SOC Analyst at SALTYBRANDS
Sydney, South Australia, Australia -
Full Time


Start Date

Immediate

Expiry Date

03 Jan, 27

Salary

0.0

Posted On

05 Oct, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Services

Description

About the job


Penetration Tester / SOC Analyst

Melbourne | Contract | Hybrid Cyber Security Role

We’re looking for an experienced Penetration Tester / SOC Analyst to join a large and complex technology environment, working across both offensive security and security operations.This is a genuinely hands-on role, with an approximate 50/50 split between penetration testing and SOC activities. You’ll have the opportunity to identify and exploit vulnerabilities, while also using those insights to improve detection, monitoring and incident response capabilities.


What you'll be doing

  • Penetration TestingPlan and deliver authorised penetration tests across web applications, APIs, infrastructure, identity services, cloud platforms and enterprise technologies.
  • Conduct vulnerability discovery, manual validation, controlled exploitation, privilege escalation and attack-path analysis.
  • Produce detailed penetration testing reports covering evidence, risk, business impact and remediation recommendations.
  • Map attack activity to MITRE ATT&CK and use testing outcomes to validate security controls and SOC detection capabilities.



  • Security OperationsMonitor and triage alerts across SIEM, EDR, XDR, identity, cloud, email and network security platforms.
  • Investigate suspicious activity by correlating endpoint, identity, network, application and cloud telemetry.
  • Support incident containment, eradication, recovery and evidence collection.
  • Develop, tune and validate detection rules, dashboards, alert logic and response playbooks.
  • Conduct proactive threat hunting using threat intelligence, indicators of compromise and recognised adversary behaviours.



What we're looking forYou'll ideally bring experience across both penetration testing and security operations within a complex enterprise environment.

  • We're particularly interested in people with:Strong hands-on penetration testing experience across web applications, APIs, networks, infrastructure, identity and cloud.
  • Practical experience with enterprise SIEM, EDR or XDR platforms, including alert triage and incident investigation.
  • Strong knowledge of vulnerabilities, exploitation, privilege escalation, lateral movement, credential access and defence evasion.
  • Experience developing or tuning detections using KQL, SPL, Sigma, correlation rules or behavioural analytics.
  • Strong understanding of Active Directory, Microsoft Entra ID, Microsoft 365, Windows and Linux security, networking and endpoint telemetry.
  • Experience with MITRE ATT&CK, threat hunting and incident response.
  • Strong scripting, analytical, documentation and stakeholder communication skills.


  • Relevant tertiary qualifications and extensive cyber security experience are required, with recognised penetration testing, SOC, incident response or cloud security certifications highly regarded.
Responsibilities
Loading...