Senior Insider Threat Analyst
Date: 29 Jul 2026
Location: Sydney, Australia
Company: Singtel Group
Optus is a leading Telecommunications company known for delivering innovative solutions to its customers, disrupting the industry, and evolving as a technology company with a diverse range of products and services. As cyber threats continue to evolve, protecting our people, data, and intellectual property is more important than ever. We're looking for a Senior Insider Threat Analyst to help strengthen our security posture by identifying, investigating, and mitigating insider risks while championing a culture of trust, accountability, and risk awareness.
What You'll Do
Partnering closely with the Director, Insider Threat, and collaborating with stakeholders across Cyber Security, Physical Security, Legal, Privacy, HR, Risk, Compliance, and Business Leadership, you will be responsible for:
- Operating and enhancing insider risk detection capabilities across technologies including UEBA, DLP, CASB, EDR, SIEM, User Activity Monitoring, and cloud telemetry platforms.
- Developing and maintaining analytics, detection rules, investigative playbooks, and monitoring models to identify data exfiltration, intellectual property theft, fraud, sabotage, privileged misuse, and policy violations.
- Leading and supporting insider threat investigations, including evidence collection, timeline reconstruction, case management, reporting, and stakeholder engagement.
- Correlating technical indicators with business and people-related risk signals, including access changes, employee lifecycle events, physical access records, and behavioural indicators within approved governance frameworks.
- Triaging and assessing insider risk alerts, determining severity, intent, business impact, and recommending appropriate containment and remediation actions.
- Producing clear, defensible investigation reports and executive briefings suitable for legal, audit, compliance, and leadership audiences.
- Coordinating technical and administrative containment activities, including access management, monitoring enhancements, data quarantine, and control improvements.
- Driving proactive risk reduction through awareness initiatives, policy reviews, behavioural change strategies, and recommendations for improved security controls.
- Contributing to insider threat governance forums, metrics reporting, threat intelligence activities, and continuous improvement of the Insider Threat Program.
- Staying current on emerging insider threat techniques, data exfiltration methods, cloud security risks, and industry best practices.
What You'll Bring
- 3+ years of experience in insider threat, cyber security operations, threat hunting, investigations, fraud intelligence, digital forensics, law enforcement, or a related discipline.
- Experience leading or supporting complex investigations involving sensitive information and multiple stakeholders.
- Strong knowledge of security monitoring and detection platforms such as Microsoft Sentinel, Splunk, CrowdStrike, Defender for Endpoint, DLP, CASB, UEBA, or similar technologies.
- Proficiency in security analytics and query languages such as KQL, SPL, or SQL.
- Understanding of data exfiltration techniques, insider threat tactics, and behavioural risk indicators.
- Knowledge of evidence handling, chain of custody processes, and the creation of defensible investigation documentation.
- Strong stakeholder management skills and the ability to collaborate effectively across Security, HR, Legal, Privacy, and Compliance functions.
- Excellent written and verbal communication skills with the ability to present findings to both technical and non-technical audiences.
- High levels of integrity, discretion, sound judgment, and professionalism when handling sensitive matters.
Nice to Have
- Industry certifications such as Security+, CySA+, GCIH, GCFA, GCFE, CISM, CIPM, or Certified Cybersecurity (CC).
- Experience with Microsoft Purview Insider Risk Management, Microsoft Defender, Google Workspace auditing, or cloud security platforms.
- Knowledge of regulatory and compliance frameworks such as ISO 27001, NIST, SOX, PCI DSS, or privacy legislation.
- Experience with scripting and automation using PowerShell or Python.
The Good Stuff...
- Competitive remuneration and employee discounts. Make life easier (and more affordable) with $80 monthly credit and 25% off Optus products and unique shopping discounts with our retail partners.
- Flexible working arrangements with opportunities to work three days in the office and two days remotely.
- Vibrant and collaborative office campus featuring cafes, convenience store, chill-out zones, GP, post office, gym, and on-site childcare centre.
- Competitive leave policies, including additional Connected Days to focus on culture, family, health, community, or whatever matters most to you.
- Inclusive, carer-neutral paid parental leave of up to 16 weeks.
- Ongoing learning and development opportunities through Optus U and industry-focused micro-credentials.
- Employee-led inclusion networks and diversity initiatives that foster belonging and connection.
- Access to confidential wellbeing and support services available 24/7.
At Optus, we are strengthened by others and that means valuing diversity and saying "yes" to embracing individual differences. We are committed to ensuring our application process provides equal employment opportunities to all job seekers, including individuals from diverse gender, cultural and linguistic backgrounds, people with disability, LGBTQIA+ individuals, veterans, and Aboriginal and Torres Strait Islander peoples.
If you require adjustments or accessibility support during the recruitment process, please let us know. We're here to help.
For more information on Diversity, Inclusion & Belonging at Optus, please visit: https://www.optus.com.au/about/inclusion-diversity.