Principal Cyber Threat Response Analyst
- Permanent Position
- Eastern Suburbs Location | Hybrid Working Arrangement
- Splunk Enterprise Security | MITRE ATT&CK | ISO 27001/27002 & NIST
The Role
This is a senior, high-impact cyber security opportunity for a Principal-level practitioner to play a defining role in strengthening threat detection, vulnerability management, and security intelligence across a complex technology environment. Working within a well-resourced cyber security function, you will leverage advanced SIEM capabilities, including Splunk Enterprise Security, to deliver effective monitoring, threat hunting, and incident response. You will apply deep expertise across operating systems, security frameworks, and modern threat landscapes to protect critical systems and data, while continuously improving detection coverage and aligning security controls with industry-leading standards including ISO 27001/27002, NIST, and CIS.
Key Responsibilities
- Monitor, detect, and investigate cyber threats using advanced SIEM capabilities, including Splunk Enterprise Security and SPL-based threat hunting techniques, to ensure timely identification and mitigation of security risks.
- Lead vulnerability management activities, identifying, prioritising, and driving remediation across the enterprise environment in line with a risk-based approach and aligned to relevant security frameworks.
- Conduct end-to-end incident response, from initial triage and containment through to root cause analysis, lessons learned, and improvement recommendations that strengthen the organisation’s security posture.
- Enhance and refine detection use cases, continuously improving coverage, fidelity, and response playbooks in alignment with MITRE ATT&CK TTPs, APT intelligence, and evolving threat landscapes.
- Translate complex technical risks and security findings into clear, risk-based reporting and recommendations for stakeholders, supporting informed security decision-making across the organisation.
Skills & Experience Required
- Proven experience in cyber security operations, encompassing vulnerability management, threat detection, and incident response across complex enterprise environments.
- Advanced hands-on proficiency with SIEM platforms, preferably Splunk Enterprise Security, including SPL query development, use case tuning, and threat hunting workflows.
- Strong knowledge of security frameworks including ISO 27001/27002, NIST, and CIS, with demonstrated ability to align security controls and operational practices to these standards.
- Solid understanding of MITRE ATT&CK, APT groups, TTPs, threat modelling, and attack vectors, with practical experience applying this knowledge to detection engineering and response activities.
- Excellent stakeholder engagement and communication skills, with the ability to translate technical findings into clear, business-relevant risk insights for diverse audiences, from technical teams to senior leadership.
What’s in it for You
- Permanent ongoing position.
- High-impact, principal-level role embedded within a mature and well-resourced cyber security function.
- Work at the forefront of threat intelligence, detection engineering, and vulnerability management in a complex enterprise environment.
Apply today and Jimmy Nguyen will reach out to disclose further information.