The Role
Investigate and triage complex security alerts using Splunk, Microsoft Sentinel and SentinelOne; perform endpoint containment with CrowdStrike and Microsoft Defender; tune detections with KQL and SPL; conduct MITRE ATT&CK-based threat hunting; produce incident reports; understand DLP; participate in paid on-call roster every three weeks.
Summary Generated by Built In
Position Title: SOC Analyst
Location: Canberra, ACT - Australia
Role Purpose :
Join our Australian SOC team as a SOC Analyst. In this role, you will be the "engine room" of our security operations, moving beyond basic alert monitoring to lead deep investigations across a diverse range of client environments in Asia Pacific (APAC). You will work with a world-class security stack and have the autonomy to hunt for threats and recommend custom detections.
Key Responsibilities
Summary
- Triage and Investigation: Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs.
- Endpoint Response: Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR.
- Detection Tuning: Optimise detection rules using KQL and SPL to enhance our proactive defence posture.
- Threat Hunting: Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity.
- Reporting & Mentorship: Produce detailed incident reports for technical and executive stakeholders.
- DLP: Understand data-loss prevention in the context of Security Operations.
- On-call: Participate in paid on-call roster every 3 weeks.
Skills, Knowledge & Expertise
What we are looking for in you
- Experience: 2–4 years in a SOC or high-pressure security operations environment.
- Tooling Expertise: Hands-on proficiency in Splunk, Sentinel, CrowdStrike, and Microsoft Defender. Experience with other SIEM and EDR technologies highly regarded.
- Technical Skills: Strong understanding of TCP/IP, Windows/Linux internals, Cloud Security and common attack vectors (Phishing, Ransomware, Living-off-the-Land).
- Certifications: One or more of the following: SC-200, Splunk Core Certified Power User, CompTIA CySA+, or SANS GCIH.
- Communication: Ability to clearly articulate technical risks to non-technical client stakeholders verbally and/or via email and ticketing system.
Job Benefits
Behaviours
- Client-focused with a proactive and solution-oriented mindset.
- High attention to detail and commitment to quality.
- Collaborative and able to work effectively across teams.
- Comfortable managing multiple priorities in a fast-paced environment.
- Curious and eager to learn, with a passion for cybersecurity.
- Professional and confident in client-facing scenarios.
Ways of working
- Focusing on Clients and Customers.
- Working as One NCC.
- Always Learning.
- Being Inclusive and Respectful.
- Delivering Brilliantly.
Our company
At NCC Group, our mission is to create a more secure digital future. That mission underpins everything we do, from our work with our incredible clients to groundbreaking research shaping our industry. Our teams' partner with clients across a multitude of industries, delving into, securing new products, and emerging technologies, as well as solving complex security problems. As global leaders in cyber and escrow, NCC Group is a people-powered business seeking the next group of brilliant minds to join our ranks.
Our colleagues are our greatest asset, and NCC Group is committed to providing an inclusive and supportive work environment that fosters creativity, collaboration, authenticity, and accountability. We want colleagues to put down roots at NCC Group, and we offer a comprehensive benefits package, as well as opportunities for learning and development and career growth. We believe our people are at their brilliant best when they feel bolstered in all aspects of their well-being, and we offer wellness programs and flexible working arrangements to provide that vital support.
Come join us?
About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
Skills Required
- 2-4 years in a SOC or security operations environment
- Hands-on proficiency with Splunk, Microsoft Sentinel, SentinelOne, CrowdStrike Falcon, and Microsoft Defender for Endpoint
- Experience with EDR and SIEM technologies and incident response workflows
- Detection tuning using KQL and SPL
- Threat hunting experience using the MITRE ATT&CK framework
- Strong understanding of TCP/IP, Windows and Linux internals, cloud security, and common attack vectors
- One or more certifications: SC-200, Splunk Core Certified Power User, CompTIA CySA+, or SANS GCIH
- Ability to communicate technical risks clearly to non-technical stakeholders
- Understanding of data loss prevention (DLP) in security operations
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
NCC Group is a global cyber security and resilience company that helps organizations manage risk, strengthen resilience, and build trust. They provide services in cyber security consulting, managed services, technical assurance, and software escrow.









