← all opportunities

LH-08127

buyict×3

Senior Cyber Threat Analyst

minimum of 3 Senior Cyber Threat Analyst

Services AustraliabaselineInvited sellersHybridACTcloses in 4 days

3 agency ads are matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.

Sign up free

Your CVs matching this role

0

Sign in to see which of your uploaded CVs match this role.

Candidate Search

Find candidates for this role externally, then cache them here.

Sign in to search candidates for this role.

Job description

Cyber Threat Analysts need to understand cyber intrusion activities then use their research skills to provide reporting on threat modelling and intelligence. The Cyber Threat Analyst will have cyber threat hunting, malware analysis, AI engineering and incident response skillset and will be responsible for conducting technical analysis and investigative activities to identify, assess and report on malicious or suspicious cyber activity affecting the agency. The role supports proactive threat hunting and incident response operations and contributes to strengthening the agency’s cyber defensive posture through timely analysis and reporting. Key duties and responsibilities Conduct proactive cyber hunt activities based on hypotheses, intelligence reporting, anomalous activity and identified risks. Investigate cyber intrusion activity and suspicious behaviour across networks, systems and data sources. Support incident response activities through technical triage, investigation, containment support and reporting. Research adversary tactics, techniques and procedures and translate findings into threat modelling and actionable reporting. Work closely with threat intelligence, detection, vulnerability management and other cyber teams to improve investigative outcomes and defensive uplift. Document investigative findings, methods, artefacts and recommendations in a clear and defensible manner. Contribute to knowledge transfer, mentoring and capability uplift of APS staff within the Hunt and Incident Response function. Ability to work across multiple cyber disciplines and contribute to technically complex operational outcomes. Manage intrusion and analysis work with the ability to make decisions on appropriate response and escalate as necessary. Manage complex threat intelligence/modelling tasks and/or threat assessments. Manage major Information Security incidents. Assist with corporate response to an Information Security incident. Identifies and implements improved controls to reflect changes in factors such as threat levels and legislation. Undertake advanced research into vulnerabilities or cryptography, including producing complex exploits, undertake effective reverse engineering and/or effectively researched mitigation bypasses. Analyse security risks, identify control deficiencies, develop remediation strategies and implement security engineering solutions within large and complex ICT environments. Technical skills (continued) Understanding of investigation and forensic techniques and tools. Design, code, verify, test, document, amend and refactors moderately complex programs/scripts. SFIA: Intrusion Detection and Analysis level 5 Threat Intelligence, Assessment and Threat Modelling level 5 Research level 4 Risk Assessment level 5 Essential Technologies: Microsoft Defender Query tables within Advanced Hunting (using KQL) to identify logs that answer investigative questions i.e. Network Events, Email Events, and Device File Events. Create and store custom playbooks. Elastic Use Kibana Endpoint, Events, NET and TI feeds to identify logs that answer investigative questions, using KQL Lucene and/or ES|QL queries. Navigate dashboards, review and respond to security alerts, imported from Microsoft Defender and Qradar. GatewayPE - Extrahop: Identify Communications from hosts to external IPs and domains. Search Extrahop to identify if malicious domains have reached endpoints. Use available data to extrapolate the nature of network communications from hosts and enemy domains & IPs. Log02: Use Linux command line skills to navigate through log02 files, such as windows event and firewall logs. AUPDNS Use Threat Intelligence to interrogate potential communication with suspicious domains. Highly Desirable technologies::: Engine Server FlareVM Malware Analysis tools HxD Pestudio Sysinternal QRadar Windows Server Linux Active Directory Microsoft Entra ID. Identity and Access Management (IAM) technologies. Security Information Event management (SIEM) platforms: Microsoft Sentinel or equivalent. Security Orchestration, Automation and Response (SOAR) platforms. Vulnerability management platforms: Rapid7 Tenable Microsoft Defender. Endpoint Detection and Response (EDR) technologies.Cloud platforms: Microsoft Azure Amazon Web Services Google Cloud Platform Network, firewall and infrastructure security technologies. Infrastructure hardening and security baseline implementation. Security automation and scripting: PowerShell Python. Security architecture and systems integration concepts. Knowledge / Qualifications Relevant tertiary qualifications, industry certifications or equivalent practical experience in cyber security will be regarded favourably Relevant experience in cyber security operations, cyber threat analysis, incident response, digital forensics and threat hunting is required. Other required cyber security knowledge and experience: Protective Security Policy Framework (PSPF) Information Security Manual (ISM) Essential Eight Strategies National Institute of Standards and Technology (NIST) Appropriate and relevant certifications including: CREST Certified Network Intrusion Analyst, CREST Certified Host Intrusion Analyst, CREST Certified Malware Reverse Engineer. Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. Demonstrated ability in cyber hunt and analysis of cyber threats, identifying threats within research conducted or provided. Constructs Hunt exercises based on research. 2. Demonstrated ability to lead, engage, influence, communicate and collaborate with a broad range of stakeholders, including senior executives, technical specialists, business representatives, other government agencies/departments and external providers. 3. Demonstrated and proven experience performing the duties and responsibilities relevant to the role being applied for, including the required technical skills, technologies, frameworks and methodologies identified in the RFQ. 4. Demonstrated understanding and practical application of cyber security operations and risk management principles, including threat detection, hunting and analysis, security monitoring, threat intelligence, vulnerability management, incident response and relevant Australian Government security frameworks such as the PSPF, ISM and Essential Eight. 5. Demonstrated ability to communicate complex technical and cyber security concepts to both technical and non-technical audiences and contribute to capability uplift through mentoring, collaboration and knowledge transfer activities. Desirable criteria 1. Experience working within large-scale enterprise environments involving cloud platforms, identity and access management, security operations, infrastructure, applications and data services. 2. Demonstrated ability to deliver outcomes within tight timeframes while managing competing priorities, dependencies and stakeholder expectations. 3. Demonstrated and proven experience performing the duties and responsibilities relevant to the specialised sub role (Senior Cyber Threat Hunter, Senior Malware Analyst, Senior AI Engineer), including the required technical skills, technologies, frameworks and methodologies identified/applicable. 4. Demonstrated experience identifying, assessing and managing cyber security risks, vulnerabilities, compliance obligations and remediation activities. Demonstrated experience engineering threat analysis tool integrations across a broad enterprise security ecosystem, including technologies such as threat intelligence platforms, endpoint or network detection and response, identity and access management, vulnerability management, cloud security, firewalls and case management. Opportunity summary Sellers can submit Up to 2 candidates Number of sellers invited Between 5 and 10 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia

3 matches locked

Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.

Other open contracts for Services Australia

Related reading