Jobs and Careers
UN

Manager, Cyber Security Incident Response

UNSW
AustraliaRemotefull_timeVerifiedPosted 20 Aug 2026

About the role

  • Full time continuing role as Manager, Cyber Security Incident Response
  • Excellent salary package available 
  • Kensington, Sydney location, 2-3 days in the office, Hybrid working 
About UNSW: 

UNSW isn’t like other places you’ve worked. Yes, we’re a large organisation with a diverse and talented community; a community doing extraordinary things. Together, we are driven to be thoughtful, practical, and purposeful in all we do. Taking this combined approach is what makes our work matter. It’s the reason we’re one of the top 20 universities in the world (QS top 20) and a member of Australia’s prestigious Group of Eight. If you want a career where you can thrive, be challenged and do meaningful work, you’re in the right place. 

With a significant uplift within our Cyber teams, this role of Manager, Cyber Security Incident Response will lead an experienced CSIRT team responsible for managing all aspects of the incident response process operating within a hybrid operating model working closely together with our Managed Security Service Providers (MSSP). The position requires expert knowledge and significant experience in:  

Cyber security incident management and response, digital forensics, threat intelligence and threat hunting, cyber security frameworks, security technologies and automation including SIEM, EDR and SOAR, and Security Operations Centre service delivery. 

We need someone who has exceptional interpersonal skills, enabling effective communication and collaboration with partners, vendors, and both internal and external stakeholders. The role will also develop and maintain incident reports, playbooks, procedures, escalation processes, and response plans aligned to best practices. The role reports directly to the Head of Cyber Security Operations. There will be a team of Specialists reporting to the Manager, Cyber Security Incident Response.  

Specific accountabilities for this role include:  

  • Lead and mentor a team of incident response specialists, overseeing major incident response, threat hunting, threat intelligence, and digital forensics services within a hybrid operating model.  
  • Foster team development and collaboration ensuring high standards of performance in delivering these critical services.  
  • Manage investigations and ensure resources are appropriately assigned to perform actions in partnership with all relevant stakeholders  
  • Manage and co-ordinate incident response activities between UNSW and external partners.  
  • Act as an escalation point for major security incidents impacting the organisation, coordinating communications and response activities together with other operations teams.  
  • Actively participate in crisis management efforts, ensuring alignment between incident response, business continuity, and executive leadership to minimise impact and expedite recovery.  
  • Accurately document all actions taken during an incident, preparing detailed technical reports and executive summaries in alignment with established processes, standards, and frameworks.  
  • Present security reports on a regular basis analysing trends, patterns, and insights to provide recommendations  
  • Provide regular updates on all aspects of the incident management function to ensure issues, risks, and problems are addressed in a timely manner and services are operating effectively following a continuous improvement model  
  • Develop and maintain playbooks, operating procedures, technical standards, processes, knowledge base articles and other documentation as required  
  • Lead the design, implementation, and continuous improvement of an Agentic SOC operating model, ensuring automation and AI-enabled workflows materially strengthen detection and response capability, while embedding appropriate human oversight, governance, accountability, and operational assurance  
  • Analyse and report on cyber threat intelligence to prepare, prevent, and identify threats targeting the organisation  
  • Proactively conduct threat hunting to detect anomalous activity leveraging advanced techniques to identify emerging threats, vulnerabilities, and suspicious behaviours across the environment  
  • Regularly track and validate supplier performance in accordance with KPI’s, objectives, and contract terms, and resolving or escalating performance issues or disputes  
  • Contribute to the development, implementation, and optimisation of security controls, services, and technologies across Security Operations  
  • Adhere to IT Service Management practices across UNSW IT, Faculties, Divisions, and Affiliates  
  • Oversee and finalise effective communications with key stakeholders, both internal and external and provide influential input with s

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

UNSW

View company profile →