Talent.com
Department of Education
Cyber Incident Response LeadDepartment of Education • Melbourne, AU
Cyber Incident Response Lead

Cyber Incident Response Lead

Department of Education • Melbourne, AU
9 days ago
Job description

The Cyber Incident Response Lead plays a critical role in protecting the Department, including schools, by leading the detection, management, and response to cyber security incidents.

About the role

The Cyber Incident Response Lead plays a critical role in protecting the Department, including schools, by leading the detection, management, and response to cyber security incidents. This position provides incident response leadership by operating the Cyber Security Incident Response Service in accordance with the Department's Cyber Security Incident Response Plan (CSIRP).

The role provides operational leadership during cyber incidents, ensuring effective containment, eradication, recovery, stakeholder communication, and post-incident review while minimizing business disruption and cyber risk. Working in a fast-paced, high-volume, and complex environment, using a wide range of enterprise security platforms, the role will manage and coordinate incidents, cyber threat intelligence and deliver cyber advice to enhance the Department's overall security posture.

The role develops high-quality reporting and data insights for internal and external stakeholders on cyber incidents, threats, and vulnerabilities to inform performance, recovery, and remediation activities. The role will work closely with multi-disciplinary ICT teams, school technical teams, other divisions, and external agencies including the Victorian Government Cyber Incident Response Service (CIRS), the Australian Signals Directorate (ASD), and the Office of the Victorian Information Commissioner (OVIC) to support efficient response to threats.

Key Responsibilities

  • Lead and control cyber security incidents from detection through containment, eradication, and recovery
  • Lead Cyber Security Incident Response Team (CSIRT) meetings and provide clear, timely updates and advice to stakeholders
  • Manage the workflow ensuring incidents are allocated and coordinated with the relevant internal and/or external teams as required and maintains oversight and coordination until closure.
  • Analyse events and incidents to determine severity, impact, and long-term consequences to categorise appropriately to initiate response
  • Supports in analysis, investigations and remediation of threats and vulnerabilities
  • Develop and provides inputs to incident, operational, situational and compliance reports and data insights on incidents, threats, vulnerabilities, and response effectiveness
  • Performs stakeholder management by working closely with internal teams, external partners, other government agencies to coordinate efficient response to incidents and threat advisories
  • Perform other Security Operational activities to support maintenance and uplift of Department's security posture

Skills & Expertise

  • Expertise in and knowledge of NIST Cybersecurity Framework, Incident Response framework
  • Strong understanding of security operations practises
  • Understanding of attack tactics, techniques, and procedures using the MITRE ATT&CK framework
  • Understanding of cloud platforms
  • Proven ability to lead cross-functional teams during high-pressure situations.
  • Strong decision-making and crisis management capabilities.
  • Excellent stakeholder engagement and executive communication skills.
  • Ability to influence outcomes without direct authority.
  • Strong written and verbal communication.
  • Ability to translate complex technical issues into business-focused language.
  • Experience presenting to senior executives and crisis management teams.
  • Hands-on experience in the use of various security platforms namely MS Sentinel, Defender, ServiceNow, Tenable

Qualifications & Experience

  • Bachelor's degree or Diploma in Cyber Security or a related field
  • Minimum 3–4 years demonstrated experience in cyber incident response and security operations in a similar, large and complex environme nt
  • Experience leading responses to ransomware, malware, data breach, insider threat, phishing, cloud security, and advanced persistent threat (APT) incidents.
  • Proven experience leading cyber incident response activities
  • Proven stakeholder management experience and report writing skills

Desirable

  • Experience in Threat analysis and investigations
  • Cybersecurity Certifications:
    • CC
    • CISSP
    • Security+
    • SANS Digital Forensics or Incident Response certifications

Further Information

For more details regarding this position please see attached position description for the capabilities to address in application.

The department values diversity and inclusion in all forms - gender, religion, ethnicity, LGBTIQ+, disability and neurodiversity. Aboriginal and Torres Strait Islander candidates are strongly encouraged to apply. For more information about our work, working for the Department, diversity and inclusion, and our employment conditions visit the Department website and our Diversity and Inclusion page

Applicants requiring adjustments can contact the nominated contact person.

Information about the Department of Education's operations and employment conditions can be located at www.education.vic.gov.au.

For further information pertaining to the role, please contact Ashok Sangra - Acting Chief Information Security Officer via ************@education.vic.gov.au

Preferred applicants may be required to complete a police check and may be subject to other pre-employment checks. Information provided to the Department of Education will be treated in the strictest confidence.

Please let us know via phone or email if you require any adjustments to ensure your full participation in the recruitment process or if you need the ad or any attachments in an accessible format (e.g large print) due to any viewing difficulties or other accessibility requirements.

Applications close

11:59pm on Tuesday 29 Septamber 2026.

#J-18808-Ljbffr

Create a job alert for this search

Cyber Incident Response Lead • Melbourne, AU

Similar jobs

Cyber Security Risk Manager

Beyond Bank AustraliaMelbourne, VIC, AU

Full time (75 hours per fortnight).Be part of Beyond Bank-a bank that is for and with you.We are one of Australia's largest, 100% member owned mutual banks with a credit union heritage.With more th... Show more

Senior Cybersecurity Incident Analyst – Onsite

NTT DATA, Inc.Melbourne, AU

A global technology services leader is seeking a Principle Analyst Cybersecurity Incident based in Melbourne.The role involves detecting security threats and managing incident responses, while coll... Show more

 • Promoted

Tech Lead

Two CirclesMelbourne, AU

We are a Sports & Entertainment Marketing business.We grow audiences and revenues.We do that by knowing fans best.We work with clients to help them understand & influence what their fans are doing ... Show more

 • Promoted

Remote Senior DFIR & Incident Response Lead

DatacomMelbourne, AU
Remote

Datacom is seeking a Senior Cybersecurity Incident Responder to join our Cybersecurity Incident Response Team (CSIRT).This role involves leading DFIR engagements and providing proactive advisory se... Show more

 • Promoted

Senior Cyber Defense Incident & Threat Responder Lead

News CorpMelbourne, AU

News Corp seeks a Lead Engineer in Cyber Security, focused on incident response and threat mitigation within the Cyber Defense team in Melbourne.You will identify and respond to cyber security even... Show more

 • Promoted

Senior Cyber Defense & Incident Response Lead (Splunk)

Experis AustraliaMelbourne, AU

A leading technology organization in Melbourne seeks a Principal Cyber Security Analyst to lead cyber defence initiatives and provide operational leadership.You will mentor a team of analysts and e... Show more

 • Promoted

Senior IAM & One Identity Platform Lead (Contract)

Experis ManpowerGroup Sp. z o.o.Melbourne, AU

Lead Cyber Security Analyst in Melbourne to enhance the One Identity platform within a high-performing team.The role involves managing access security, troubleshooting issues, and supporting enhanc... Show more

 • Promoted

Senior Cyber Security Transformation Lead

SaltMelbourne, AU

Salt is seeking an experienced Senior Program Manager to lead a major cyber security transformation in Melbourne, Australia.This key leadership role will drive the shift from legacy systems to next... Show more

 • Promoted

Senior Incident & Problem Manager - Contract, Transformation

EmmbrMelbourne, AU

A leading IT organization in Melbourne seeks an Incident & Problem Manager for a 3-month contract role.You will oversee incident responses, investigate high-impact issues, and drive problem resolut... Show more

 • Promoted

Cybersecurity SDR: Drive Global Lead Gen & Impact

watchTowrMelbourne, AU

A cybersecurity firm is seeking a Sales Development Representative to build a pipeline of potential clients.The role involves engaging with prospects through calls and emails, conducting research, ... Show more

 • Promoted

Senior Threat Intelligence Lead - Flexible Work

nbn® AustraliaMelbourne, AU

A leading telecommunications company in Australia is seeking a Senior Threat Research and Intelligence Analyst to drive their threat intelligence strategy.The role requires extensive experience in ... Show more

 • Promoted

IT Incident & Change Manager — Reliability at Scale

Regis Aged CareWilliamstown, AU

A leading aged care provider in Australia is seeking an IT & Change Manager.This role involves ensuring the stability and reliability of critical digital services, leading Major Incident Management... Show more

 • Promoted

Cyber Security Delivery Lead: Drive Secure Programs

LibertyMelbourne, AU

A major non-bank lender in Australia seeks a Cyber Security Delivery Manager to coordinate cyber security initiatives across the organization.The role entails improving delivery visibility and acco... Show more

 • Promoted

Senior Cyber Risk & Advisory Lead

Scyne AdvisoryMelbourne, AU

A public purpose sector consultancy in Melbourne seeks a Cyber Advisory Consultant to enhance public trust in government digital services.You will manage cyber risks, advise clients on strategic ch... Show more

 • Promoted

Senior SOC Analyst: Incident Response and Threat Hunting

Kaizen Global TechnologiesMelbourne, AU

A leading IT services firm is seeking a Senior Talent Acquisition Specialist for a Mid-Senior level SOC Analyst role in Sydney, Australia.The ideal candidate will have over 6 years of SOC experienc... Show more

 • Promoted

Senior Incident & Network Operations Lead

TelstraMelbourne, AU

A major telecommunications company is seeking a Senior Lead - Incident Manager to oversee incident management processes.The successful candidate will have at least 5 years of experience in Incident... Show more

 • Promoted

Incidents Lead & Platform Reliability Specialist

SportsbetMelbourne, AU

Sportsbet is seeking a Service Operations Specialist to join our Technology team in Melbourne.This role involves incident management to ensure platform stability and seamless customer experience.Th... Show more

 • Promoted

Cyber Threat Defence Squad Lead - Threat Detection & Response

MedibankMelbourne, AU

A leading health insurance provider in Melbourne is seeking a Squad Lead - Cyber Threat Defence to oversee a security team and develop threat defence strategies.This role requires extensive experie... Show more

 • Promoted

Cyber Security Lead

RSM AustraliaMelbourne, AU

At RSM, our purpose is to instill confidence in a world of change for both our clients and our people.RSM Australia supports a people-centric and collaborative culture where we are committed to emp... Show more

 • Promoted

Security Program Lead | Strategy, Compliance & Incident Response

DavidsonMelbourne, AU

A leading technology consultancy in Melbourne is seeking an experienced Information Security Manager to enhance security operations and manage the cybersecurity framework.The ideal candidate will h... Show more