Remote job
Security Operations Analyst
Job details
About this role
Role overview A remote-first Security Operations Analyst position focused on detecting and responding to active cyber intrusions against small and mid-sized organisations that often lack dedicated headcount. The role sits inside a 24/7 human-led SOC that defends millions of endpoints and identities, triaging alerts, scoping incidents, and guiding remediation end to end. Analysts are also expected to contribute to product improvements, customer enablement, and public-facing research over time.
Responsibilities - Triage, investigate, and remediate alerts raised by the detection platform, including active hands-on-keyboard intrusions. - Review EDR and SIEM telemetry, logs, and forensic artefacts to determine root cause and remove threats from compromised environments. - Perform dynamic malware analysis to extract indicators of compromise and assess intent when needed. - Investigate suspicious activity in Microsoft 365 and Google Workspace tenants and deliver clear remediation guidance. - Refine detection content and queue hygiene by crafting and tuning signals for emerging adversary behaviour. - Partner with customer success, product, and engineering teams to support escalations and evolve agentic SOC workflows.
Requirements - Two or more years in a SOC, incident response, MDR, or digital forensics role. - Hands-on experience with at least one of Windows, Linux, or macOS, covering attack surfaces, malware behaviour, and common threat-actor tradecraft. - Familiarity with techniques mapped to MITRE ATT&CK, including credential dumping, lateral movement, persistence, and exfiltration. - Working knowledge of core networking concepts such as ports, protocols, NAT, public versus private addressing, and VLANs. - Strong written and verbal communication, with the ability to translate complex findings for varied audiences.
Nice to have - Comfort using AI tooling to accelerate analysis while validating outputs before acting. - Willingness to contribute through blogs, conference talks, webinars, or research publications.
Benefits and work setup - Fully remote within Australia, with shifts aligned to Western Australia or East Coast business hours. - Competitive base compensation plus bonus and equity, with stock options for full-time staff. - Annual Summer Summit trip to the US and additional local in-person events in Australia. - Home office setup reimbursement, monthly phone and internet allowance, and a recurring tech stipend. - Twelve weeks paid parental leave for primary and secondary carers, subsidised private health cover, and access to a coaching and development platform.