CTIR - Cyber Threat Response Analyst (Adversary Operations)
Summary
Adversary-focused Cyber Threat Response Analyst on a global Cyber Threat and Incident Response team for a financial services organization, performing intelligence-driven threat hunting across large-scale telemetry (EDR, SIEM, TIP) using MITRE ATT&CK/ATLAS, with Splunk/Google SecOps and Windows/Linux/AD/cloud environments.
Salary: $200k - $230k plus bonus on top
The OpportunityJoin a diverse, global Cyber Threat and Incident Response team within the Cyber Security function of a global financial services organisation's Technology division. This role is based in Sydney within the Cyber Threat Defense team.
What You'll Do
- Perform hypothesis-driven threat hunting, combining behavioral threat intelligence, controls-based research, and defensive cyber expertise to improve overall cybersecurity posture
- Conduct proactive, intelligence-driven threat hunting across a global environment using attacker TTPs, behavioral analytics, and large-scale telemetry (EDR, SIEM, TIP)
- Perform threat modeling and execute structured, hypothesis-driven hunts to uncover previously undetected threats
- Identify detective and preventative control gaps and translate findings into actionable improvements
- Collaborate closely with Security Operations and Detection Engineering teams
- Apply frameworks such as MITRE ATT&CK and MITRE ATLAS operationally, while maintaining a continuous learning mindset around adversarial techniques and AI-driven tooling
- Experience in aggregate log analysis (Splunk, Google SecOps, or similar) and with an Endpoint Detection and Response platform
- Ability to translate technical findings into actionable insights and communicate clearly with both technical and non-technical stakeholders
- Offensive security/adversarial mindset with strong knowledge of threat actor TTPs
- Experience threat hunting in enterprise infrastructure, including Windows/Linux systems, Active Directory, cloud platforms, and identity systems
- Minimum 4 years' related security or technology experience in enterprise environments, with a focus on threat hunting, security operations, or penetration testing