- Location
- Melbourne
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Closing date
- Today
- Source
- CareersPage
Description
Level 3 SOC Engineer
Melbourne | Permanent | Hybrid
We are partnering with a large, established cybersecurity firm to appoint an experienced Level 3 SOC Engineer to its Melbourne team.
This senior, hands-on position will lead complex security investigations, support proactive threat hunting and provide technical guidance to junior SOC analysts. You will work within a mature security environment protecting enterprise and critical client systems against evolving cyber threats.
Key responsibilities
- Lead the investigation, containment and remediation of complex security incidents
- Perform advanced threat hunting, malware analysis and root-cause investigations
- Analyse alerts and telemetry across SIEM, EDR, network and cloud-security platforms
- Develop and improve detection rules, playbooks and incident-response procedures
- Automate SOC processes to improve detection and response times
- Provide escalation support and mentoring to Level 1 and Level 2 analysts
- Produce clear incident reports and communicate findings to technical and business stakeholders
Technologies may include
- Microsoft Sentinel and Splunk
- Microsoft Defender XDR and CrowdStrike Falcon
- Palo Alto Networks and Fortinet security platforms
- Azure and AWS cloud-security services
- SOAR platforms and automated-response playbooks
- Wireshark and network-analysis tools
- Python, PowerShell and KQL
- MITRE ATT&CK and common threat-intelligence platforms
About you
- Strong experience in a Level 3 SOC, senior security operations or incident-response role
- Advanced knowledge of SIEM, EDR/XDR and security-monitoring platforms
- Experience investigating threats across Windows, Linux, network and cloud environments
- Strong understanding of attacker techniques and the MITRE ATT&CK framework
- Scripting or security-automation capability
- Strong analytical, problem-solving and stakeholder-communication skills
- Relevant cybersecurity certifications will be highly regarded
Applicants must currently be based in Australia and hold unrestricted Australian working rights.
This is an excellent opportunity to join a major cybersecurity organisation, work alongside experienced specialists and respond to sophisticated threats within a well-established security operation.
To discuss this opportunity confidentially, submit your application to Us.