Job Description
The IT Security Analyst will support the protection of a Microsoft-based environment across global operations through security monitoring, incident response, identity and access management, vulnerability management, and continuous improvement of cyber security controls. The role will work closely with internal IT teams and external security providers to investigate threats, coordinate remediation, and support the organisation’s Essential Eight and IT service management processes.
- Triage and investigate Microsoft Defender alerts and Arctic Wolf SOC escalations, including phishing, malware, suspicious sign-ins and endpoint activity.
- Coordinate containment, eradication and recovery activities with Arctic Wolf and internal IT teams, maintaining incident evidence and escalating major incidents where required.
- Support Microsoft Defender endpoint protection, Microsoft 365 security posture, security hardening and endpoint detection and response.
- Prioritise vulnerabilities based on exploitability, exposure and business criticality, and track remediation through to closure.
- Support security baselines and patch compliance using Microsoft management tools and NinjaOne where applicable.
- Review and strengthen Active Directory and Microsoft Entra ID security, including MFA, Conditional Access, least-privilege access and periodic access reviews.
- Review privileged accounts, role-based access, service accounts and application permissions, and support identity-related threat response.
- Support improvement of Essential Eight controls, maintain evidence and remediation actions, and work with control owners to verify implementation.
- Support security risk assessments, policy reviews and audits, translating identified control gaps into prioritised actions.
- Record and manage security incidents, requests, problems and changes in Freshservice in line with agreed ITSM processes.
- Perform root cause analysis, maintain response playbooks and knowledge articles, and support continuous improvement of recurring security issues.
- Report on incident response, remediation ageing, Defender coverage, identity risks and Essential Eight progress.
- Collaborate with service desk, infrastructure, application and business teams to resolve security issues while supporting operational continuity.
- Provide practical security guidance and contribute to phishing awareness and user education.
- Support incident handovers across time zones and participate in agreed after-hours incident response arrangements when required.
- Other position-level duties as they arise.
Requirements
- At least 3 years’ relevant experience in cyber security operations, incident response, or an IT role with substantial hands-on security responsibilities is essential.
- Practical experience securing Microsoft enterprise environments and investigating threats using Microsoft Defender for Endpoint or equivalent EDR tooling is essential.
- Hands-on experience with Active Directory, Microsoft Entra ID, MFA, Conditional Access and access reviews is essential.
- Experience working with a SIEM and managed SOC or MDR provider is essential; Arctic Wolf experience is highly regarded.
- Working knowledge of Essential Eight implementation or assessment and ITIL-aligned IT service management processes is essential; Freshservice experience is desirable.
- Strong knowledge of Microsoft 365 and Windows security, including Exchange Online, Windows endpoints and Windows Server, is essential.
- Experience with log analysis and threat investigation, including common attack techniques, phishing and ransomware, is essential.
- Sound understanding of networking fundamentals, including TCP/IP, DNS, firewalls and VPNs, is essential.
- PowerShell or Kusto Query Language (KQL) experience for investigation and automation is desirable.
- Exposure to Intune, Defender for Office 365 and Defender for Identity is desirable.
- Experience within global or multi-site operations is desirable.
- Relevant qualifications in cyber security, information technology or a related discipline, or equivalent practical experience, are essential.
- Relevant Microsoft security or identity certifications, CompTIA Security+, ITIL Foundation certification or Essential Eight assessment training are desirable.
- Strong analytical judgement, problem-solving ability and clear written and verbal communication skills are essential.
- Ability to prioritise competing incidents and handle sensitive information with discretion and accountability is essential.
Benefits
Why Join Twoconnect?
We offer more than just a job — we offer a supportive and rewarding career experience. Here’s what you can expect from this opportunity:
- Work from home
- Mon - Fri: 9:00 AM – 6:00 PM AEST/AEDT (adjustments will be made for daylight saving time)
- HMO with 2 free dependents and medical reimbursements
- Government-mandated benefits
- Opportunities to work with leading companies in Australia and beyond
- Training programmes for career development
- Engaging company outings, team activities and wellness sessions
- Supportive, inclusive culture
- Dedicated managers focused on your growth and success
Twoconnect connects highly skilled Filipino professionals with established companies in Australia, New Zealand, the United States, the United Kingdom and Europe, providing direct access to global careers and long-term opportunities.
We offer competitive pay and benefits, additional entitlements and structured career development programs that make employment both financially rewarding and professionally sustainable.
Our industry-leading retention rate demonstrates our commitment to a people-first culture that prioritizes stability, growth and genuine care for every employee.
Twoconnect is an equal opportunity employer. We value cultural diversity and foster an inclusive workplace where every employee is respected and supported as part of a growing global team.