Overview

Security Operations Center Analyst Jobs in Sydney, New South Wales, Australia at Baidam Pty Ltd

Title: Security Operations Center Analyst

Company: Baidam Pty Ltd

Location: Sydney, New South Wales, Australia

Level 2 SOC Analyst

Location

Sydney, Brisbane or Perth (hybrid working available – three days in the office)

Employment

Full-time, rotating roster supporting 24×7 SOC operations

About Baidam Solutions

Baidam Solutions is an Australian-owned cybersecurity services provider with a strong social impact mission. We partner with First Nations communities, customers, and global technology providers to deliver leading-edge security solutions while creating pathways for Indigenous participation in the ICT industry.

Our Security Operations Centre (SOC) is growing, and we are seeking talented Level 2 SOC Analysts who are passionate about defending organisations against cyber threats, improving detection and response processes, and contributing to a skilled and diverse cyber workforce in Australia.

Why Join Us

  • Competitive salary and clear progression pathways into senior cyber security roles.
  • Investment in ongoing training and industry-recognised certifications, including SANS, Microsoft, CrowdStrike and Splunk.
  • Hybrid working flexibility within a supportive, collaborative and multicultural team environment.
  • Hands-on exposure to leading security technologies, including Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon Next-Gen SIEM, SOAR and advanced threat intelligence platforms.
  • The opportunity to join a purpose-driven organisation that delivers measurable social impact.

Key Responsibilities

  • Investigate, validate, triage and respond to security alerts and incidents across Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon Next-Gen SIEM, EDR/XDR, SOAR and cloud security platforms.
  • Perform deeper technical analysis of complex incidents across endpoint, identity, cloud and network environments, and escalate matters requiring specialist or senior support.
  • Lead or support incident response activities for escalated security events, including containment, eradication, recovery and post-incident review.
  • Conduct proactive threat hunting using telemetry from CrowdStrike Falcon, Microsoft Sentinel, Microsoft Defender XDR and other security technologies.
  • Onboard new customers, data sources and security technologies into the SOC, including validating data quality, parsing, normalisation and end-to-end alerting.
  • Develop, test, tune and maintain detection rules, correlation logic and analytics to improve coverage, increase alert fidelity and reduce false positives.
  • Create and maintain KQL and other investigation queries, analytics rules, automation workflows, SOAR playbooks and investigation documentation.
  • Identify gaps in visibility, logging, telemetry and detection coverage, and recommend practical improvements.
  • Work directly with customers to investigate incidents, communicate findings and provide clear, actionable technical recommendations.
  • Produce high-quality documentation, including incident reports, post-incident reviews, knowledge articles, investigation procedures and SOC playbooks.
  • Support the continuous improvement of SOC processes, playbooks, response procedures, detections and operational maturity.
  • Mentor Level 1 SOC Analysts, assist with complex investigations and contribute to the ongoing development of the wider SOC team.
  • Stay current with emerging threats, vulnerabilities, attacker techniques and modern detection engineering practices.
  • Participate in an on-call rotation to support incident escalation and operational requirements outside standard business hours.

What We're Looking For

Skills and Experience

  • Previous experience working in a SOC, security operations, cyber defence or incident response role is mandatory.
  • Hands-on experience investigating, validating and responding to security alerts and incidents.
  • Experience performing Level 2 analysis and managing complex investigations across Windows, Microsoft 365, Azure, endpoint, identity and cloud environments.
  • Experience onboarding customers, log sources, security products or data integrations into a SIEM platform.
  • Experience developing, testing and tuning security detections, correlation rules and alert logic.
  • Strong practical knowledge of Microsoft Sentinel, Microsoft Defender XDR and CrowdStrike Falcon Next-Gen SIEM.
  • Experience with enterprise SIEM platforms such as Microsoft Sentinel, CrowdStrike Falcon Next-Gen SIEM, Splunk, Google SecOps or similar.
  • Experience with EDR/XDR platforms, SOAR technologies and security automation workflows.
  • Familiarity with KQL, SPL or similar query languages; basic PowerShell or Python scripting capability is desirable.
  • Understanding of common attack techniques, identity threats, endpoint security, cloud security and the MITRE ATT&CK framework.
  • Ability to identify security gaps and translate technical findings into practical improvements.
  • Strong written and verbal communication skills, with the ability to engage effectively with technical and non-technical stakeholders.
  • A proactive, collaborative approach to problem-solving and continuous improvement.
  • Ability to prioritise multiple incidents in a fast-paced, 24×7 managed SOC environment.

Essential Experience

  • Experience working within a Managed Security Service Provider (MSSP) or customer-facing managed SOC environment.
  • Demonstrated hands-on experience with Microsoft Sentinel, Microsoft Defender XDR and CrowdStrike products.
  • Experience supporting multiple customer environments and balancing competing operational priorities.

Security Knowledge

  • Incident response and security operations best practice.
  • Threat intelligence and threat hunting.
  • Malware analysis fundamentals and digital forensics concepts.
  • MITRE ATT&CK framework and Cyber Kill Chain.
  • Microsoft Azure and Microsoft 365 security.

Clearance Requirements

  • Australian Citizenship is required.
  • Ability to obtain and maintain an Australian Government Security Clearance.

Desirable Certifications

  • CrowdStrike Falcon Administrator or Falcon Hunter
  • Microsoft SC-200
  • Microsoft AZ-500
  • CompTIA Security+
  • GIAC GCIH or GCIA
  • Security Blue Team certifications

Salary and Benefits

  • Salary range of AUD $110,000-$140,000 plus superannuation, depending on experience.
  • Dedicated training budget for Microsoft, CrowdStrike and SANS certifications.
  • Exposure to enterprise government, critical infrastructure and commercial environments.
  • Career pathways into Senior SOC Analyst, Detection Engineer, Incident Response and Threat Hunting roles.
  • Indigenous mentoring, education programs and career pathways unique to Baidam Solutions.
  • Flexible hybrid work model with SOC presence in Sydney, Brisbane and Perth.

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.