# SOC Analyst (Canberra - Remote) at NCC Group

AI Level 1, AI centrality 37 out of 100. Remote (Sydney, New South Wales).

## Details

- Company: [NCC Group](https://jobsbylevel.com/companies/ncc-group)
- AI level: AI Level 1 (score 37 out of 100)
- Location: Remote (Sydney, New South Wales)
- Posted: October 7, 2026
- Apply: https://jobsbylevel.com/go/7c3650fa-d783-4905-9210-df4c91525db6

## Description

Position Title: SOC Analyst Location: Canberra, ACT - Australia Role Purpose : Join our Australian SOC team as a SOC Analyst. In this role, you will be the "engine room" of our security operations, moving beyond basic alert monitoring to lead deep investigations across a diverse range of client environments in Asia Pacific (APAC). You will work with a world-class security stack and have the autonomy to hunt for threats and recommend custom detections. Key Responsibilities Summary Triage and Investigation : Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs. Endpoint Response : Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR. Detection Tuning : Optimise detection rules using KQL and SPL to enhance our proactive defence posture. Threat Hunting : Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity. Reporting & Mentorship : Produce detailed incident reports for technical and executive stakeholders. DLP : Understand data-loss prevention in the context of Security Operations. On-call: Participate in paid on-call roster every 3 weeks. Skills, Knowledge & Expertise What we are looking for in you Experience: 2–4 years in a SOC or high-pressure security operations environment. Tooling Expertise: Hands-on proficiency in Splunk, Sentinel, CrowdStrike, and Microsoft Defender. Experience with other SIEM and EDR technologies highly regarded. Technical Skills: Strong understanding of TCP/IP, Windows/Linux internals, Cloud Security and common attack vectors (Phishing, Ransomware, Living-off-the-Land). Certifications: One or more of the following: SC-200, Splunk Core Certified Power User, CompTIA CySA+, or SANS GCIH. Communication: Ability to clearly articulate technical risks to non-technical client stakeholders verbally and/or via email and ticketing system.

Source: https://jobsbylevel.com/jobs/soc-analyst-canberra-remote-at-ncc-group-f186f2

## Cite this page

Level. https://jobsbylevel.com/jobs/soc-analyst-canberra-remote-at-ncc-group-f186f2.

Get job alerts: https://jobsbylevel.com/newsletter
