Enter a job title or keyword

EL1 Lead Cyber Operations Security Expert


Job Location:

Canberra - Australia

Monthly Salary: Not provided by the employer
Posted: 9 September 2026 (3 hours ago)
Application Deadline: 7 December 2026
Vacancies: 1 Vacancy

Job Summary

Australian Citizens residing in Australia only respond.

Job details

Role/s: 1 x EL1 Cyber Operations Security Expert

The Cyber Operations Security Expert will undertake technical cyber security activities under the leadership of the Director of Cyber Security Operations. The Cyber Operations Security Expert must possess and demonstrate technical competency in areas of cloud security (Azure/AWS) endpoint and network security threat intelligence and hunting data loss prevention vulnerability management and incident response. The Cyber Operations Security Expert will be required to support and contribute to the protection of the Agencys systems users and data to support NDIAs objectives to build a world-leading National Disability Insurance Scheme.

As part of the Cyber Security Operations team the role will help ensure that NDIA has the capability to build and protect cyber-resilient information technology platforms and support strategic objectives.

Key duties and responsibilities

The role will involve the key responsibilities:

  • Lead proactive monitoring investigation and mitigation of security incidents within security tools (including Sentinel Microsoft Defender 365 stack Azure Security Centre Splunk)
  • Analyse security event data and identifying suspicious/malicious activity from networks and systems
  • Lead incident response activities including initial and detailed investigation computer forensics chain of custody implications
  • Respond to events and incidents using established Standard Operating Procedures (SOPs)
  • Be a point of escalation for complex incidents and act as a subject matter expert in areas of cloud security active defence and threat mitigation
  • Develop and manage phishing simulations
  • Research new and evolving threats and vulnerabilities to the Agencys threat landscape
  • Conduct log analysis and develop visualisation and reporting within Splunk
  • Identify critical data sources required by cyber for ingestion and normalisation into the SIEMs
  • Collaborate with Security Operations and IT engineers to implement security controls
  • Supervise mentor and develop junior staff and identify areas of people process and defensive tool improvement
  • Produce and disseminate incident response reports activity reports and intelligence and threat briefs