Skip to main content
AfterDuty

Senior Cyber Security Analyst

AusNet · Melbourne, Victoria

Type
Full-time
Posted
10 days ago

Overview

Your investigative discipline and incident command experience transfer to cyber incident response and threat hunting.

About this role

We bring the energy!

*Through purpose and people -*not just through the infrastructure we operate, but through the way we show up for each other, our customers’ and our communities. The future of energy is in our hands. Let’s shape it together.

Are you ready to shape the future of energy?

This is a great opportunity for someone who wants to work in critical infrastructure, playing a key role in defending critical energy assets through monitoring and response, threat hunting, security engineering, and continuous improvement of cyber security operations.

We are looking for a Senior Cyber Security Analyst to be a key technical subject matter expert, responsible for driving cyber security outcomes across AusNet’s Information Technology (IT) and Operational Technology (OT) environment. This role requires deep expertise in cyber defence, incident investigation and response, automation, and cloud security and will be instrumental in supporting the implementation of the cyber security roadmap.

What you’ll be doing in this role

  • Lead technical investigations and response activities for cyber security incidents, coordinating internal teams and external service providers.
  • Provide advanced technical analysis, remediation advice and clear incident reporting to technical and management stakeholders.
  • Contribute to intelligence-led threat hunting using threat-actor tactics, techniques and procedures (TTPs) and relevant threat intelligence.
  • Provide technical oversight and quality assurance for investigations and response activities, ensuring alignment with approved runbooks and leading practices.
  • Develop, maintain and improve incident response runbooks, investigation procedures and operational processes.
  • Improve detection and response coverage by developing and tuning rules across SIEM, XDR and other security platforms.
  • Use threat intelligence and lessons learned from incidents to prioritise mitigations and strengthen security controls.
  • Support the continuous monitoring of IT and Operational Technology (OT) environments and report on operational performance, incidents and emerging threats.
  • Represent AusNet in relevant industry forums and contribute to trusted information-sharing communities.

Required experience and capabilities

You do not need to meet every criterion; however, we are looking for a strong combination of the following:

  • Extensive hands-on experience in security operations, cyber incident response, threat hunting or detection engineering.
  • Demonstrated ability to investigate and respond to complex cyber security threats, supported by a strong understanding of threat-actor tradecraft and adversary tactics, techniques and procedures.
  • Experience using and improving security operations technologies, including SIEM, XDR, SOAR and NDR.
  • Experience developing and tuning detection rules, investigation processes and incident response workflows.
  • Strong working knowledge of enterprise technologies, including Windows, Linux, Active Directory, Microsoft Entra ID, Microsoft 365, DNS, DHCP, web proxies, mail relays and TCP/IP networking.
  • Proficiency in Python, PowerShell or similar scripting languages, with experience automating security operations and incident response activities.
  • Experience investigating identity-related threats and security weaknesses within Active Directory or Microsoft Entra ID environments.
  • Ability to coordinate technical teams and stakeholders during cyber incidents and support timely containment and remediation decisions.
  • Strong written and verbal communication skills, including the ability to explain complex technical matters to technical and non-technical audiences.

Desirable experience and capabilities

  • Experience with cloud platforms and security technologies, particularly Microsoft Azure or AWS.
  • Exposure to cyber security monitoring and incident response within Operational Technology (OT) or Industrial Control System (ICS) environments.
  • Experience in digital forensic investigations, including malware analysis, memory analysis, disk forensics or network packet analysis.
  • Working knowledge of Web Application Firewalls, vulnerability management platforms and OT vulnerability management technologies.
  • Knowledge of common web and mobile application vulnerabilities and experience providing security remediation advice.
  • Participation in cyber security competitions, responsible vulnerability disclosure or bug bounty programs, open-source projects or security research communities.
  • Relevant industry certifications, such as GCFA, GCFE, GCIH, GNFA, OSCP or OSCE, or relevant Microsoft and cloud security certifications.

In this role you’ll need to demonstrate some key attributes

  • A commitment to continuous learning and staying current with threat-actor tradecraft, detection techniques and security operations practices.
  • Calm, decisive and resilient judgement in high-pressure, dynamic and complex situations.
  • Strong analytical and problem-solving skills, supported by close attention to detail.
  • Ability to manage competing priorities and deliver accurate, high-quality outcomes within required timeframes.
  • A collaborative working style and the ability to build productive relationships across organisational levels and functions.
  • A continuous-improvement mindset, with the initiative to identify and implement practical improvements to cyber defence capabilities.

The AusNet experience is all about…

  • Growing your impact: We’ll support you to build your career through real opportunities and strong connections.
  • Solving some of the most complex energy challenges of our time: We love unpacking complex challenges in clever ways and looking at things differently.
  • Building an energy future to be proud of:*We’re a trusted leader, with deep expertise, driven to do what’s right for our communities and customers.

We’re committed to building an inclusive culture and a diverse workforce. We believe different perspectives are essential to our success, and we encourage all applicants to apply. If you need any adjustments during the recruitment process, we're happy to discuss how we can support you.

At AusNet, we bring the energy! Ready to make your impact? Apply now!

We will not be engaging with Recruitment agencies for this role, so please apply directly.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Melbourne

Why this fits a police background

  • Evidence & case files
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Security operations

More cyber security & digital forensics jobs for ex-police

  • Control Manager Vulnerability Management

    Commonwealth Bank · Melbourne

    Full-time

    Control Manager, Vulnerability Management Do you thrive at the intersection of cyber security, technology, and stakeholder engagement? Help drive vulnerability remediation, shape governance practices, and make a real impact across the organisation.

    Posted 6 days ago

  • Information Security & Risk Analyst

    The Royal Australian College of General Practitioners (RACGP) · Melbourne

    Full-time

    Your incident command and threat assessment experience maps directly to security risk and resilience work.

    Posted 8 days ago

  • Contract

    Your experience with evidence handling and regulatory compliance maps directly to security assurance and vendor risk assessment.

    Posted 8 days ago

  • Cloud Security Engineer

    IFM Investors · Melbourne

    Full-time

    About Us JOB DESCRIPTION IFM Investors is a global asset manager, founded and owned by pension funds, with capabilities in infrastructure equity and debt, private equity, private credit, real estate and listed equities.

    Posted 13 days ago