LH-07772
buyict×1ClosedLead Cyber Operations Security Expert
1 Lead Cyber Operations Security Expert
2 agency ads are matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.
Sign up freeYour CVs matching this role
0Sign in to see which of your uploaded CVs match this role.
Candidate Search
Find candidates for this role externally, then cache them here.
Sign in to search candidates for this role.
Job description
Role/s: 1 x EL1 Cyber Operations Security Expert The Cyber Operations Security Expert, will undertake technical cyber security activities under the leadership of the Director of Cyber Security Operations. The Cyber Operations Security Expert,must possess and demonstrate technical competency in areas of cloud security (Azure/AWS), endpoint and network security, threat intelligence and hunting, data loss prevention, vulnerability management, and incident response. The Cyber Operations Security Expert,will be required to support and contribute to the protection of the Agency’s systems, users, and data, to support NDIA’s objectives to “build a world-leading National Disability Insurance Scheme”. As part of the Cyber Security Operations team, the role will help ensure that NDIA has the capability to build and protect cyber-resilient information technology platforms and support strategic objectives. Supplier Briefing: A supplier briefing will be held for this role on 9 September 2026 – meeting details will be posted in the “Q&A” section of the RFQ for invited Sellers only. Rate: The proposed rate should reflect candidate's skills and experience against the Evaluation Criteria. Candidates that do not demonstrate these criteria will not be assessed. Candidates should be aware that rates may be negotiated further as part of the selection process. Citizenship: As part of the eligibility and suitability requirement, NDIA seeks Labour Hire Workers who are Australian citizens only. Successful candidates will be required to furnish valid evidence of citizenship during the Pre-engagement Check. Labour Hire Licence: Applicable for ACT, VIC and QLD: Labour hire licences are required in the state that specified personnel are being contracted. Key duties and responsibilities The role will involve the key responsibilities: Lead proactive monitoring, investigation, and mitigation of security incidents within security tools (including Sentinel, Microsoft Defender 365 stack, Azure Security Centre, Splunk) Analyse security event data and identifying suspicious/malicious activity from networks and systems Lead incident response activities including initial and detailed investigation, computer forensics, chain of custody implications Respond to events and incidents using established Standard Operating Procedures (SOPs) Be a point of escalation for complex incidents and act as a subject matter expert in areas of cloud security, active defence, and threat mitigation Develop and manage phishing simulations Research new and evolving threats and vulnerabilities to the Agency’s threat landscape Conduct log analysis and develop visualisation and reporting within Splunk Identify critical data sources required by cyber for ingestion and normalisation into the SIEMs Collaborate with Security Operations and IT engineers to implement security controls Supervise, mentor and develop junior staff, and identify areas of people, process, and defensive tool improvement Produce and disseminate incident response reports, activity reports, and intelligence and threat briefs Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. Minimum 7 years in IT or cybersecurity, with at least 3 years operating at a management or senior architectural level. 2. Direct experience leading high severity cyber investigations, threat hunting, and crisis management. 3. Deep, multi-domain technology experience encompassing cloud environments (AWS, Azure), Zero Trust Network Architecture (ZTNA), and DevSecOps. 4. Proven track record of aligning security programs with global frameworks such as NIST, ISO 27001, or the Australian ASD Essential Eight. Desirable criteria 1. Demonstrated familiarity with log aggregation and Security Incident and Event Management (SIEM) systems 2. Knowledge of the Information Security Manual (ISM) and cyber security concepts. 3. Demonstrated experience implementing and using Incident Response Frameworks (NIST SP 800-61 Incident Handling Guide, Mitre Frameworks) 4. Formal tertiary qualifications or industry certifications in a cyber security related field (e.g. Azure/AWS, Splunk Certified) Opportunity summary Sellers can submit Up to 6 candidates Number of sellers invited More than 10 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia
2 matches locked
Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.
Other open contracts for National Disability Insurance Agency
- LH-07850Manager Delivery ManagersNSWcloses in 1 day
- LH-07779Lead Domain ArchitectQLD, ACT, VIC, NSW, SAcloses in 3 days
- LH-07824Manager CIAM Service ManagerQLD, ACT, VIC, NSWcloses in 3 days
- LH-07534Lead Domain ArchitectQLD, ACT, VIC, NSW, SAcloses in 4 days
- LH-07826Senior Solution ArchitectQLD, WA, ACT, VIC, NSW, SAcloses in 4 days