Back to Jobs

Lead Cyber security AnalystApply Now

ACT

IT & Telecomms IT Security

  • Canberra, ACT
  • Hybrid
  • 12-Month Contract + Extensions
Lead Cyber Threat Analyst

An exciting opportunity is available for experienced Lead Cyber Threat Analysts to join a major Federal Government cyber security team supporting critical systems and services.
This role will see you leading threat hunting, cyber investigations, incident response activities, and intelligence-led security operations within a complex enterprise environment.
Security Requirements Applicants must be Australian Citizens and able to obtain or hold an NV1 Security Clearance.
Key Responsibilities

  • Lead proactive cyber threat hunting activities across enterprise environments.
  • Investigate cyber security incidents, intrusions and suspicious activity.
  • Conduct technical analysis of emerging threats, adversary behaviours, and attack patterns.
  • Support and lead incident response activities, including containment, investigation and reporting.
  • Develop threat intelligence products, threat models and risk assessments.
  • Analyse vulnerabilities, identify security gaps and recommend remediation strategies.
  • Collaborate with cyber operations, threat intelligence, engineering and security teams.
  • Mentor team members and contribute to capability uplift initiatives.
  • Produce high-quality reports and briefings for technical and non-technical stakeholders.

Essential Skills & Experience

  • Extensive experience in Cyber Threat Hunting and Threat Analysis.
  • Strong Incident Response and Cyber Investigation experience.
  • Expertise with Microsoft Defender XDR and Advanced Hunting using KQL.
  • Experience working with SIEM platforms such as Microsoft Sentinel, QRadar, or Elastic.
  • Strong understanding of Threat Intelligence and Threat Modelling.
  • Experience within large enterprise or government cyber security environments.
  • Knowledge of PSPF, ISM, Essential Eight and NIST security frameworks.
  • Excellent stakeholder engagement and communication skills.

Desirable Experience

  • Malware Analysis and Reverse Engineering.
  • Digital Forensics.
  • Security Automation and SOAR platforms.
  • Rapid7, Tenable or other vulnerability management solutions.
  • Active Directory and Microsoft Entra ID.
  • Azure, AWS or Google Cloud security.
  • PowerShell and Python scripting.
  • Identity and Access Management (IAM) technologies.

What’s on Offer

  • Initial 12-month contract.
  • Potential extensions up to 24 months.
  • Hybrid working arrangements.
  • Opportunity to work on high-impact cyber security initiatives.
  • Exposure to advanced threat hunting, incident response and security technologies.

Application Deadline Applications close 13 October 2026, so early applications are encouraged.ply now or contact Tushar Musale for a confidential discussion.

Please include your updated CV, security clearance status, availability and daily rate expectations with your application.
Apply Now