Job title: Incident Responder
Job type: Permanent
Emp type: Full-time
Industry: Financials
Location: Remote
Job published: 23-07-2026
Job ID: 70581

Job Description

A global enterprise is growing its Cyber Threat Detection & Response team.

This isn't a traditional SOC where you'll spend your day clearing queues or chasing false positives. The fundamentals are already well covered, allowing the team to focus on higher-value work.

You'll investigate sophisticated threats, improve detection capabilities, hunt for adversary activity, and work closely with engineering teams to strengthen security controls. Depending on your experience, you'll either focus on deep technical investigations or lead the coordination of cyber security incidents, with opportunities to develop across both areas over time.

Tier 1 monitoring has largely been removed from the model, with technology owners responsible for first-line monitoring. That allows this team to concentrate on complex investigations, incident response, threat hunting and continuously improving the organisation's defensive capability.

This is a team that wants to understand how attackers operate, improve detection logic, and build stronger relationships across engineering, infrastructure and security teams—not simply work through an endless stream of routine alerts.

What they're looking for

  • Experience investigating security incidents within a SOC, Cyber Defence or Incident Response environment.
  • Strong SIEM experience (Splunk or similar), including alert investigation, detection tuning or rule creation.
  • Hands-on EDR experience, with the ability to investigate endpoint activity and understand attacker behaviour.
  • Strong understanding of phishing investigations, including analysing email headers, links, attachments and indicators of compromise.
  • Knowledge of attacker tactics, techniques and procedures (MITRE ATT&CK).
  • Excellent communication skills and the ability to work with both technical teams and business stakeholders.

Whether your background is more technical investigation or incident response coordination, you'll join a mature cyber security function focused on solving complex security problems rather than simply responding to alerts.

russell@theonset.com.au / 0438984265