Level

This role is closed. NCC Group is no longer accepting applications for it.

Open roles like this one

See all open roles at NCC Group

Get new remote cybersecurity jobs like this

Free. Unsubscribe in one click.

NCC Group

SOC Analyst (Canberra - Remote)

AI in this role


Position Title: SOC Analyst
Location: Canberra, ACT - Australia 
Role Purpose :
Join our Australian SOC team as a SOC Analyst. In this role, you will be the "engine room" of our security operations, moving beyond basic alert monitoring to lead deep investigations across a diverse range of client environments in Asia Pacific (APAC). You will work with a world-class security stack and have the autonomy to hunt for threats and recommend custom detections.
 

Key Responsibilities

Summary 

  • Triage and Investigation: Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs. 

  • Endpoint Response: Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR. 

  • Detection Tuning: Optimise detection rules using KQL and SPL to enhance our proactive defence posture. 

  • Threat Hunting: Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity. 

  • Reporting & Mentorship: Produce detailed incident reports for technical and executive stakeholders. 

  • DLP: Understand data-loss prevention in the context of Security Operations. 

  • On-call: Participate in paid on-call roster every 3 weeks. 

Skills, Knowledge & Expertise

What we are looking for in you 
  • Experience: 2–4 years in a SOC or high-pressure security operations environment. 

  • Tooling Expertise: Hands-on proficiency in Splunk, Sentinel, CrowdStrike, and Microsoft Defender. Experience with other SIEM and EDR technologies highly regarded. 

  • Technical Skills: Strong understanding of TCP/IP, Windows/Linux internals, Cloud Security and common attack vectors (Phishing, Ransomware, Living-off-the-Land). 

  • Certifications: One or more of the following: SC-200, Splunk Core Certified Power User, CompTIA CySA+, or SANS GCIH. 

  • Communication: Ability to clearly articulate technical risks to non-technical client stakeholders verbally and/or via email and ticketing system. 

How we rate this

SOC Analyst (Canberra - Remote) at NCC Group rates 37 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Get new remote cybersecurity jobs by email

One email a week with the new remote cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More cybersecurity jobs

Related searches

Same AI level