Australia
1 day ago
Senior Security Engineer, Incident Response Team logo

Senior Security Engineer, Incident Response Team

Jobgether

Senior Security Engineer, Incident Response Team

Senior Security Engineer needed for a partner company's Incident Response Team, based in Australia. The role leads complex DFIR investigations and high-severity incident response across cloud and corporate environments, combining detection engineering, automation, threat intelligence, and operational improvement within a global 24/7 security organization.

AI-enabledHybridFull-timeSeniorDigital Forensics And Incident Response (DFIR)Git

Salary

Not specified

Work Location

Australia, AU

Work Model

Hybrid; fully remote position based in Australia

Employment Type

Full-time

Experience Level

Senior

Core Qualifications

Technical (Must-have)
Digital Forensics and Incident Response (DFIR)GitGitLabSIEMEDRDetection EngineeringAWSGCPThreat IntelligenceMITRE ATT&CKPythonScriptingSOARAIMachine Learning
Soft Skills
AnalyticalProblem-solvingJudgmentComposureWritten communicationProactive mindsetCollaborationMentoring

Key Responsibilities

  • Lead and coordinate end-to-end response to high-severity security incidents across cloud and corporate environments.
  • Cover the APAC operating window within a global 24/7 follow-the-sun model and participate in a rotating on-call schedule.
  • Prepare clear, concise executive communications that keep stakeholders informed throughout significant security incidents.
  • Conduct complex security investigations using strong Digital Forensics and Incident Response (DFIR) methodologies.
  • Partner with Detection Engineering to develop and improve SIEM use cases, alerting strategies, detection capabilities, and telemetry pipelines.
  • Build and enhance automation and AI-assisted workflows to improve incident triage, investigation efficiency, response consistency, and detection fidelity.
  • Collaborate with Threat Intelligence teams to contextualize emerging threats, understand adversary behavior, and strengthen detection coverage.
  • Conduct root cause analysis and lead post-incident reviews, translating findings into measurable improvements in security controls and processes.
  • Develop and maintain incident response runbooks, playbooks, procedures, and operational documentation.
  • Collaborate with Engineering, Infrastructure, Legal, Product, Communications, and other teams during incidents and proactive security initiatives such as tabletop exercises.
  • Mentor other security engineers and contribute to improving the team's overall incident response maturity and operational effectiveness.
Security EngineerIncident ResponseDFIRCloud SecurityDetection EngineeringThreat IntelligenceAutomationAISeniorAustralia