Staff Incident Response Commander
Contract Type:
Contractor
Location:
Sydney - New South Wales
Industry:
Information & Communication Technology
Contact Name:
Craig Nel
Contact Email:
craign@coxpurtell.com.au
Contact Phone:
0292203400
Date Published:
06-Oct-2026
- 12-month Sydney contract with a global software company
- Hands-on forensics across Kubernetes, AWS and GCP
- Senior IC role shaping process, tooling and mentoring
About the client
Our client is a global software and digital media company whose products are used by individuals and enterprises around the world. It's cyber defence centre protects the company’s products, platforms and customers, working closely with engineering, product and partner teams. The incident response team handles serious, high-visibility security events across modern cloud and application environments. It is a team that values sound judgement, composure and genuine technical depth.
About the role
This is one of the most senior incident command roles in the team, and it stays hands-on. You will lead the most complex security incidents from first alert to closure while doing the forensic investigation yourself, across web applications, APIs, containers and multi-cloud infrastructure. You will bring order to incidents that span many internal teams and external partners, and move comfortably between deep technical analysis and clear briefings for senior leadership. Beyond live incidents, you will help shape how the team responds through better process, tooling, exercises and mentoring.
Duties
- Command complex security incidents across the full response lifecycle, coordinating internal teams, external partners and their security operations centres.
- Personally investigate web application, API, cloud and container compromises, including credential and data-exposure scenarios.
- Collect, preserve and analyse forensic evidence across hosts, networks, cloud platforms and large log sources, keeping defensible records throughout.
- Brief senior leadership clearly under pressure, and assign and drive remediation across multiple teams and organisations.
- Build tooling for evidence collection at scale, and lead retrospectives, tabletop exercises, training and mentoring for responders and commanders.
Requirements
- Extensive front-line incident response and digital forensics experience across many major incidents, with proven command of the full incident lifecycle.
- Hands-on investigation of web application and API compromises, such as broken access control, authentication and authorisation bypass, IDOR, API abuse and CMS exploitation.
- Cloud-native and container forensics, including Kubernetes and ephemeral infrastructure, with strong AWS and GCP experience across logging, identity and authorisation models.
- Deep host and network forensics, including Linux internals and Windows and macOS artefacts.
- EDR at scale (for example CrowdStrike Falcon), complex SIEM analytics, and log and data analysis across large platforms and data warehouses.
- Scripting in Bash and at least one interpreted language, such as Python.
- Working knowledge of ISO 27001, SOC 2, HIPAA, GDPR and PCI.
- Willingness to join an on-call rotation and respond to critical events.
- Highly regarded: Azure, malware triage and reverse engineering, GCFA, GCIH, GNFA or cloud security certifications, and a government or law-enforcement investigation background.
How to apply
If this sounds like the kind of work you do best, we would love to hear from you, apply now.
Share this job

