- Type
- Full-time
- Department
- Security
- Seniority
- Senior
- Education
- Master
- Source
- RecruiterFlow
Description
Staffstream is hiring a Senior Security Analyst for an Australian allied health provider that delivers clinical services to people living with disability. They run a cloud-only Microsoft 365 environment and are scaling up their cyber defence and detection and response capability as their digital footprint grows. You'd report directly to the IT Operations and Security Manager and take real ownership of day-to-day security operations.
This role has two genuine halves: architecting and delivering security uplift projects (Essential Eight hardening, identity and application control, data protection), and triaging incidents end to end. If you've only ever closed tickets without ever building or improving the systems behind them, that's only half the job here. This is a replacement role for someone with a genuine security analyst background, not a support role with security added on. This role is open to candidates based in the Philippines.
What you will actually do
Security operations and alert triage
- Own the day-to-day security alert queue across Microsoft 365 Defender, Sentinel (where in use), and Entra ID Identity Protection.
- Investigate and resolve incidents end to end using a standard incident handling workflow, from evidence through to a clean, documented resolution.
Incident response and playbook execution
- Execute documented playbooks across the full incident catalogue: phishing, identity compromise, data exfiltration, mail redirect, lost or stolen device, OAuth abuse, and privacy breach scenarios.
- Select and apply the right containment action based on the evidence in front of you, from investigation package collection through to device isolation and live response.
Threat hunting and detection engineering
- Write, tune, and maintain KQL queries and custom detection rules across Defender Advanced Hunting (and Sentinel, where in use).
- Close detection gaps and cut down false-positive noise through iterative rule refinement.
Security uplift and project delivery
- Actively drive security uplift projects: Essential Eight hardening, MFA maturity, Conditional Access uplift, application control, and data-layer protection.
- Deploy and validate hardening policies in Intune for application control, macro control, and legacy runtime restrictions.
- Contribute to application and data governance initiatives using Microsoft Defender for Cloud Apps and Microsoft Purview.
Identity, endpoint, and cloud security operations
- Investigate identity-based threats (risky user, risky sign-in, anomaly detections) and coordinate remediation.
- Own the employee offboarding security procedure and maintain endpoint security policy hygiene across Intune and Defender.
Compliance, reporting, and documentation
- Report notifiable cybersecurity incidents to the relevant regulator and provide incident summaries to leadership.
- Own and maintain SOC playbooks, runbooks, and detection library entries, and track hardening maturity progress against the roadmap.
Using AI as a genuine force multiplier
- Use AI tools to speed up KQL query authoring, incident summaries, and playbook drafting.
- Apply AI for structured software vetting and to flag red flags in third-party applications and browser extensions.
- Use AI to spot patterns across historical incidents and surface recurring root causes, and to draft first cuts of reports and documentation.
- At least 2 to 3 years of genuine, hands-on experience specifically as a Security Analyst, SOC Analyst, or Blue Team role, not primarily an IT support role with some security exposure added on.
- Demonstrated, hands-on experience across the Microsoft Defender suite (Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps).
- Experience with Entra ID (Azure AD), Conditional Access, and Identity Protection.
- Real experience writing and tuning KQL queries for threat hunting and detection.
- Experience with Microsoft Cloud App Security and Microsoft Purview.
- Experience with Microsoft Intune for endpoint security policy deployment.
- A genuine investigative mindset: you drive both incident triage and security uplift project work, not just one or the other.
- A bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent hands-on experience.
- Clear enough written and verbal communication to document playbooks and explain an incident when needed. This role is judged mainly on technical depth, but you still need to be understood.
- Experience with Microsoft Sentinel (common in larger organizations, genuinely useful but not required).
- Microsoft security certifications such as SC-200, SC-100, SC-300, AZ-500, or MS-500, or CompTIA Security+ or CySA+.
- Experience contributing to a company achieving or maintaining a security certification or accreditation (this is about the company's accreditation, not a personal certificate).
- Exposure to compliance regimes such as the Australian Privacy Principles, GDPR, or HIPAA, since the business handles sensitive personal data under similar obligations.
- Experience in health, disability, aged care, or another regulated, sensitive-data industry.
- Familiarity with the ACSC Essential Eight Maturity Model, ISM controls, or ACSC Intune hardening guidelines.
- This role is open to Philippines-based candidates. There's no requirement for international or Australian-specific work experience; strong local experience is genuinely fine.
- Fully remote, working full Australian business hours (9am to 5pm AEST/AEDT).
- Staffstream provides your work-from-home equipment.
A stable, full-time role with a business that genuinely needs you and wants you to grow into it. You'd be trusted to own your area, not micromanaged, working with a small team that values someone who can take things off their plate and run with them. On top of that, Staffstream looks after you properly:
- HMO health cover, with one dependent covered for free.
- Group life insurance.
- Paid leave credits.
- Work-from-home equipment provided.
You're employed compliantly under Philippine law: a proper local employment contract, your taxes handled correctly, and all your government-mandated benefits (SSS, PhilHealth, Pag-IBIG) plus 13th month pay. That means real security and peace of mind, not a loose freelance arrangement. Everything is above board and looked after for you.