Skip to main content
AfterDuty

SOC Incident Responder

KBR · Canberra, Australian Capital Territory

Type
Full-time
Posted
8 days ago

Overview

Your investigative discipline and evidence-handling skills directly apply to incident triage and forensic analysis.

About this role

Title

SOC Incident Responder

The Opportunity

The SOC Incident Responder is responsible for identifying, investigating, containing, and responding to cybersecurity incidents affecting the organization's systems, networks, cloud environments, and users. This role serves as a key member of the Security Operations Center, performing rapid incident triage, threat analysis, containment actions, and escalation of significant security events.

The successful candidate will combine technical cybersecurity expertise with strong analytical, communication, and documentation skills to minimize risk and ensure timely response to cybersecurity threats.

Key Responsibilities

Incident Detection & Response

  • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents.
  • Perform initial triage and analysis of suspicious events and potential security incidents.
  • Determine incident severity, scope, and business impact.
  • Contain security incidents through actions such as:
  • Account disablement
  • Password resets
  • Session revocation
  • Device isolation
  • IP and domain blocking
  • Escalate complex or high-severity incidents to senior security personnel.

Investigation & Analysis

  • Analyze endpoint, network, identity, and cloud telemetry.
  • Correlate indicators of compromise (IOCs) with threat intelligence sources.
  • Conduct malware investigations and support forensic analysis activities.
  • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.

Incident Documentation

  • Maintain detailed incident records and case documentation.
  • Create incident reports detailing findings, actions taken, and business impact.
  • Ensure evidence is collected, preserved, and documented appropriately.
  • Participate in post-incident reviews and lessons-learned sessions.

Collaboration

  • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations.
  • Support major incident response activities and virtual war room operations during significant security events.

Continuous Improvement

  • Contribute to development of SOC playbooks and response procedures.
  • Recommend improvements to detection rules, monitoring coverage, and response workflows.
  • Assist in threat hunting and security control validation activities.
  • Stay current with emerging threats, vulnerabilities, and industry best practices.

Required Qualifications

Education

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience or,
  • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience.
  • Familiarity with Windows, Linux, cloud platforms, and enterprise networking.

Technical Skills

Familiarity with

  • SIEM technologies
  • EDR/XDR platforms (Microsoft Defender, CrowdStrike, SentinelOne, Taegis, etc.)
  • Email security technologies
  • Identity platforms such as Active Directory and Entra ID
  • Network protocols and traffic analysis

Preferred Certifications

  • Baseline Clearance, NV-1 Eligible or Existing NV-1 Preferred
  • GCIH (GIAC Certified Incident Handler)
  • GCIA
  • GCFA
  • CISSP
  • Security+
  • CySA+
  • SC-200 (Microsoft Security Operations Analyst)

Working Conditions

  • Participation in a 24x7 SOC shift rotation and on-call coverage as required.
  • Support for major cybersecurity incidents outside normal business hours.
  • Ability to manage multiple concurrent security investigations.

Why Join KBR?

At KBR, our people are at the heart of everything we do. Our success is built on a culture of caring, collaboration, trust and continuous learning, where every team member feels safe, supported, valued and empowered to thrive.

We are committed to creating an inclusive environment where people can belong, connect and grow, while doing meaningful work that makes a lasting impact on communities across Australia. Through genuine collaboration and strong partnerships with our clients, we deliver innovative and sustainable solutions for a better tomorrow.

When you join KBR, you'll become part of a team that shares common values, works together towards a common purpose, and genuinely cares about the success and wellbeing of its people.

Benefits include

  • Industry leading salaries reviewed annually.
  • Flexible work arrangements (start/finish times, WFH, Flex time)
  • Salary packaging and novated leases
  • Paid professional membership fees
  • Life/Health insurance discounts
  • Employee stock purchase plans
  • Personal career development plans
  • Growth and promotion opportunities

Help shape tomorrow by applying today!

#LI-DNP #LI-DNI #S-DNI

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Canberra

Why this fits a police background

  • Police experience explicitly valued
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Security operations

More cyber security & digital forensics jobs for ex-police

  • GRC and Advisory Consultant

    DXC Technology · Canberra

    Full-time

    Job Description DXC Technology (NYSE: DXC) is a leading enterprise technology and innovation partner delivering software, services, and solutions to global enterprises and public sector organisations — helping them harness AI to drive outcomes at a time of exponential change with speed.

    Posted 5 days ago

  • Senior Cyber Security Governance Analyst

    radk tech pty ltd · Canberra

    Contract

    Your analytical discipline and experience with strict frameworks (e.g., PACE, CPIA) map well to governance and compliance in cyber security.

    Posted 6 days ago

  • Full-time

    Our Mission At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts.

    Posted 7 days ago

  • ICT Security Analyst

    Fujitsu · Canberra

    Full-time

    Your incident response and investigative skills from policing translate directly to managing security incidents and access controls.

    Posted 8 days ago