380,223open jobs
9,940companies
48,310added this week
Browse all
Location
Remote/Hybrid (Melbourne, Australia)
Employment
Full-Time
Overview
Company
Impact
Profile match
Triskele Labs provides cybersecurity consulting and managed detection services. Its work covers penetration testing, governance and security operations. Mid-market Australian organisations form its main client base.

Triskele Labs is one of Australia’s leading sovereign cyber security firms, delivering Managed Detection & Response (MDR), Digital Forensics & Incident Response (DFIR), Offensive Security, and Governance, Risk & Compliance (GRC) services to regulated enterprises, government, and the higher education sector. Built over more than a decade, founder-led and independently owned, we partner with clients operating under some of Australia’s most demanding regulatory regimes.

Our Security Operations Centre runs 24x7x365 and remains completely onshore, and we are the largest CREST Registered Penetration Testing company in Melbourne. Sovereign Australian ownership, deep technical capability, and front-line threat intelligence from one of the most active DFIR practices in the country sit at the centre of how we differentiate.

We are hiring a SOC Manager to lead the operational performance of our Australian Security Operations Centres. You will manage our L1 to L3 analyst structure, you will own rostering and capacity across a 24x7x365 operation, own the SOC’s workflow and triage automation roadmap through your SOC Automation Analyst, and be accountable for how well our MDR service actually runs in front of the client.

The role sits alongside our Platform Engineering Manager, and the two roles carry the MDR service between them. Platform Engineering owns what the service can detect, hunt and validate: detection engineering, cyber threat intelligence, threat hunting and breach attack simulation. The SOC owns how well that capability is operated: triage quality, service levels, escalation handling, client communication, the development of the analysts doing the work, and the workflow and triage automation that makes the operation scale.

That boundary is deliberate and it is the most important thing to understand about this role. You are not building the detection capability. You are leading the function that consumes it well, and will need to be the peer who tells Platform Engineering the truth about what is and is not working in the queue. The partnership is at a minimum a weekly operating rhythm and joint prioritisation, not an escalation path used after something has gone wrong.

Automation runs the other way. Workflow and triage automation belongs to the SOC, and the SOC Automation Analyst reports to you. You decide what gets automated next, you hold the quality bar on playbook design, and you partner with the SOAR Engineer and the DevOps team, who provide the platform capability, integrations and infrastructure underneath.

This is a hands-on operational leadership role, not a reporting layer. You will need enough technical depth to challenge an analyst’s conclusion, review playbook logic rather than just its outcomes, and judge the operational impact of a detection or automation change before it reaches the live queue.

You must be able to weigh the risk and the benefit of those decisions, to keep our service at the forefront of our clients’ cyber security concerns while supporting our team to do their work effectively and safely.

Key Responsibilities

Leadership

  • Lead, coach and manage the SOC analyst team from L1 through to L3, and the SOC Automation Analyst, across state-based Security Operations Centres, owning performance reviews, career development and succession planning.
  • Own rostering, scheduling and capacity across a 24x7x365 operation, including roster fairness, fatigue monitoring, mental health awareness and analyst wellbeing.
  • Refine and drive the analyst development pathway from L1 through to L3 and onward into Platform Engineering, DFIR or engineering specialisations, identifying training needs and knowledge gaps and acting on them.

Operational management

  • Ensure day-to-day SOC operations meet SLA, KPI and incident response commitments, and act as the key operational escalation point for the team.
  • Oversee escalations across the L1 to L3 tiers and coordinate high-severity incident response, shift standups and handoffs.
  • Own workflow and triage automation and the SOC automation roadmap, agreed with the Head of Managed Services and delivered through the SOC Automation Analyst who reports to you: deciding what gets automated next, reviewing playbook design and logic, and holding delivery and quality.
  • Maintain SOC processes, SOPs, runbooks and knowledge management aligned to ISO 20000, ISO 27001 and SOC 2, and support audit preparation and evidence rigour.
  • Drive incident simulation planning, and support post-incident reviews so that what is learned reaches the runbooks.

Client service

  • Act as a senior escalation contact for key MDR clients, and attend client meetings during onboarding, escalation and service review.
  • Own the operational readiness of new client onboarding into the SOC: tooling, alerting, runbooks and analyst enablement in place before the client goes live.
  • Ensure the quality, consistency and timeliness of incident documentation, case categorisation, remediation guidance, threat briefs and monthly service reporting.

Capability and tooling

  • Drive the evolution of the SOC’s tooling and automation, SIEM, SOAR and EDR, from the operational side, and evaluate emerging technology for what it would genuinely do for triage quality, response time and analyst effort.
  • Define the SOC’s operational requirements for tooling and workflow, and work with Engineering, DevOps and Platform Engineering to see them delivered.

Platform Engineering partnership

  • Hold the peer relationship with the Platform Engineering Manager: weekly operational alignment, joint prioritisation of detection improvements, and integration of client feedback into their roadmap.
  • Own the SOC side of the feedback loop, ensuring false-positive patterns, noisy alerts and missed-detection observations reach Detection Engineering in a structured, actionable form.
  • Ensure Platform Engineering output, validated detections, enriched indicators, hunt findings and BAS gap data, is operationalised in the SOC with analysts trained and runbooks updated before the change reaches the queue.

Governance and reporting

  • Ensure SOC practice remains compliant with ISO 27001, ISO 20000 and SOC 2, and contribute to internal and external governance and assurance reporting.
  • Provide regular reporting to the Head of Managed Services on performance, escalations, threats, staffing and initiatives.

Organisational contribution

  • Contribute to Triskele Labs’ thought leadership through blog content, Brown Bag talks and internal showcases.
  • Represent the SOC at industry events and client forums where useful.
  • Lead by example to uphold the culture, values and technical standards expected of a high-performing SOC.

Application Process

A cover letter addressed to Brad Morgan, Head of Managed Services, is mandatory for this role. Applications without one will not be considered. Tell us about a SOC you have run and one operational problem you fixed that the metrics can prove.

Requirements

  • Australian citizenship or permanent residency. This is a sovereign MDR requirement and sponsorship is not available.
  • Based in Melbourne and able to work on-site, with some work from home available by agreement.
  • Minimum five years in a SOC environment, including at least two years in a leadership role.
  • Proven experience managing 24x7 SOC operations, shift teams and security case processes in an MSSP or enterprise environment, including ownership of rostering and capacity planning.
  • Strong technical understanding of SIEM, SOAR, EDR and incident response, enough to challenge an analyst’s conclusion, review playbook logic, and hold a quality bar, not only to report on one.
  • Sound judgement on risk and benefit: able to weigh the operational upside of a detection, automation or process change against its impact on service quality, client risk, and the analysts who have to work with it.
  • Excellent written and verbal communication across technical and executive audiences, including direct client escalation handling.
  • Available for after-hours escalation as required, and able to travel occasionally to other state-based SOC locations or clients.

Highly Regarded

  • Demonstrated ownership of a workflow and triage automation capability: deciding what to automate, reviewing playbook design, and directing the person building it.
  • Demonstrated ability to operate as a peer to an engineering or platform function without absorbing or duplicating its remit.
  • Strong working knowledge of security frameworks including MITRE ATT&CK, NIST and ISO.
  • Experience with our stack or equivalent: Microsoft Sentinel, Splunk, Rapid7 InsightIDR, Elastic, Microsoft Defender, CrowdStrike, and Shuffle or an equivalent SOAR platform.
  • Hands-on SOAR playbook build experience, or the ability to review playbook logic in detail rather than only its outcomes.
  • Experience managing geographically distributed or state-based operational teams.
  • Exposure to ISO certification audits or SOC-CMM assessment.
  • Experience building or operating an analyst development pathway and moving people through it.
  • Certifications such as GCIA, GCIH or equivalent SOC leadership credentials, and experience with reporting tools such as Power BI.
  • A bachelor’s degree in cyber security or information technology, or demonstrated equivalent experience.

Benefits

Team culture is everything to Triskele Labs and it is the reason we exist. We are a forward-thinking company and always looking for ways to boost our team culture to ensure we are a destination employer. We continually undertake surveys to seek feedback from our team on ways we can improve our work environment and team member experience at Triskele Labs.

We provide our team a great range of additional benefits such as:

  • Collaborate closely with C-Suite executives and gain insights from top industry leaders.
  • Help influence and lead the SOC Team’s growth as we continue to expand throughout the Australian market.
  • Enjoy a brand-new office located in the heart of Melbourne CBD.
  • Frequent events organised by our People & Culture Team.

Benefits Specific to this role

  • Operational leadership of an onshore, sovereign 24x7 SOC serving financial services, government, health and higher education.
  • A genuine peer partnership with a dedicated Platform Engineering function, rather than carrying detection engineering and operations in one overloaded role.
  • A dedicated SOC Automation Analyst reporting to you, and a SOAR Engineer and DevOps team to partner with. The workflow and triage automation agenda is yours to set, with people to deliver it.
  • Direct reporting line to the Head of Managed Services, and close collaboration with our C-Suite. This is a role with genuine access to the people setting the direction of the business.
  • Real influence over the growth of the SOC team as we continue to expand across the Australian market.
  • Real capability to draw on: DFIR, CTI, threat hunting, detection engineering and offensive security practices in the same business.
  • Funded certification and development, for you and for your team.
  • A team that backs each other, with leaders who work the floor rather than manage from a distance.

You must include a cover letter addressed to Brad Morgan, Head of Managed Services to be considered for this role.

Working Arrangements:

The role is full time, Monday to Friday in our Melbourne office.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
380,223 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Melbourne
$245k – $384k per year • Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • Bucharest
C#
JavaScript
Node JS
PowerShell
SQL
TypeScript
C#
.NET
Databases
Redis
Frontend
Angular
DevOps
Azure
Azure DevOps
CI/CD
GitHub
GitHub Actions
GitOps
Terraform
Analytics
Power BI
Apply
$122k – $245k per year (Estimated) • Remote/Hybrid • New York
PHP
PHP
Laravel
Databases
BigQuery
Google BigQuery
Pinecone
AI/ML
Claude
Evidently AI
LLM
LLM Guardrails
OpenAI
RAG
Vertex AI
DevOps
Amazon CloudWatch
Amazon EC2
Amazon EKS
Amazon S3
AWS
AWS CDK
Buildkite
CI/CD
Docker
GCP
GitHub
Google GKE
IAM
Incident Management
Kubernetes
OpenTelemetry
Shift-Left
Terraform
Vector
Cybersecurity
GDPR
ISO 27001
Lacework
Least Privilege
SBOM
Shift-Left Security
SLSA
SOC 2
Wiz
Apply
In office • Internship • Hong Kong
Visual Basic
Analytics
Power BI
Apply
In office • 2+ years exp • Bachelor's Degree
SQL
Analytics
Power BI
Tableau
Marketing
Instagram
LinkedIn
X (Twitter)
YouTube
Apply
$200k per year • Equity • Remote • Full-Time • 3+ years exp
TypeScript
AI/ML
AI Agents
Edge AI
LLM
Red Teaming
DevOps
AWS
Azure
GCP
Kubernetes
Cybersecurity
Burp Suite
Cobalt Strike
Metasploit
MITRE ATT&CK
OWASP Top 10
Apply
Remote/Hybrid • Full-Time • Melbourne
Cybersecurity
Carbon Black
Crowdstrike
KAPE
Magnet AXIOM
Microsoft Defender
Microsoft Entra ID
Microsoft Sentinel
SentinelOne
Velociraptor
Volatility
X-Ways Forensics
Apply
In office • Full-Time • Melbourne
PowerShell
Python
DevOps
Platform Engineering
Splunk
Cybersecurity
Crowdstrike
Microsoft Defender
Microsoft Sentinel
SentinelOne
Wazuh
Apply
$98k – $201k per year (Estimated) • In office • Full-Time • Melbourne
DevOps
Platform Engineering
Apply
up to $93k per year • Remote/Hybrid • Full-Time • 3+ years exp • Melbourne
Apply
Sr Developer 10 hours ago
$73k – $183k per year (Estimated) • Remote/Hybrid • Full-Time • Melbourne • Brisbane • Canberra
C#
PowerShell
SQL
TypeScript
JavaScript
C#
.NET
Frontend
Angular
DevOps
AWS
Azure
Azure DevOps
CI/CD
Apply
Remote/Hybrid • Full-Time • Canberra • Brisbane • Melbourne
C#
Node JS
PowerShell
SQL
TypeScript
JavaScript
C#
.NET
Databases
MS SQL
Frontend
Angular
DevOps
AWS
Azure
Azure DevOps
CI/CD
Git
Rest API
QA
Postman
Selenium
Apply
$39k – $97k per year (Estimated) • In office • Full-Time • 10+ years exp • Sydney • Melbourne
Java
TypeScript
DevOps
CI/CD
GitHub
GitHub Actions
GitLab
Jenkins
Shift-Left
Cybersecurity
Shift-Left Security
QA
Playwright
Apply
$107k – $257k per year (Estimated) • In office • Full-Time • Sydney • Brisbane • Melbourne
Java
Python
Scala
SQL
Databases
Snowflake
AI/ML
dbt
DevOps
AWS
Azure
CI/CD
Cortex
Datadog
GCP
Splunk
Terraform
Vector
Prometheus
Cybersecurity
GDPR
HIPAA
SOC 2
Analytics
ETL/ELT
Apply
$86k – $205k per year (Estimated) • In office • Full-Time • Melbourne • Sydney • Brisbane
DevOps
Incident Management
Apply
See all jobs
This is one of many
380,223 more open roles from verified company boards, updated every day.