Senior Analyst / Assistant Manager – Incident Response
McGrathNicol
Sydney, New South Wales
The Role
This position involves supporting cyber incident response engagements across triage, evidence collection, and forensic analysis of endpoints, servers, and cloud environments. Analysts examine security telemetry and logs to reconstruct timelines, assess incident scope, and assist technical teams with containment and eradication, while producing clear, client-ready reporting under senior direction.
Skills & Experience
Candidates should bring hands-on experience with forensic acquisition, chain-of-custody procedures, and log analysis tools such as EDR and SIEM platforms. Familiarity with defensible evidence handling practices is essential. Relevant certifications in digital forensics or incident response, such as GCFE, GCFA, or GCIH, are advantageous for this level of role.
Who It Suits
This role suits an analytically minded professional with a solid incident response foundation who thrives in fast-paced, high-pressure environments. Someone seeking structured career development within a collaborative advisory team, comfortable balancing technical investigation work with clear written communication to both technical and non-technical client audiences, will find it rewarding.
Typical advertised salary for Incident Response roles in Australia: A$95,000–A$129,000 (median A$100,000 — from 9 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in Australia →
Certifications mentioned: GCFA · GCFE · GCIH — find training for these on the DFIR Training Finder.





