in law enforcement confirms this is a role built for your background, not a sideways move into a completely new field.

    Posted 5 days ago

  • Full-time

    Your investigative experience from policing—evidence handling, chain of custody, case file management, and conducting structured interviews—maps directly onto the core responsibilities of this insider threat role. You are used to working with sensitive information, maintaining confidentiality, and producing defensible reports for multiple stakeholders, which is exactly what this position demands. The analytical and risk-assessment skills you developed through intelligence-led policing and managing complex investigations will let you hit the ground running in identifying and mitigating insider

    Posted 7 days ago