Cyber Security Analyst
PRIMARY DETAIL$114,992–$124,676 per annum (HEW Level 7), plus 17% superannuation and annual leave loading2-year fixed-term contractBased at Macquarie University, Wallumattagal Campus, North RydeDetect, investigate and outsmart cyber threats to help protect our systems, data and people. At Macquarie University, our Information Technology team plays a vital role in protecting the systems, information and people that power world-class education, research and health services. As a Cyber Security Analyst, you will be at the frontline of our detect-and-respond capability, monitoring, analysing and responding to threats that target one of Australia's most dynamic university environments.This is an opportunity to move beyond routine monitoring and genuinely shape how we protect our community. You'll investigate incidents end-to-end, uncover root causes, run penetration testing, and help build the playbooks, detection content and secure baselines that keep us resilient. You'll also help guide and mentor emerging talent, sharing your knowledge across the team.Joining MQ IT means becoming part of a service-focused, partnership-driven team that embraces the University's mission to be bold, distinctive, progressive and transformational. If you thrive on solving complex problems and want your work to have real impact at scale, we'd like to hear from you.About the RoleReporting to the Cyber Security Operations Manager, you will help protect the University's computer systems, network and data from cyber threats and attacks. Your responsibilities will include:Managing first and second level cyber security incident response activities end-to-end investigating root causes, providing effective resolutions in line with MQ processes, and escalating as needed.Supporting penetration testing using AI, penetration test report analysis and auditing using established tools and techniques. Working to enhance current state through a defined roadmap.Building and continuously improving detect-and-respond capability, including SIEM content strategy, EDR response playbooks, identity protection policies and mail hygiene posture, aligned to frameworks such as the Essential Eight.Delivering threat-informed improvements through engineering changes such as telemetry onboarding, correlation logic and attack path reductions, and helping design and monitor SOC service SLOs/OKRs.Coordinating the vulnerability and exposure reduction programme for critical services and producing risk narratives and executive dashboards.Acting as a technical escalation point and mentor for junior team members, running simulations and table-top exercises, and reviewing complex changes and detection content.Partnering with IT owners to embed secure configuration baselines and hardening patterns across endpoints, identity, email, cloud and on-premises platforms.Producing post-incident reports with causal analysis and control gap identification and helping develop and maintain SOPs and playbooks.About UsThe D...