Hybrid SOC Lead – Cyber Incident Response, Data Security

Posted 2 days ago

Apply now

About the role

  • SOC Lead managing advanced cyber incident response and data security for The Missing Link, an awarded IT provider in Australia.

Responsibilities

  • Lead end-to-end response for complex cyber security incidents
  • Design and enforce advanced incident response procedures
  • Develop sophisticated SIEM and EDR detections and search queries
  • Build dashboards covering alerts, KPIs, and SOC performance metrics
  • Conduct malware analysis, adversary tracking, and impact assessments
  • Produce detailed incident and threat intelligence reports
  • **Threat Intelligence & Hunting**
  • Analyse threat intelligence and map adversary TTPs
  • Develop and execute structured threat hunting programs
  • Identify emerging risks and environmental weaknesses
  • Recommend mitigation strategies to reduce organisational risk
  • **Data Security & Insider Threat**
  • Define and tune DLP policies and data protection controls
  • Investigate insider threat and data loss incidents
  • Align data security controls with business and regulatory requirements
  • **Automation & Continuous Improvement**
  • Build and optimise SOAR playbooks across SOC and IR workflows
  • Automate reporting and operational processes
  • Conduct SOC maturity assessments
  • Drive strategic improvements across security operations
  • **Leadership & Stakeholder Engagement**
  • Mentor and uplift L1 and L2 analysts
  • Partner with internal teams and stakeholders
  • Deliver consistent, high-quality security operations outcomes

Requirements

  • 7–12 years’ experience across Security Operations, Incident Response, and Data Security
  • Deep hands-on expertise with SIEM, EDR, DLP, and SOAR platforms
  • Strong background in Threat Intelligence and Threat Hunting
  • Proven experience improving SOC processes and operational maturity
  • Strong analytical capability and ability to lead complex investigations
  • **Preferred Certifications**
  • At least three of the following:
  • Splunk Core Certified Consultant
  • Splunk Certified Cybersecurity Defense Engineer
  • CrowdStrike Certified Falcon Responder or Hunter
  • Microsoft SC-400 or SC-401
  • Palo Alto XSOAR Engineer
  • CyberArk Sentry or Guardian
  • Google Cybersecurity Certificate
  • Professional Security Operations Engineer
  • **Highly Regarded:**
  • SANS FOR508 (or equivalent)
  • CISSP or CISM
  • CyberArk Guardian

Benefits

  • Supportive environment and fun collaborative culture
  • Training / mentoring programs
  • Regular, fun social events

Job title

SOC Lead – Cyber Incident Response, Data Security

Job type

Experience level

Senior

Salary

Not specified

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job