Classification: Parliamentary Executive Level 1
Branch: Cyber Security
Section: Cyber Security Operations
Immediate supervisor: Director, Cyber Security Operations
Duty Statement
Under limited/general direction undertake duties in accordance with the agreed standards for the specified classification. The duties will include, but are not limited to, the following:
1. Lead and manage the CSOC Detection Lifecycle Management process, including the identification, prioritisation, development, testing, deployment, tuning, health monitoring and retirement of cyber security detections across DPS and APH environments.
2. Translate cyber threat intelligence, incident findings, vulnerability information, threat hunting outcomes and adversary tactics, techniques and procedures into actionable detection hypotheses, analytics, alert logic, response guidance and playbooks.
3. Develop, maintain and assure technical CTI products, systems and workflows that support CSOC monitoring, detection and response, including indicator management, enrichment processes and intelligence-led detection engineering.
4. Provide expert technical advice to CSOC analysts, cyber engineering, cyber intelligence, CHATE, system owners, service providers and senior stakeholders on detection coverage, logging requirements, telemetry gaps, detection health, alert quality and practical uplift options.
5. Prepare clear, evidence-based technical reports, briefs, detection documentation, assurance artefacts and recommendations that communicate cyber risk, operational impact, detection effectiveness, known limitations and remediation priorities to technical and non-technical audiences.
6. Contribute to the continual uplift of CSOC capability by developing frameworks, procedures, quality assurance practices, metrics, tooling, automation and stakeholder engagement approaches aligned to DPS cyber security objectives, the CSOC Charter, the Cyber Security Incident Response Plan, the System Logging and Audit Plan, the ISM and the PSPF.