About TAFE Queensland
TAFE Queensland is proud to be the largest and most experienced Vocational Education and Training (VET) provider in the State. For more than 140 years, TAFE Queensland has delivered practical and industry-relevant training to provide students with the skills and experience they need to build lifelong careers. Our award-winning training is delivered on campus, online, and in the workplace to give people the skills they need to enrich their communities, support their industries, and strengthen their local economies.
By working at TAFE Queensland, you can be part of a highly experienced workforce that is closely connected with their industries and dedicated to delivering best practices and innovative training.
Your Opportunity
As the Senior Cyber Security Analyst you will:
Actively monitor the on-premise and cloud environments for cyber threats, lead investigations into network intrusions and other cyber security events within TAFE Queensland's state-wide operations.
Take a leading role in building upon and the continued improvement of TAFE Queensland's threat hunting capabilities.
Take a leading role in the ongoing development of TAFE Queensland's SIEM solution, building capability in Cloud native SIEM technology based on Microsoft Sentinel.
Support the identification and delivery of key security technology initiatives to continually enhance TAFE Queensland's security posture.
Play a key role in coordinating security assessment and penetration tests with internal teams and external service providers.
This position reports to the Manager, Cyber Security Operations.
This is a Permanent, Full-Time opportunity.
The position will be based primarily at Mount Gravatt, however you may be required to perform work at other TAFE Queensland campuses.
Key Responsibilities
Manage the time sensitive detection, identification, and alerting of possible intrusions, anomalous activities, and misuse activities, and be able to distinguish these incidents and events from benign activities across on-premise and cloud environments.
Manage incident response planning and coordinate security activities, incident assessment and investigation and reporting on cyber security breaches, ensuring all identified breaches in security are promptly and thoroughly investigated, including determining potential impact, and making recommendations on timely remediation.
Manage incident detection, response, handling, reporting, working closely with the cyber engineering team to coordinate and streamline response workflows and automation and the continual improvement of these services across both cloud and on-premise systems and services.
Support the delivery of key security technology initiatives to continually enhance TAFE Queensland's security posture.
Collaborate with the cyber engineering team to enhance cyber security orchestration within the Microsoft Defender/Sentinel/Azure environments, and integration into third party security solutions.
Manage, plan and administer the operations and administrative activities for the security of the organisation, including event correlation, monitoring, research, assessment and analysis using enterprise security tools, Security Incident Event Management, Firewalls, Antivirus systems, Intrusion detection and other cloud-based systems.
Lead proactive threat hunting activities, analysing and responding to complex and advanced threats.
Manage and address security risks through an effective vulnerability management program and undertake regular security reviews and respond where required, providing advice on emerging security issues, threats and trends to provide visibility and assurance to the Director, Cyber Security.
Identify and escalate gaps in visibility, intelligence and technology that could improve the efficiency or efficacy of the Cyber security services.
Engage and manage external service providers on cyber security related activities, including TAFE Queensland's primary managed service provider, and other providers of security-related services.
Coordinate and support the delivery of cyber security assessments and penetration tests including scheduling, scoping and engagement with internal stakeholders, subject matter experts and external service providers.
Contribute to the success of transformation and cultural change through promoting and modelling the established values of Showing Initiative, Working Together, focusing on our Customer and Taking Responsibility.
How you will be assessed
The ideal applicant will be someone who has the following key capabilities:
Demonstrated experience working within a Cyber Security Operations team, successfully and consistently undertaking incident response activities, with experience in the use of SIEM solutions.
Demonstrated experience working within a Cyber Security Operations team performing threat hunting activities across enterprise environments.
Operational experience in configuring, tuning and analysing events from Microsoft Defender for Endpoint, Microsoft Sentinel and Windows Security Events.
Demonstrated ability in programming in a security environment, with skills in Kusto Query Language desirable
Demonstrate hands on experience implementing and securing cloud-based environments and in identifying and validating Microsoft, Azure and O365 services security controls.
Operational experience in the effective security monitoring of Microsoft Azure and Office 365 cloud-based environments.
Demonstrated interest in SIEM/SOAR technologies and ability to collaborate with the cyber engineering team to support the design and operational integration of security automation workflows.
Demonstrated hands on experience in performing key cyber security operational activities, such as end point security management, to effectively identify and mitigate observed attacks.
Strong written and verbal communication skills, with the proven ability to engage effectively at all levels of an organisation, including the ability to work effectively alongside outsourced delivery partners.
Demonstrated ability to live and promote a strong ICT team culture that values the contributions of all team members, is honest and considerate, and through that is an active participant in building and maintaining a highly respected high-performance team.
Highly Desirable Requirements
Tertiary qualification in Cyber Security, Information and Communications Technology or demonstrated equivalent experience is highly regarded.
You will possess minimum of 3 years of security operational experience in enterprise environments.
Possession of industry acknowledged Security certifications is preferred, such as detection and incident response certifications from leading industry organisations (e.g. SANS, Microsoft, Google, Xintra, SpecterOps, BlackHat).
Experience with the Microsoft, Cisco, and Elastic security technology stacks.
How to apply
If you're interested in this role, click the 'Apply' button to submit your application via the TAFE Queensland Recruitment Portal. When submitting your application, please ensure you provide the following:
a detailed resume including the contact details for two referees (one of whom is your current supervisor); and
a cover letter (maximum 2 pages) that outlines your experience, skills and abilities and responds to the 'How you will be assessed' criteria.
Closing date: 11:59pm, Sunday 9 August 2026.
Job Reference Number: TQ2026-748
For further information, please contact:
Chris Said, Manager, Cyber Security Operations
[email protected] work is licensed under a Creative Commons Attribution 3.0 Australia License.