BLACK OPS SOLUTIONS · IT Graduate IT Interview PackAU · 2026

Cyber Security Analyst · graduate level · Australia

Graduate Cyber Security Analyst

Works the alert queue that decides whether an intrusion is caught in an hour or a month.

Job description · fictional employer

Graduate Cyber Security Analyst

Ironbark Security Group

Location
Canberra - hybrid, 3 days in office, on site during onboarding
Employment type
Full-time, permanent - 18-month structured graduate pathway
Salary
AUD $84,000 base + 12% superannuation + shift allowance once rostered
Reports to
SOC Manager, Detection and Response
Intake
February 2027 - applications close 25 September 2026

About us

Ironbark Security Group runs a 24/7 security operations centre in Canberra for 40 clients - federal and state agencies, a water utility, two health networks and a national retailer. We are 120 people, 55 of them in the SOC. Our clients do not buy dashboards from us. They buy the judgement of the person reading the alert at 3am.

The team you would join

Detection and Response is 22 people: nine Tier 1 analysts, six Tier 2, three threat hunters and four detection engineers. Tier 1 is where every ticket starts and where most of the learning happens. Nothing a graduate closes goes out unreviewed for the first six months.

What you will do

  • Triage alerts from the SIEM queue from your third week, with a Tier 2 analyst reviewing everything you close
  • Investigate reported phishing end to end - headers, links, attachments, who received it, who clicked, what to contain
  • Escalate with a hypothesis and the evidence behind it, not a screenshot and a question mark
  • Write the client-facing incident notes, in language a practice manager or a finance officer can act on
  • Help tune detections that fire constantly and catch nothing, and measure whether your change worked
  • Run scheduled vulnerability scans and help clients decide what actually has to be patched this week
  • Fix the playbook when you find a step in it that is wrong - we would rather you edit it than work around it
  • Join the rostered shift pattern from month 9. No overnight shifts in your first year

What we are looking for

  • A completed or in-progress bachelor degree in cyber security, IT, computer science or a related discipline, graduating between November 2025 and December 2026
  • A working picture of how a network conversation happens - DNS, TCP, HTTP, and what normal looks like so you can notice abnormal
  • Comfort with Windows and Linux fundamentals: processes, services, accounts, permissions, and where the logs live
  • Curiosity that survives a boring queue. Most alerts are nothing. The discipline is in the one that is not
  • Clear written English. An investigation nobody can read has no value to the client
  • Australian citizenship and eligibility for an Australian Government Baseline security clearance, which we sponsor

Nice to have

  • A home lab, CTF results, or a TryHackMe or Hack The Box profile you can talk through
  • Any scripting - Python or PowerShell, even short and ugly
  • Hands on a SIEM, including a free tier or a lab build
  • Familiarity with the Essential Eight or the ISM
  • Security+, SC-200, BTL1 or similar. Useful signals, never a substitute for reasoning

What you would work in

Microsoft SentinelSplunkKQL / SPLDefender for EndpointCrowdStrike FalconProofpointTenableMITRE ATT&CKSigmaPython / PowerShellJira Service Management

What the program gives you

  • Four weeks of structured onboarding and shadowing before you touch the live queue
  • Paid certification - SC-200 or Security+ - with study leave and one paid resit
  • Fortnightly review of your own closed tickets with a Tier 2 analyst, which is the fastest way anyone learns this job
  • A six-week rotation into detection engineering or threat hunting in your second year
  • Shift allowance, time off in lieu, and a hard rule that nobody works a double

How the process runs

  1. 1

    Application

    CV plus three short written questions. No cover letter.

  2. 2

    Online assessment

    45 minutes - networking, log reading and scenario judgement. No trick questions.

  3. 3

    Talent screen

    30-minute call - motivation, shift work, citizenship and clearance eligibility.

  4. 4

    Technical interview

    60 minutes - fundamentals plus a triage scenario you drive.

  5. 5

    Panel

    45 minutes with the SOC manager and a Tier 2 analyst, including a short written summary you produce on the day.

We hire graduates for judgement and for how they write, not for how many acronyms they can list. If you meet most of the essential criteria and none of the desirable ones, apply anyway. Reasonable adjustments are available at any stage of the process - tell your talent partner what you need.

Example CV · fictional candidate

Aisha Rahman

Written to the job description on the previous tab. Notes on the right explain each choice.

Aisha Rahman

Graduate Cyber Security Analyst

Canberra ACT · 0400 000 000 · [email protected] · github.com/aisharahman · linkedin.com/in/aisha-rahman

Professional summary

Cyber security graduate with a twelve-week SOC internship, a home detection lab where I run the attack and then hunt it in my own SIEM, and a habit of writing up what I find. Comfortable taking an alert from queue to closure and explaining it to someone non-technical. Australian citizen, eligible for a Baseline clearance.

Technical skills
Security tooling
Microsoft Sentinel, Wazuh, Splunk (free tier), Defender for Endpoint (lab), Nessus Essentials, Burp Suite Community
Detection and analysis
KQL, Sigma rules, MITRE ATT&CK mapping, Wireshark, email header and URL analysis
Scripting
Python, PowerShell, bash (all working level, not polished)
Systems
Windows Server and Active Directory, Ubuntu, pfSense, Proxmox
Frameworks
Essential Eight, ISM familiarity, NIST CSF basics
Ways of working
Ticket hygiene, incident write-ups, peer review of closed tickets
Education
Bachelor of Cyber Security
Feb 2023 - Nov 2026

University of Canberra

  • GPA 6.0 / 7. Distinction average across security units
  • Relevant units: Network Security (7), Digital Forensics (7), Incident Response (6), Systems Administration (6), Cryptography (6)
  • Capstone: built an attack and detection lab and wrote twelve Sigma rules against it. See Projects below
Experience
Security Operations Intern (Tier 1, supervised)
Nov 2025 - Feb 2026 (12-week vacation program)

Saltbush Managed Services, Canberra

  • Triaged around 40 Tier 1 alerts a week, every one reviewed by a Tier 2 analyst before closure
  • Investigated and wrote up six phishing campaigns, including one where credentials were entered and sessions had to be revoked
  • Proposed two scoped exclusions that took a chronically noisy detection from 60 alerts a day to 4, with no known misses in the following six weeks
  • Rewrote the phishing triage playbook after finding two steps in it that no longer matched the tooling
IT Service Desk Officer (casual, 15 hrs/week)
Mar 2024 - present

University of Canberra, IT Services

  • First-line support for around 600 staff and students - accounts, MFA enrolment, device setup
  • Spotted and escalated a credential phishing wave from three near-identical tickets, with samples attached
  • Wrote the MFA troubleshooting article that is now the most-viewed page in the internal knowledge base
Duty Manager
Feb 2022 - Feb 2024

Capital Cinemas, Canberra

  • Ran evening shifts of up to nine staff while studying full time
  • Handled cash reconciliation, incident reports and the occasional genuinely difficult customer
Projects
Detection lab - build the attack, then catch it
Proxmox, Windows Server 2022, Active Directory, Sysmon, Wazuh, Atomic Red Team
  • Two-domain lab where I execute ATT&CK techniques and then write detections for them
  • Twelve Sigma rules published with the false positives each one produced in my own environment, which is the part most repositories leave out
  • github.com/aisharahman/detection-lab
Phish-report - reported email triage helper
Python, Microsoft Graph API, VirusTotal API
  • Parses a reported email, extracts headers, URLs and attachment hashes, and produces a one-page summary for the analyst
  • Cut my own average triage time during the internship from about 12 minutes to about 4
  • Deliberately does not auto-close anything - it gathers, a human decides
BSides Canberra CTF 2025
Team event, 60 teams
  • Placed 9th. Wrote up the two forensics challenges I solved, including the one that took me four hours and should have taken forty minutes
Leadership and activities
  • Vice-President, UC Cyber Security Club, 2025 - 2026. Ran a weekly hands-on session; attendance went from 8 to 30
  • Volunteer, BSides Canberra 2025 - registration desk and speaker wrangling
  • Mentor, high school Cyber Explorers day, 2025
Certifications
  • CompTIA Security+ (SY0-701), January 2026
  • Microsoft SC-900: Security, Compliance and Identity Fundamentals, August 2025
  • TryHackMe SOC Level 1 pathway completed, 2025
Referees

Available on request.