Cyber Security Analyst

4 days ago


Wellington Central, Wellington, New Zealand Cubic Transportation Systems Full time NZ$120,000 - NZ$180,000 per year

Job Description

Job Description

Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.

Job Summary:

As a member of the Cubic Information Security Team, you will be responsible for supporting efforts to monitor security for Cubic systems and assist in the analysis and response to incidents. The successful candidate must be proficient at security monitoring using Tenable, Crowd Strike, Splunk, and Imperva and other security tools. Work will be on Windows and Linux assets in cloud or data centers. Analysts will be responsible for IT security tools and processes to manage and report operational security risks to operations teams for remediation. The analyst must have an intimate awareness of PCI security compliance expectations. The candidate will be a partner to support external audits to facilitate PCI-DSS, ISO 27001, and SOC compliance/audit efforts. Scanning operations will involve routine daily or weekly operations as well as support for pen testing or audit efforts. Findings must be risk rated and effectively escalated for remediation. Will be recognised internally as a subject matter expert. Works autonomously, able to assess and drive work priorities, with limited support or guidance needed.

RESPONSIBILITIES

Essential Job Duties and Responsibilities

Security Monitoring Configuration

  • Design and implement security monitoring solutions using SIEM, EDR, NDR, CSPM, and cloud-native tools (e.g. Azure Cloud Defender, AWS Security Hub, Guard Duty, Inspector, and Cloud Watch).
  • Integrate log sources from on-prem systems (firewalls, servers, endpoints, network devices) and cloud platforms (IaaS, PaaS, SaaS) into centralized monitoring systems.
  • Develop and tune detection rules and correlation logic to identify suspicious behavior, policy violations, and potential threats.
  • Tune detection rules to reduce false positives and improve signal-to-noise ratio.
  • Maintain visibility across hybrid environments by ensuring telemetry coverage and log integrity.

Threat Detection and Analysis

  • Monitor alerts and logs for indicators of compromise (IOCs) and suspicious activity.
  • Correlate events across multiple sources to identify potential threats.
  • Perform triage and initial investigation of alerts to determine severity, scope, and potential impact.
  • Use threat intelligence feeds to enrich alerts and prioritize response.

Incident Escalation and Coordination

  • Document and escalate validated security incidents to the appropriate operations or incident response teams.
  • Provide detailed context, including affected systems, users, and potential impact.
  • Collaborate with operations staff to ensure timely containment, eradication, and recovery.
  • Track and report on escalated incidents, including root cause analysis and remediation status.

Continuous Improvement

  • Review and refine detection logic based on incident post-mortems, false positives, emerging threats, and operational feedback.
  • Participate in threat hunting and proactive analysis to identify gaps in monitoring coverage.
  • Recommend and implement automation for alert triage and response workflows.
  • Contribute to playbooks and standard operating procedures for alert handling and escalation.
  • Stay current with emerging threats, vulnerabilities, and security technologies.

Compliance and Reporting

  • Ensure monitoring configurations support regulatory and policy requirements (e.g., PCI, ISO 27001, GDPR, CIS, etc).
  • Generate reports on security posture, alert trends, and incident metrics for leadership and governance teams.
  • Assist with audits and provide evidence of monitoring controls and incident handling.

General Duties and Responsibilities:

  • Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.
  • Able to work effectively and uphold professional standards, with the customer and system stakeholders.
  • Self-motivated and able to work unsupervised
  • Methodical and Attentive to detail
  • Proactive in seeking advice from security subject matter experts when required
  • Comfortable working with staff at all levels and in other geographical locations within the organization

  • Comply with Cubic's Quality Management System

  • Comply with Cubic's quality, health, safety, and security policies.
  • Support the company's strategic objectives and collaborate across departments.
  • Comply with Cubic Human Resources Procedures

SKILLS/EXPERIENCE/KNOWLEDGE

Essential:

  • Familiarity with PCI DSS 4, ISO , and/or SOC I/II requirements and audits.
  • Experience installing, configuring and supporting Tenable, Crowd Strike, Splunk, and Imperva in Windows and Linux environments
  • Experience performing monitoring in Azure and AWS cloud environments, as well as in data centers.
  • In depth understanding and experience in network security. Strong preference for someone who has had experience working as a network security admin and/or cloud or systems security admin.
  • Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization. Able to adapt style efforts to persuade in delivering messages that relate to the wider business. Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.
  • Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures. Provides solutions to issues in creative and effective ways. Understands the interrelationships of different disciplines. Directs the application of existing principles and guides development of new policies and ideas.
  • Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Determines methods and procedures on new assignments. Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.
  • This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.

Desirable:

  • Deep understanding of security risks and threats as they relate to the company's operating environments.

QUALIFICATIONS

Essential:

  • Minimum 8 years' experience in services or IT systems in a mission critical setting.
  • University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.
  • At least 5 years' experience working in IT security and/or Payment Card processing systems. Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.
  • The candidate must reside within commuting distance from CTS offices in Brisbane QLD, Sydney NSW or Wellington NZ, and be able to periodically travel within the region.

Desirable

  • Certification as an Information Security professional (e.g. ISACA CISA/CISM/CRISC, ISC(2) CISSP, BCS CISMP/IISP)
  • Payment Card Industry Security Standards Council certification (ISA/ QSA)

Condition of Employment:

Successful outcome of a National Police Check

The description provided above is not intended to be an exhaustive list of all job duties, responsibilities and requirements.  Duties, responsibilities and requirements may change over time and according to business need.



  • Wellington, Wellington, New Zealand New Zealand Government Full time NZ$1,100,000 - NZ$1,500,000 per year

    The Ministry acts in the world to build a safer, more prosperous and more sustainable future for New Zealanders.Kia hangai ake e te Manatu he ao-haumaru, ao-tonui, ao-pumau, ki te oranga tonutanga mo Aotearoa whanui.Keep our people, information and systems safeJoin a diverse team in a unique organisation with a global footprintWellington based - Permanent...


  • Wellington, Wellington, New Zealand Ministry of Foreign Affairs & Trade Full time NZ$106,973 - NZ$125,850 per year

    Company description: The Ministry acts in the world to build a safer, more prosperous and more sustainable future for New Zealanders.Kia hangai ake e te Manatu he ao-haumaru, ao-tonui, ao-pumau, ki te oranga tonutanga mo Aotearoa whanui.Job description: Keep our people, information and systems safeJoin a diverse team in a unique organisation with a global...


  • Wellington, Wellington, New Zealand New Zealand Government Full time NZ$60,000 - NZ$120,000 per year

    Mo te tunga | About the roleOur Defence Cyber Security Centre (DCSC) defends and protects the Defence Information Environment against cyber security threats.Based in Wellington CBD, the DCSC operates a Cyber Security Operations Centre (CSOC) to detect and respond to cyber security incidents at pace with the evolving cyber threat landscape.As you will be...


  • Wellington Central, Wellington, New Zealand Taska360 Full time NZ$80,000 - NZ$120,000 per year

    Our customer is seeking two Cyber Technical Analysts Key things we are ideally looking for: Strong mixture of BA skills along with exposure to IDAM conceptsIt's likely you are more of a Cyber practitioner than a BA practitioner.Familiar with implementation, configuring and supporting identity platforms and access management solutions.Experience working in...


  • Wellington Central, Wellington, New Zealand Kiwibank Full time NZ$104,000 - NZ$150,000 per year

    Wellington/Auckland based opportunityBanking benefits, health insurance, flexible working options and more (parental benefits, wellbeing days of leave, etc.)Join our growing Digital & Technology TeamKō tātou tēnei. Hei kawe i ngā mahi kia tutuki | This is us. Where making an impact matters.The Information Security Analyst plays a vital part in helping to...


  • Wellington, Wellington, New Zealand New Zealand Government Full time NZ$120,000 - NZ$180,000 per year

    Mo te tunga | About the roleWe are offering an exciting opportunity for an experienced Senior Cyber Vulnerability and Penetration Tester to join our growing security team.At the Defence Cyber Security Centre (DCSC), we are committed to defending and ensuring the security of the Defence Information Environment against potential ICS threats. Our work involves...


  • Wellington, Wellington, New Zealand Ministry of Foreign Affairs & Trade Full time NZ$120,000 - NZ$160,000 per year

    Company description: The Ministry acts in the world to build a safer, more prosperous and more sustainable future for New Zealanders.Kia hangai ake e te Manatu he ao-haumaru, ao-tonui, ao-pumau, ki te oranga tonutanga mo Aotearoa whanui.Job description: An important role in the Information Management Division (IMD)You and your team will be responsible for...


  • Wellington, Wellington, New Zealand New Zealand Government Full time NZ$100,000 - NZ$150,000 per year

    The Ministry acts in the world to build a safer, more prosperous and more sustainable future for New Zealanders.Kia hangai ake e te Manatu he ao-haumaru, ao-tonui, ao-pumau, ki te oranga tonutanga mo Aotearoa whanui.An important role in the Information Management Division (IMD)You and your team will be responsible for cyber security incident responses,...


  • Wellington Central, Wellington, New Zealand BNZ Full time

    Here at BNZ, it's about more than just banking. We work together in an agile, energising environment to create innovative solutions through our promise "If you can imagine a better future, let's find a way." We support wellbeing, flexible working and have a generous leave offering. There is the opportunity for growth, learning and career development. No...


  • Wellington, Wellington, New Zealand New Zealand Government Full time NZ$90,000 - NZ$120,000 per year

    Mo te tunga | About the roleThis is a unique opportunity to become a Cyber Security expert. Drawing on a broad range of information, you will conduct intelligence analysis, assessing the intent and capabilities of cyber threat actors. You will communicate your outputs to colleagues within the Defence Cyber Security Centre (DCSC), senior officials within the...