Overview
Security Operations Center Analyst Jobs in Sydney, New South Wales, Australia at Baidam Pty Ltd
Title: Security Operations Center Analyst
Company: Baidam Pty Ltd
Location: Sydney, New South Wales, Australia
Level 2 SOC Analyst
Location
Sydney, Brisbane or Perth (hybrid working available – three days in the office)
Employment
Full-time, rotating roster supporting 24×7 SOC operations
About Baidam Solutions
Baidam Solutions is an Australian-owned cybersecurity services provider with a strong social impact mission. We partner with First Nations communities, customers, and global technology providers to deliver leading-edge security solutions while creating pathways for Indigenous participation in the ICT industry.
Our Security Operations Centre (SOC) is growing, and we are seeking talented Level 2 SOC Analysts who are passionate about defending organisations against cyber threats, improving detection and response processes, and contributing to a skilled and diverse cyber workforce in Australia.
Why Join Us
- Competitive salary and clear progression pathways into senior cyber security roles.
- Investment in ongoing training and industry-recognised certifications, including SANS, Microsoft, CrowdStrike and Splunk.
- Hybrid working flexibility within a supportive, collaborative and multicultural team environment.
- Hands-on exposure to leading security technologies, including Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon Next-Gen SIEM, SOAR and advanced threat intelligence platforms.
- The opportunity to join a purpose-driven organisation that delivers measurable social impact.
Key Responsibilities
- Investigate, validate, triage and respond to security alerts and incidents across Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon Next-Gen SIEM, EDR/XDR, SOAR and cloud security platforms.
- Perform deeper technical analysis of complex incidents across endpoint, identity, cloud and network environments, and escalate matters requiring specialist or senior support.
- Lead or support incident response activities for escalated security events, including containment, eradication, recovery and post-incident review.
- Conduct proactive threat hunting using telemetry from CrowdStrike Falcon, Microsoft Sentinel, Microsoft Defender XDR and other security technologies.
- Onboard new customers, data sources and security technologies into the SOC, including validating data quality, parsing, normalisation and end-to-end alerting.
- Develop, test, tune and maintain detection rules, correlation logic and analytics to improve coverage, increase alert fidelity and reduce false positives.
- Create and maintain KQL and other investigation queries, analytics rules, automation workflows, SOAR playbooks and investigation documentation.
- Identify gaps in visibility, logging, telemetry and detection coverage, and recommend practical improvements.
- Work directly with customers to investigate incidents, communicate findings and provide clear, actionable technical recommendations.
- Produce high-quality documentation, including incident reports, post-incident reviews, knowledge articles, investigation procedures and SOC playbooks.
- Support the continuous improvement of SOC processes, playbooks, response procedures, detections and operational maturity.
- Mentor Level 1 SOC Analysts, assist with complex investigations and contribute to the ongoing development of the wider SOC team.
- Stay current with emerging threats, vulnerabilities, attacker techniques and modern detection engineering practices.
- Participate in an on-call rotation to support incident escalation and operational requirements outside standard business hours.
What We're Looking For
Skills and Experience
- Previous experience working in a SOC, security operations, cyber defence or incident response role is mandatory.
- Hands-on experience investigating, validating and responding to security alerts and incidents.
- Experience performing Level 2 analysis and managing complex investigations across Windows, Microsoft 365, Azure, endpoint, identity and cloud environments.
- Experience onboarding customers, log sources, security products or data integrations into a SIEM platform.
- Experience developing, testing and tuning security detections, correlation rules and alert logic.
- Strong practical knowledge of Microsoft Sentinel, Microsoft Defender XDR and CrowdStrike Falcon Next-Gen SIEM.
- Experience with enterprise SIEM platforms such as Microsoft Sentinel, CrowdStrike Falcon Next-Gen SIEM, Splunk, Google SecOps or similar.
- Experience with EDR/XDR platforms, SOAR technologies and security automation workflows.
- Familiarity with KQL, SPL or similar query languages; basic PowerShell or Python scripting capability is desirable.
- Understanding of common attack techniques, identity threats, endpoint security, cloud security and the MITRE ATT&CK framework.
- Ability to identify security gaps and translate technical findings into practical improvements.
- Strong written and verbal communication skills, with the ability to engage effectively with technical and non-technical stakeholders.
- A proactive, collaborative approach to problem-solving and continuous improvement.
- Ability to prioritise multiple incidents in a fast-paced, 24×7 managed SOC environment.
Essential Experience
- Experience working within a Managed Security Service Provider (MSSP) or customer-facing managed SOC environment.
- Demonstrated hands-on experience with Microsoft Sentinel, Microsoft Defender XDR and CrowdStrike products.
- Experience supporting multiple customer environments and balancing competing operational priorities.
Security Knowledge
- Incident response and security operations best practice.
- Threat intelligence and threat hunting.
- Malware analysis fundamentals and digital forensics concepts.
- MITRE ATT&CK framework and Cyber Kill Chain.
- Microsoft Azure and Microsoft 365 security.
Clearance Requirements
- Australian Citizenship is required.
- Ability to obtain and maintain an Australian Government Security Clearance.
Desirable Certifications
- CrowdStrike Falcon Administrator or Falcon Hunter
- Microsoft SC-200
- Microsoft AZ-500
- CompTIA Security+
- GIAC GCIH or GCIA
- Security Blue Team certifications
Salary and Benefits
- Salary range of AUD $110,000-$140,000 plus superannuation, depending on experience.
- Dedicated training budget for Microsoft, CrowdStrike and SANS certifications.
- Exposure to enterprise government, critical infrastructure and commercial environments.
- Career pathways into Senior SOC Analyst, Detection Engineer, Incident Response and Threat Hunting roles.
- Indigenous mentoring, education programs and career pathways unique to Baidam Solutions.
- Flexible hybrid work model with SOC presence in Sydney, Brisbane and Perth.