Director - Cyber & Digital Forensic Investigations - Sydney
A AUD 75K-227K (estimate) Executive-level Full Time
Tasks
- Advise regulators under incident timelines
- Analyze AWS Azure GCP audit trails
- Analyze network flow data
- Apply DFIR tooling during investigations
- Apply chain of custody discipline
- Communicate with senior stakeholders during incidents
- Conduct EDR driven hunting
- Integrate threat intelligence into engagement narrative
- Lead breach response delivery
- Lead host network cloud memory forensics
- Mentor delivery managers
- Perform dead box and live imaging
- Perform identity provider log analysis
- Perform post incident hardening
- Provide sanctions advisory payment decision support
- Reconstruct SIEM and log aggregation
- Reconstruct command and control activity
- Stay current on threat actor tactics and tooling
- Support breach disclosure and notification
- Support ransomware response negotiations
- Support threat actor attribution
- Triage malware indicators
- Validate decryptors and backup recovery
Perks/Benefits
- N/A
Skills/Tech-stack
ACSC | APRA | ASD | AUSTRAC | AWS | Arkime | Azure | Breach response | Carbon Black | Chain of Custody | Cloud platform | CrowdStrike Falcon | Data Breach | Dead Box Imaging | Digital forensics | EDR Hunting | Elastic | EnCase | Entra ID | Essential Eight | FTK | Forensic Imaging | Ghidra | Google Cloud | Google Cloud Platform | Google Workspace | IDA Pro | Incident Response | Live forensics | Log Aggregation | MISP | Magnet Axiom | Malware analysis | Malware triage | Mandiant Advantage | Memory Forensics | Microsoft 365 | Microsoft Defender | Microsoft Entra | Microsoft Entra ID | Microsoft Sentinel | Mitre Attack | NIST 800 | NIST 800-61 | NIST 800-86 | Network Forensics | Notifiable Data Breach | OAIC | Okta | QRadar | Ransomware response | Recorded Future | Rekall | Reverse Engineering | SANS DFIR | SIEM | SOCI Act | SOCI Act 2018 | SentinelOne | Splunk | Threat Actor | Threat Intelligence | Threat actor attribution | Volatility | Wireshark | X-Ways | X64dbg | Zeek
Education
N/A
Regions
Countries
States
Cities
Related jobs
-
ACSC Essential Eight | AI Assisted DFIR | APRA CPS 234 | APRA Information Security Operational Risk | AUSTRAC ComplianceSenior-level Full TimeSydney, New South Wales, Australia1d ago
-
ACSC | AI Assisted DFIR | AI Assisted DFIR Governance | APRA | APRA CPS ComplianceSenior-level Full TimeSydney, New South Wales, Australia1d ago
-
Head of Cyber Security and Risk AUD 131K-167KBy Design | Cyber Risk | Cyber Security | Cyber policy | GovernanceFlexible public holidays | Flexible working arrangements | Gender Affirmation Leave | Hybrid working | Inclusive workplace initiativesExecutive-level Full TimeSydney, NSW, Australia11d ago
-
Head of Cyber Security and Risk AUD 131K-167KBy Design | Compliance | Cyber Risk | Cyber Risk Management | Cyber SecurityFlexible working arrangements | Gender Affirmation Leave | Hybrid working | Inclusive leave options | Paid parental leaveExecutive-level Full TimeMelbourne, VIC, Australia11d ago
-
Head of Cyber Security Operations AUD 75K-200KCrisis management | Cyber Security | Executive Communication | Forensics | IEC 27001Access to professional memberships and industry networks | Discounted services | Employee assistance program | Flexible work arrangements | Parental leaveExecutive-level Full TimeAustralia1mo ago