
Senior Cyber Defense Analyst
Posted Jul 22

Posted Jul 22
This is a fully remote position, open to applicants in Australia.
• Oversee and prioritize security alerts across SIEM, EDR, and CSPM systems for both corporate and product environments.
• Analyze alerts to assess their scope, severity, and determine if escalation is necessary.
• Utilize AI-assisted triage and enrichment tools to enhance analysis speed and minimize mean time to detect.
• Classify, document, and monitor alerts throughout their entire lifecycle using ticketing and case management systems.
• Engage in or lead incident response activities from detection to remediation, including collecting evidence, conducting forensic analysis, identifying root causes, and communicating with stakeholders.
• Perform investigations utilizing SIEM, EDR, CSPM, and cloud-native log sources, encompassing identity provider logs, cloud audit trails, and network flow data across both corporate and product infrastructure.
• Implement established incident response runbooks across identity, endpoint, cloud, and email investigation processes.
• Handle or assist with evidence management, forensic artifact collection, and maintaining chain-of-custody procedures.
• Generate clear, decision-ready incident summaries and post-incident reports for both technical teams and leadership.
• Contribute to the design, implementation, and fine-tuning of detection rules across SIEM and EDR platforms, focusing on minimizing false positives and closing coverage gaps.
• Transform threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, particularly addressing threats aimed at privileged access tools and supply chain attack vectors.
• Assist in maintaining and enhancing detection coverage aligned with MITRE ATT&CK.
• Collaborate with threat hunting colleagues to validate detection logic through hypothesis-driven hunts.
• Incorporate AI-driven tools for alert triage, enrichment, and investigation as a consistent component of daily operations.
• Contribute to the assessment, integration, and enhancement of AI and automation functionalities across the team's workflows.
• Assist in designing prompts, agent workflows, or LLM-based pipelines that enhance analyst capabilities and decrease manual effort.
• Collaborate with engineering teams to optimize log ingestion, data quality, and tool integrations.
• Maintain daily operational notes and document shift handoffs.
• Participate in the development and refinement of incident response runbooks, playbooks, and standard operating procedures.
• Engage in on-call rotations for after-hours incident escalations.
• Monitor and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify areas for improvement.
• Take part in tabletop exercises, purple team activities, and post-incident reviews.
• A minimum of 2 years of experience in a SOC, security operations, or incident response position.
• Knowledge of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behaviors.
• Experience with at least one SIEM platform and familiarity with crafting search or detection queries.
• Familiarity with EDR platforms and cloud environments (IaaS preferred).
• Comfort in using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) within security workflows.
• Excellent written communication skills; capable of documenting findings clearly and concisely for both technical and non-technical audiences.
• Health insurance
• Flexible work arrangements
• Professional development opportunities
• Remote work options
Manulife
Agile Defense
DYOPATH
Get handpicked remote jobs straight to your inbox weekly.