You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Early Window: Be the first to open itNo views yetCloses in
Company hidden

Senior Security Operations Analyst

  • Hybrid
  • 6+ years

Salary

Not stated

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

When something goes wrong in security at the company, our Response team are first on the scene. We're looking for a Senior Security Operations Analyst who loves incident response, enjoys building things, and wants a hand in shaping what a SOC looks like when AI agents are part of the team.

You'll lead our complex investigations and take command of medium and high impact incidents, keeping people calm, decisions moving and stakeholders in the loop. When things settle down, you'll make sure what we learnt changes something, whether that's a detection, a runbook or the way we train.

You'll also help us build. Our Analysts improve the queue as well as working it, so part of your time will go on creating automations and AI-assisted workflows that take repetitive work off the team and leave more room for the investigations that need a person.

The team and how they connect

Response is a follow-the-sun global team. You'll be in the Southern Hemisphere half, based in New Zealand or Australia, and at the end of your day you'll hand over to colleagues in the UK and North America, who hand back to us the next morning. You'll work business hours in your time zone and take a share of our on-call roster for after-hours incidents.

You won't be doing it on your own. You'll join a cohort of Senior Analysts who share the load on complex work and lead our initiatives, with a Lead Analyst alongside for the hardest problems. Our XFLT, a cross-functional leadership team of Security Operations Managers, our Lead Analyst and our Product Manager, sets the direction and clears the way, so there's always someone to think out loud with.

The team is currently working on / Initially, you will focus on

We're building towards an agentic SOC, where AI agents and automation carry more of the first pass, and analysts direct them and step in where judgement matters. We're working through it carefully: which low-risk work agents can take on, where the guardrails and human approvals belong, and how we'll know it's working. People still make the big calls, because our robots aren't that good yet.

You don't need to be an AI expert. We'd love you to be curious, to have tried a few things, and to want to help us get this right.

You’ll also:

Lead complex investigations and step up as Incident Commander for medium and high impact incidents

Be a go-to escalation point for our Graduate, Associate and Analyst crew, and coach them through the tricky stuff

Run post incident reviews that lead to real change in detections, runbooks and training

Lead initiatives with our Product Manager and Security Operations Managers, turning goals into work that gets delivered

Build and improve automations and AI-assisted workflows, with guardrails and human sign-off where they matter

Work with our Defence engineers on detection and response logic, and test new capabilities in real incidents

Turn threat intelligence into practical action for the company

Give customers and internal teams clear, timely answers to their security concerns

Where and how you can work

We support a flexible working model that empowers you to balance your professional and personal life. You will have the option to work in a hybrid capacity, combining the focus of remote work with the collaboration of our office spaces and team boost days to foster connection and alignment.

Here are some of the things we're looking for

Incident response comes first for us, so we're looking for:

Solid experience in security operations, and a real passion for incident response

A track record of leading complex investigations and incidents through to resolution, including coordinating people and making calls under pressure

Sound technical judgement and good knowledge of attack and defence techniques, particularly in cloud and SaaS environments

Confidence writing queries in a SIEM or log platform

Clear, calm communication and a generous approach to sharing what you know

It'd be great if you also have:

Scripting skills (Python or similar) and experience building automations in a SOAR platform. We use Tines, and we're happy to teach it.

Hands-on experience with AI tools in security work, or a clear view of where they help and where they don't

Intermediate or advanced certifications in incident response, threat hunting or cloud security

Experience in a distributed team working across time zones

If you're strong on incident response and the builder side is still growing, we'd still love to hear from you.

You'll do work that matters to millions of small businesses and their advisors, in a team that shares what it knows and backs each other up, with a real say in how an AI-powered SOC works in practice.

Apply even if your experience isn't a perfect match! At the company, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Responsibilities

  • When something goes wrong in security at the company, our Response team are first on the scene. We're looking for a Senior Security Operations Analyst who loves incident response, enjoys building things, and wants a hand in shaping what a SOC looks like when AI agents are part of the team.
  • You'll lead our complex investigations and take command of medium and high impact incidents, keeping people calm, decisions moving and stakeholders in the loop. When things settle down, you'll make sure what we learnt changes something, whether that's a detection, a runbook or the way we train.
  • You'll also help us build. Our Analysts improve the queue as well as working it, so part of your time will go on creating automations and AI-assisted workflows that take repetitive work off the team and leave more room for the investigations that need a person.
  • The team and how they connect
  • Response is a follow-the-sun global team. You'll be in the Southern Hemisphere half, based in New Zealand or Australia, and at the end of your day you'll hand over to colleagues in the UK and North America, who hand back to us the next morning. You'll work business hours in your time zone and take a share of our on-call roster for after-hours incidents.
  • You won't be doing it on your own. You'll join a cohort of Senior Analysts who share the load on complex work and lead our initiatives, with a Lead Analyst alongside for the hardest problems. Our XFLT, a cross-functional leadership team of Security Operations Managers, our Lead Analyst and our Product Manager, sets the direction and clears the way, so there's always someone to think out loud with.
  • The team is currently working on / Initially, you will focus on
  • We're building towards an agentic SOC, where AI agents and automation carry more of the first pass, and analysts direct them and step in where judgement matters. We're working through it carefully: which low-risk work agents can take on, where the guardrails and human approvals belong, and how we'll know it's working. People still make the big calls, because our robots aren't that good yet.
  • You don't need to be an AI expert. We'd love you to be curious, to have tried a few things, and to want to help us get this right.
  • You’ll also:
  • Lead complex investigations and step up as Incident Commander for medium and high impact incidents
  • Be a go-to escalation point for our Graduate, Associate and Analyst crew, and coach them through the tricky stuff
  • Run post incident reviews that lead to real change in detections, runbooks and training
  • Lead initiatives with our Product Manager and Security Operations Managers, turning goals into work that gets delivered
  • Build and improve automations and AI-assisted workflows, with guardrails and human sign-off where they matter
  • Work with our Defence engineers on detection and response logic, and test new capabilities in real incidents
  • Turn threat intelligence into practical action for the company
  • Give customers and internal teams clear, timely answers to their security concerns
  • Where and how you can work
  • We support a flexible working model that empowers you to balance your professional and personal life. You will have the option to work in a hybrid capacity, combining the focus of remote work with the collaboration of our office spaces and team boost days to foster connection and alignment.
  • Here are some of the things we're looking for
  • Incident response comes first for us, so we're looking for:
  • Solid experience in security operations, and a real passion for incident response
  • A track record of leading complex investigations and incidents through to resolution, including coordinating people and making calls under pressure
  • Sound technical judgement and good knowledge of attack and defence techniques, particularly in cloud and SaaS environments
  • Confidence writing queries in a SIEM or log platform
  • Clear, calm communication and a generous approach to sharing what you know
  • It'd be great if you also have:
  • Scripting skills (Python or similar) and experience building automations in a SOAR platform. We use Tines, and we're happy to teach it.
  • Hands-on experience with AI tools in security work, or a clear view of where they help and where they don't
  • Intermediate or advanced certifications in incident response, threat hunting or cloud security
  • Experience in a distributed team working across time zones
  • If you're strong on incident response and the builder side is still growing, we'd still love to hear from you.
  • You'll do work that matters to millions of small businesses and their advisors, in a team that shares what it knows and backs each other up, with a real say in how an AI-powered SOC works in practice.
  • Apply even if your experience isn't a perfect match! At the company, we hire based on your skills, passion, and the unique perspective you can bring to enhance our culture and team.

Where you’d work

Part of the week in the office

You can work from

  • Australia

About the company

Company hidden

Offices in Wellington, New Zealand, Auckland, New Zealand

Your chances

Still hiring, not crowded yet, and you'd be among the first.

  • 16 checks run
  • 5 good signs
  • 0 red flags

Still hiring?

11 checks

Actively hiring

In its favour3

  • Still on the company's own careers site, checked 1 h agoModerate evidence
  • Found in the last 48 hours, before the big job boardsModerate evidence
  • The company opened 18 roles and closed 28 in the last 2 weeks: hiring is movingModerate evidence

How crowded?

5 checks

Low

In its favour2

  • In its Early Window: not on the big job boards yetStrong evidence
  • Senior level: far fewer people qualifySlight evidence

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details12 facts · Role, Location, Compensation, Employment
Tech stack
  • Python
Seniority
Senior
Type
Full-time
Specialty
Security
Region
Australia
Pay period
Annual
Show 6 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
6+ years
Tech stack
  • Python

Location

Work model
Hybrid
Region
Australia
Offices
  • Wellington, New Zealand
  • Auckland, New Zealand
Remote from
  • Australia

Compensation

Salary
Salary by agreement
Pay period
Annual

Employment

Type
Full-time

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Staff Security Engineer

    $245,000 - 290,000 / year

    • Hybrid · Bellevue, Menlo Park +1
    • Senior

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason