SOC Analyst
Join our 24/7 Security Operations Centre — monitor, triage and respond to threats across managed clients using our Defend360 platform.
The role
SPG's Security Operations Centre provides 24/7 monitoring, managed detection and response for clients across finance, government and critical infrastructure. As a SOC Analyst you will triage alerts, investigate incidents and hunt for threats across client environments, working with SIEM, EDR and our AI-powered Defend360 platform. This is a hands-on operational role with a clear development path into senior analysis, incident response or engineering.
What you'll do
- Monitor and triage security alerts across client environments on a rotating shift roster
- Investigate and escalate incidents following playbooks and runbooks
- Perform threat hunting across SIEM and EDR telemetry
- Document incidents and contribute to post-incident reviews
- Tune detection rules and reduce false positives in collaboration with the engineering team
- Communicate with clients during active incidents with clear, calm updates
What you'll bring
- 1+ years in a SOC, security operations or incident response role (or strong IT/security fundamentals)
- Familiarity with SIEM platforms, EDR tooling and common attack techniques (MITRE ATT&CK)
- Understanding of networking fundamentals, Windows and Linux operating systems
- Willingness to work a rotating shift roster supporting 24/7 operations
- Australian citizenship or permanent residency (client clearance requirements)
Nice to have
- Certifications such as Security+, CySA+, SC-200 or BTL1
- Scripting experience (Python, PowerShell, KQL)
- Exposure to DFIR processes or digital forensics tooling