Skip to main content
AfterDuty

Senior SOC Analyst L3

Deloitte · Sydney, New South Wales

Type
Full-time
Posted
5 days ago

Overview

Your incident command and analytical skills from policing translate to SOC leadership.

About this role

Date

21 Aug 2026

Brisbane, QLD, AU

Perth, WA, AU

Adelaide, SA, AU

Melbourne, VIC, AU

Department

Technology & Transformation

Description

Job Requisition ID: 41774

Tackle big issues like cyber, trust, resilience and digital transformation

Be part of market-leading projects with global scale and complexity

Mentoring, coaching and leadership programs to help you make an impact that matters

What will your typical day look like?

Be part of the SOC leadership team, help make decisions that define our strategy, drive change and provide better services for our clients. Help us do something that really matters - keep Australian people and Australian companies safe – while enjoying work and the fast paced environment that rewards you for your efforts, encourages your ideas and recognises that work life balance is important.

Reporting to the Security Operations Centre (SOC) Team Lead, the L3 Security Analyst fills a leadership role in the Deloitte 24x7 SOC. Our mandate is to provide fully managed detection and response capability to a suite of international clients. The role will be part of the L3 escalation roster, providing first class incident response capability to identified threats and alerts using the latest tools, processes, and techniques.

This senior role fills two critical functions in the SOC

Incident Response - Acting as an escalation point for L1 and L2 SOC Analysts and a technical point of contact for our clients during Incident Responses both within and outside business hours. Using defensive measures and telemetry collected from a variety of sources to provide guidance to junior SOC members to identify, analyse, and report events that occur or might occur within client networks in order to protect information, information systems, and networks from threats.

Lead a Capability area – Work with a dedicated subset of analysts to shape process and improve delivery outcomes for a select group of high profile clients. Enjoy flexibility to drive the agenda and move the needle on day to day operations.

Enough about us, let's talk about you

You may have all or some of the following skills/experiences

Experience as an escalation point to ensure timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities.

Analysis of security events from multiple sources including but not limited to events from the Security Information and Event Management tool, network intrusion systems and Host based Intrusion Prevention tools

Analyse identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.

Determine tactics, techniques, and procedures (TTPs) for intrusion sets.

Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.

Collaborate with other L3s to ensure Threat Hunting, Threat Intel, Detections, Tuning and other L3 tasks are completed as required

Provide knowledge and expertise to L1 and L2 Analysts including night shift Analysts to upskill where possible

Creation and tuning of detections in response to new or observed threats within customer environments

Review and document and improving processes to contribute to the overall security of the environment

Must be an Australian citizen and must be able to attain and maintain an Australian Federal Government security clearance at the NV1 level or higher.

Why Deloitte?

At Deloitte, we focus our energy on interesting and impactful work. We’re always learning, innovating and setting the standard; making a positive difference to our clients and our society. We put coaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.

We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone’s perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong.

We value in-person connection with our clients and our colleagues. We offer several ways for you to work flexibly so that you can serve your clients, stay connected with your team, and manage your personal priorities.

We help you live and work well. To support your personal and professional life, we offer a range of perks and benefits , including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Sydney

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Security operations
  • Training & coaching delivery
  • Team & shift leadership

More cyber security & digital forensics jobs for ex-police

  • Contract

    The Infrastructure Engineer will be a key technical support resource in all aspects of Infrastructure BAU support and operations within the APAC & HK regions. This role will be assisting with various BAU related activities within the on premise and cloud environments in APAC & Hong Kong.

    Posted 5 days ago

  • IT Engineer, Support

    Future Secure AI · Sydney

    Full-time

    Your experience with identity access management and security operations in policing transfers directly to this in-house build role.

    Posted 5 days ago

  • Head of Technology Risk & AI

    Profusion · Sydney

    Full-time

    Head of Technology Risk & AI Financial Services | Risk Leadership | Melbourne or Sydney Australians considering a return home are encouraged to apply Company Overview Our client is a large, well-established Australian financial services organisation operating within the superannuation sector.

    Posted 5 days ago

  • Full-time

    Your experience managing risk registers, audit actions, and compliance frameworks in policing transfers directly to this governance role.

    Posted 6 days ago