Your opportunity:
The Senior Incident Response Specialist role is to take ownership of complex, high-severity security incidents from detection through recovery. You'll lead investigations into advanced threats, sharpen our detection capabilities, and act as the technical escalation point for the team. Beyond hands-on response, you'll mentor specialists, level up our offshore CSOC's L3/L4 capability, and work closely with the Incident Manager, NOC, vendors, and stakeholders to keep incidents moving and everyone informed.
Responsibilities:
Lead end-to-end response to high-severity incidents - APT activity, nation-state actors, cybercriminal intrusions - owning containment, eradication, and recovery with minimal business impact.
Serve as senior SME and escalation point for complex or high-priority cases.
Investigate complex threats across endpoint, network, cloud, and identity domains using EDR, NDR, and SIEM tools.
Apply static and dynamic malware analysis to understand attacker tooling and intent.
Build, maintain, and continuously refine playbooks, runbooks, and escalation procedures through regular tabletop exercises.
Partner with threat intel, SOC, and IT/network teams to identify and mitigate emerging threats.
Drive root cause analysis and post-incident reviews, maintaining thorough documentation throughout.
Apply MITRE ATT&CK and adversary profiling to turn investigation findings into actionable threat intelligence.
Provide expert guidance during live incidents and crisis situations.
Track emerging threats, vulnerabilities, and TTPs to keep defenses current.
Mentor and upskill CSOC analysts, contributing to the ongoing maturity of the IR program.
Leverage AI/ML-driven security tools (e.g., AI-enabled EDR/XDR, UEBA) to enhance threat detection and triage.
Analyse anomalies and patterns identified through machine learning models to identify advanced threats.
Utilise AI-assisted threat hunting and automation to improve detection speed and reduce false positives.
Participate in an on-call rotation for major incidents.
What you’ll bring:
Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
5+ years of hands-on incident response and forensics experience, with proven Tier 3-level investigation and threat hunting expertise.
Strong grounding in threat hunting, malware analysis, adversary tactics (MITRE ATT&CK), NIST, and other security frameworks.
Practical experience with SIEMs (e.g. Splunk), EDR (e.g. SentinelOne, Defender, Trend Micro), NDR (e.g. Darktrace, Vectra AI), threat intel platforms (e.g. MISP, SOCRadar), and forensic toolsets.
Familiarity with cloud security across AWS, Azure, GCP, and hybrid environments.
Strong analytical, communication, and documentation skills.
What's in it for you?
- Flexible hybrid way of working (from home and office)
- ‘Stay Connected Mobile’ – Access to a free mobile plan
- ‘Stay Connected NBN’ – Access to a free, high‑speed NBN plan (up to 500 Mbps)
- ‘Your Leave’ - an additional 4 days of leave to be used whenever you like - every year
- Access to TPG Learning Hub platform and internal development opportunities
Access to Corporate Partner Discounts
-
Come join us and build a better future. Apply today.
Don’t meet every single requirement? That’s OK! At TPG Telecom, we’re all about creating an accessible workplace where everybody feels safe to bring their authentic self to work - regardless of background. If you think this role is a great fit for you but some of the qualifications don’t align with your experience, we still encourage you to apply - you might just be the perfect candidate for a similar role with us! .
TPG Telecom also acknowledges the Gadigal People of the Eora Nation as the Traditional Custodians of lands and waterways where this office can be found in Barangaroo.
Our Talent Acquisition Team and Hiring Managers kindly request no unsolicited resumes or approaches from Recruitment Agencies. TPG Telecom is not responsible for any fees related to unsolicited resumes.
#LI-Hybrid