Brennan. Where true performance thrives.
At Brennan, we believe that
how technology is delivered is every bit as important as
what the technology is. We focus on creating real and relevant value for customers with solutions that fit their specific needs and always reflect their true interests. It’s a claim backed by our
True Performance System – a way of working engineered to get us closer, and deliver better, for our customers and their actual experience of technology.
Why join Brennan
True performance for our customers starts with a true belief in our people.
It’s why we’ve structured our business to help our teams, and their talents, shine bright. It's why we’ve created a workplace where people of all backgrounds, beliefs and experiences are welcomed and empowered. And it’s why we’ve built an organisation where real innovation makes a genuine impact and generates true rewards for our team members.
True rewards
In addition to competitive remuneration, Brennan offers extensive benefits, including:
- Training and certification bonuses
- Culture Awards that recognise excellence
- Brennan Daredevils – our annual, all-expenses paid trip awarded to our top performers and outstanding contributors
- Vibrant, fun social activities
- Discounted hardware and software
- An environment that embraces learning and development
The role:
We are looking for a Security Operations Engineer (L2) to join our Cyber Security team in Brisbane. This is an excellent opportunity for an experienced cyber security professional looking to take the next step in their career. Working within our Security Operations Centre (SOC), you will play a key role in protecting a range of sovereign and government-focused customers while helping to build, maintain and improve the security platforms that support our managed security services.
This role offers a balance of operational and engineering responsibilities. Approximately 50% of your time will be spent acting as an escalation point for Security Analysts, investigating and resolving complex security incidents and platform issues. The remaining 50% will focus on engineering activities across our security platforms, including customer onboarding, configuration, optimisation, automation and continuous improvement.
This is a Brisbane-based role requiring 5 days per week onsite. Standard business hours apply, with participation in a secondary on-call roster as required.
Please note: Applicants must be Australian Citizens and eligible to obtain NV1 Security Clearance.
Key Responsibilities:
- Act as an escalation point for Security Analysts and investigate complex security incidents and platform issues
- Perform root cause analysis and troubleshooting across multiple security technologies
- Configure, administer and optimise SIEM, SOAR, endpoint, email, identity and vulnerability management platforms
- Onboard and transition customers onto managed security services, including log collection, agent deployment and platform configuration
- Build and maintain security automations, integrations and operational processes
- Implement and support identity, access and cloud security controls
- Create and maintain runbooks, standard operating procedures and technical documentation
- Work closely with customers and internal teams to deliver high-quality security outcomes
- Support platform upgrades, tuning, testing and continuous improvement initiatives
- Participate in the SOC secondary on-call roster
What skills and experience you bring:
- Australian Citizenship and eligibility to obtain NV1 Security Clearance
- 2-3+ years' experience in a Security Operations Centre (SOC), cyber security engineering or related security role
- Experience investigating and responding to security incidents
- Strong troubleshooting, analytical and root cause analysis skills
- Experience working with SIEM, SOAR, endpoint security and identity management platforms
- Strong communication skills with the ability to engage both technical and non-technical stakeholders
- Experience working within operational support, change management or managed services environments
- Ability to work effectively in a fast-paced team environment
- A proactive approach to learning, collaboration and continuous improvement
Technical skills in some of the following areas is beneficial:
- Microsoft Sentinel and Microsoft Defender XDR
- Securonix
- SentinelOne and CrowdStrike
- Mimecast and Check Point Harmony
- Entra ID, Conditional Access and Multi-Factor Authentication (MFA)
- Azure or AWS security services
- Tenable and vulnerability management platforms
- Security incident response, threat investigation and root cause analysis
- Security automation, SOAR and API integrations
- PowerShell and Python scripting
- Microsoft SC-200 Security Operations Analyst Associate (highly regarded)
- Security+, CySA+, SC-300, AZ-500 or other relevant cyber security certifications
Note: As part of our hiring process, you will be required to undertake a National Criminal History Check.
Brennan is an equal-opportunity employer