BLACK OPS SOLUTIONS · IT Graduate IT Interview PackAU · 2026

Cyber Security Analyst · graduate level · Australia

Graduate Cyber Security Analyst

Works the alert queue that decides whether an intrusion is caught in an hour or a month.

Job description · fictional employer

Graduate Cyber Security Analyst

Ironbark Security Group

Location
Canberra - hybrid, 3 days in office, on site during onboarding
Employment type
Full-time, permanent - 18-month structured graduate pathway
Salary
AUD $84,000 base + 12% superannuation + shift allowance once rostered
Reports to
SOC Manager, Detection and Response
Intake
February 2027 - applications close 25 September 2026

About us

Ironbark Security Group runs a 24/7 security operations centre in Canberra for 40 clients - federal and state agencies, a water utility, two health networks and a national retailer. We are 120 people, 55 of them in the SOC. Our clients do not buy dashboards from us. They buy the judgement of the person reading the alert at 3am.

The team you would join

Detection and Response is 22 people: nine Tier 1 analysts, six Tier 2, three threat hunters and four detection engineers. Tier 1 is where every ticket starts and where most of the learning happens. Nothing a graduate closes goes out unreviewed for the first six months.

What you will do

  • Triage alerts from the SIEM queue from your third week, with a Tier 2 analyst reviewing everything you close
  • Investigate reported phishing end to end - headers, links, attachments, who received it, who clicked, what to contain
  • Escalate with a hypothesis and the evidence behind it, not a screenshot and a question mark
  • Write the client-facing incident notes, in language a practice manager or a finance officer can act on
  • Help tune detections that fire constantly and catch nothing, and measure whether your change worked
  • Run scheduled vulnerability scans and help clients decide what actually has to be patched this week
  • Fix the playbook when you find a step in it that is wrong - we would rather you edit it than work around it
  • Join the rostered shift pattern from month 9. No overnight shifts in your first year

What we are looking for

  • A completed or in-progress bachelor degree in cyber security, IT, computer science or a related discipline, graduating between November 2025 and December 2026
  • A working picture of how a network conversation happens - DNS, TCP, HTTP, and what normal looks like so you can notice abnormal
  • Comfort with Windows and Linux fundamentals: processes, services, accounts, permissions, and where the logs live
  • Curiosity that survives a boring queue. Most alerts are nothing. The discipline is in the one that is not
  • Clear written English. An investigation nobody can read has no value to the client
  • Australian citizenship and eligibility for an Australian Government Baseline security clearance, which we sponsor

Nice to have

  • A home lab, CTF results, or a TryHackMe or Hack The Box profile you can talk through
  • Any scripting - Python or PowerShell, even short and ugly
  • Hands on a SIEM, including a free tier or a lab build
  • Familiarity with the Essential Eight or the ISM
  • Security+, SC-200, BTL1 or similar. Useful signals, never a substitute for reasoning

What you would work in

Microsoft SentinelSplunkKQL / SPLDefender for EndpointCrowdStrike FalconProofpointTenableMITRE ATT&CKSigmaPython / PowerShellJira Service Management

What the program gives you

  • Four weeks of structured onboarding and shadowing before you touch the live queue
  • Paid certification - SC-200 or Security+ - with study leave and one paid resit
  • Fortnightly review of your own closed tickets with a Tier 2 analyst, which is the fastest way anyone learns this job
  • A six-week rotation into detection engineering or threat hunting in your second year
  • Shift allowance, time off in lieu, and a hard rule that nobody works a double

How the process runs

  1. 1

    Application

    CV plus three short written questions. No cover letter.

  2. 2

    Online assessment

    45 minutes - networking, log reading and scenario judgement. No trick questions.

  3. 3

    Talent screen

    30-minute call - motivation, shift work, citizenship and clearance eligibility.

  4. 4

    Technical interview

    60 minutes - fundamentals plus a triage scenario you drive.

  5. 5

    Panel

    45 minutes with the SOC manager and a Tier 2 analyst, including a short written summary you produce on the day.

We hire graduates for judgement and for how they write, not for how many acronyms they can list. If you meet most of the essential criteria and none of the desirable ones, apply anyway. Reasonable adjustments are available at any stage of the process - tell your talent partner what you need.

Interview questions · 21 questions with model answers

Graduate Cyber Security Analyst

Answers are hidden by default so you can attempt each one first.

Motivation and behavioural

Asked in the screen and again by the panel. The queue is repetitive, and temperament decides who lasts.

  1. Why security rather than development or infrastructure?

    Show what a strong answer coversHide answer

    A strong answer

    • Has actually done something - a lab, a CTF, a write-up - rather than describing an interest
    • Understands the job is mostly triage, evidence and writing, not exploitation
    • Can name the part that interests them specifically: detection, response, forensics, the adversary's side
    • Is honest if they are still deciding between defence and something else

    Red flagTalks about hacking and never mentions defending anything.

  2. Most of your first year is triage, and most alerts turn out to be nothing. How do you stay sharp?

    Show what a strong answer coversHide answer

    A strong answer

    • Has a method - a checklist, a consistent order of checks, notes as they go
    • Treats the boring queue as the thing that trains pattern recognition
    • Knows alert fatigue is a security risk and not just a personal one
    • Says plainly what they would find hard about it

    Red flagAssumes they will be doing threat hunting within three months.

  3. Tell me about a time you had to tell someone something they did not want to hear.

    Show what a strong answer coversHide answer

    A strong answer

    • Led with the finding rather than burying it
    • Separated what was certain from what was suspected
    • Gave the person something to do about it, not just a problem
    • Held the position when it was pushed back on, or changed it for a reason they can state

    Red flagSoftened the message until the risk disappeared from it.

  4. You will handle client evidence and personal information. What does that change about how you work?

    Show what a strong answer coversHide answer

    A strong answer

    • Need to know - looks at what the ticket requires and not what is interesting
    • Knows client data does not go into personal tools, public sandboxes or a chatbot
    • Keeps a defensible record: what was collected, when, and by whom
    • Would rather be slow and correct on an evidence question than fast

    Red flagWould upload a client sample to a public scanner without thinking about who else can then read it.

  5. What have you taught yourself outside your degree, and how did you go about it?

    Show what a strong answer coversHide answer

    A strong answer

    • Names something specific and can show it - a lab, a room, a write-up, a rule they wrote
    • Describes something they got wrong on the way
    • Chose it for a reason connected to the work
    • Keeps going after the novelty - a pattern of months, not a weekend

    Red flagLists platforms they have accounts on with nothing they can talk through.

Security and networking fundamentals

Calibration. Graduates are not expected to nail every one - listen to how they reason when they do not know.

  1. A user clicks a link in a phishing email. Walk me through what happens, and what you would want to check.

    Show what a strong answer coversHide answer

    A strong answer

    • Follows the chain: DNS lookup, redirects, the page that finally loads
    • Separates a credential harvesting page from a payload download - the response is different
    • Wants to know whether credentials were entered and whether an MFA prompt was approved
    • Checks sign-in logs, endpoint telemetry and who else received the same message

    Red flagStops at 'they get a virus'.

  2. Why is multi-factor authentication not a complete answer to phishing?

    Show what a strong answer coversHide answer

    A strong answer

    • Knows a proxy in the middle can capture the code and the session token in real time
    • Understands a stolen session cookie skips authentication entirely
    • Mentions push fatigue - approving a prompt to make it stop
    • Knows the stronger answer is phishing-resistant factors: passkeys, FIDO2, certificate-based

    Red flagTreats MFA as binary protection and cannot describe a way past it.

  3. A firewall log shows a workstation connecting to the same external IP every 60 seconds, around the clock. What do you think, and what do you check?

    Show what a strong answer coversHide answer

    A strong answer

    • Says beaconing out loud and knows it can be malware or an ordinary agent
    • Wants the process and the parent process making the connection, not just the IP
    • Checks reputation, certificate and whether other hosts do the same thing
    • Notes that regular timing with small jitter is more suspicious than pure regularity

    Red flagBlocks the IP and closes the ticket without finding out what was talking to it.

  4. What is least privilege, and why do local administrator rights matter so much?

    Show what a strong answer coversHide answer

    A strong answer

    • Admin turns one compromised user into a foothold with the run of the machine
    • Connects it to credential theft, disabling tooling and lateral movement
    • Knows removing admin is one of the highest-value controls and one of the most resisted
    • Suggests a workable middle - just-in-time elevation, a break-glass account that is monitored

    Red flagRecites the definition with no idea why anyone would push back on it.

  5. Vulnerability, exploit, threat, risk. What is the difference, and why does a CVSS of 9.8 not always mean drop everything?

    Show what a strong answer coversHide answer

    A strong answer

    • Gets the four straight without hedging
    • Knows severity is not risk until you add exposure, exploitability and what the asset does
    • Asks whether it is internet-facing, whether a patch exists, and whether it is being exploited in the wild
    • Mentions known-exploited lists or threat intel as the practical tiebreaker

    Red flagSorts by CVSS score and calls that a prioritisation.

  6. Hashing and encryption - what is the difference, and which one belongs on a stored password?

    Show what a strong answer coversHide answer

    A strong answer

    • Hashing is one way, encryption is reversible with a key
    • Passwords are hashed with a slow, salted algorithm - bcrypt, scrypt, Argon2
    • Knows a salt defeats precomputed tables and that speed is the enemy here
    • Bonus: can say why a fast hash like SHA-256 on its own is the wrong choice

    Red flagSays passwords should be encrypted and sees no problem with it.

Detection, triage and response depth

The 60-minute technical interview. Expect follow-ups that go one step past what they know.

  1. An alert fires: impossible travel, a sign-in from Sydney and one from Manila twenty minutes apart. How do you triage it?

    Show what a strong answer coversHide answer

    A strong answer

    • Knows the detection is noisy and that a VPN or a mail client explains most of them
    • Checks the device, the user agent, whether MFA was actually satisfied and by what method
    • Looks for what happened after the sign-in - inbox rules, forwarding, file access, new registrations
    • Confirms with the user or the client rather than guessing at intent

    Red flagCloses it as a false positive because the user says they were travelling, and checks nothing else.

  2. What is MITRE ATT&CK for, and how would you use it on a real ticket?

    Show what a strong answer coversHide answer

    A strong answer

    • A shared vocabulary for what an attacker did, so two analysts describe it the same way
    • Uses it to ask what usually comes next after the technique in front of them
    • Knows it maps detection coverage and shows the gaps
    • Does not treat the matrix as a checklist to be completed

    Red flagCan name the tactics in order and cannot apply one to the ticket on the screen.

  3. A client reports a phishing email that reached forty staff. What happens in the first fifteen minutes, and in what order?

    Show what a strong answer coversHide answer

    A strong answer

    • Contains first - block the sender and URL, pull the message from mailboxes
    • Scopes second - who received it, who opened it, who entered credentials
    • Responds to confirmed credential entry: reset, revoke active sessions, check for inbox rules
    • Communicates to the client early with what is known and what is still being checked

    Red flagStarts writing the report before anything has been contained.

  4. What is the Essential Eight, and if a client could only fund three of the mitigations this year, which would you argue for?

    Show what a strong answer coversHide answer

    A strong answer

    • Can name most of the eight and knows they come with maturity levels rather than a pass or fail
    • Argues from what the client actually faces, not from the order of the list
    • Patching, multi-factor authentication and restricting administrative privileges are a defensible three
    • Mentions backups as the one that decides how bad a ransomware day gets

    Red flagRecites the eight and cannot rank any of them or say why.

  5. A detection fires sixty times a day and every single one has been benign. What do you do?

    Show what a strong answer coversHide answer

    A strong answer

    • Finds out what the rule is actually matching before touching it
    • Tunes narrowly - this process, this path, this account - rather than switching the rule off
    • Measures the alert volume before and after, and records what was excluded and why
    • Knows a rule nobody reads is worse than no rule, because it looks like coverage

    Red flagWould disable it, or would leave it alone because 'it might catch something one day'.

  6. You have removed malware from a laptop. How do you know the machine is actually clean?

    Show what a strong answer coversHide answer

    A strong answer

    • Honest that reimaging is usually the defensible answer, and says why
    • Knows persistence hides in scheduled tasks, run keys, services and startup items
    • Treats any credential used on that machine as exposed until it is reset
    • Wants the root cause - how it arrived - or it happens again next week

    Red flagTrusts a clean scan result and hands the laptop straight back.

Incident scenario

Read it aloud and let them drive. Give information only when they ask for it.

  1. It is 4:20pm on a Friday. A client's finance manager calls: twenty minutes ago they approved an MFA prompt they did not trigger. What do you do?

    Show what a strong answer coversHide answer

    A strong answer

    • Treats it as live until proven otherwise rather than waiting for an alert to confirm it
    • Gets the account, the time and whether anything looked different, in a couple of minutes
    • Moves to revoke sessions and reset credentials rather than investigating first at leisure
    • Starts a timeline immediately, because everything after this depends on it

    Red flagBooks it in for Monday, or asks the user to change their password and leaves it there.

  2. Sign-in logs show a successful login from an unfamiliar IP, and a new inbox rule that moves anything containing 'invoice' to a folder nobody reads. What now, and who do you tell?

    Show what a strong answer coversHide answer

    A strong answer

    • Recognises the pattern as business email compromise heading for payment fraud
    • Removes the rule, revokes sessions, and checks sent items and any mail already forwarded
    • Escalates to Tier 2 and tells the client's nominated contact immediately, not at the end
    • Checks whether any invoice or bank detail change has already gone out

    Red flagDeletes the rule and moves on without looking at what was sent.

  3. The client asks whether they have to report this to anyone. What do you say?

    Show what a strong answer coversHide answer

    A strong answer

    • Knows there may be an obligation under the notifiable data breach scheme if personal information is involved and serious harm is likely
    • Knows an assessment has a deadline attached and that the clock has already started
    • Mentions ReportCyber and the client's own regulator or insurer where relevant
    • Is clear that the decision is the client's, made with their privacy officer or lawyer, and puts the facts in front of them

    Red flagGives a confident legal answer, in either direction, on their own authority.

  4. It is 6pm and the client wants something in writing tonight. What goes in it?

    Show what a strong answer coversHide answer

    A strong answer

    • What happened, in plain English, with a timeline in local time
    • Separates confirmed from suspected, and says what is still unknown
    • What has been done already and what the client must do now, as instructions
    • Who to call over the weekend, and when the next update lands

    Red flagSends the raw ticket, or writes three paragraphs of speculation stated as fact.

Questions to ask them

Bring three. Interviewers remember the candidate who asked something they had to think about.

  • How many tickets does a Tier 1 analyst close in a shift here, and who reviews them?
  • How much of your detection content is written in house versus vendor defaults?
  • What does the path out of Tier 1 look like, and how long does it usually take in practice?
  • When did the SOC last miss something, and what changed afterwards?
  • What happens when a client will not act on what you tell them?

Example CV · fictional candidate

Aisha Rahman

Written to the job description on the previous tab. Notes on the right explain each choice.

Aisha Rahman

Graduate Cyber Security Analyst

Canberra ACT · 0400 000 000 · a.rahman@example.com · github.com/aisharahman · linkedin.com/in/aisha-rahman

Professional summary

Cyber security graduate with a twelve-week SOC internship, a home detection lab where I run the attack and then hunt it in my own SIEM, and a habit of writing up what I find. Comfortable taking an alert from queue to closure and explaining it to someone non-technical. Australian citizen, eligible for a Baseline clearance.

Technical skills
Security tooling
Microsoft Sentinel, Wazuh, Splunk (free tier), Defender for Endpoint (lab), Nessus Essentials, Burp Suite Community
Detection and analysis
KQL, Sigma rules, MITRE ATT&CK mapping, Wireshark, email header and URL analysis
Scripting
Python, PowerShell, bash (all working level, not polished)
Systems
Windows Server and Active Directory, Ubuntu, pfSense, Proxmox
Frameworks
Essential Eight, ISM familiarity, NIST CSF basics
Ways of working
Ticket hygiene, incident write-ups, peer review of closed tickets
Education
Bachelor of Cyber Security
Feb 2023 - Nov 2026

University of Canberra

  • GPA 6.0 / 7. Distinction average across security units
  • Relevant units: Network Security (7), Digital Forensics (7), Incident Response (6), Systems Administration (6), Cryptography (6)
  • Capstone: built an attack and detection lab and wrote twelve Sigma rules against it. See Projects below
Experience
Security Operations Intern (Tier 1, supervised)
Nov 2025 - Feb 2026 (12-week vacation program)

Saltbush Managed Services, Canberra

  • Triaged around 40 Tier 1 alerts a week, every one reviewed by a Tier 2 analyst before closure
  • Investigated and wrote up six phishing campaigns, including one where credentials were entered and sessions had to be revoked
  • Proposed two scoped exclusions that took a chronically noisy detection from 60 alerts a day to 4, with no known misses in the following six weeks
  • Rewrote the phishing triage playbook after finding two steps in it that no longer matched the tooling
IT Service Desk Officer (casual, 15 hrs/week)
Mar 2024 - present

University of Canberra, IT Services

  • First-line support for around 600 staff and students - accounts, MFA enrolment, device setup
  • Spotted and escalated a credential phishing wave from three near-identical tickets, with samples attached
  • Wrote the MFA troubleshooting article that is now the most-viewed page in the internal knowledge base
Duty Manager
Feb 2022 - Feb 2024

Capital Cinemas, Canberra

  • Ran evening shifts of up to nine staff while studying full time
  • Handled cash reconciliation, incident reports and the occasional genuinely difficult customer
Projects
Detection lab - build the attack, then catch it
Proxmox, Windows Server 2022, Active Directory, Sysmon, Wazuh, Atomic Red Team
  • Two-domain lab where I execute ATT&CK techniques and then write detections for them
  • Twelve Sigma rules published with the false positives each one produced in my own environment, which is the part most repositories leave out
  • github.com/aisharahman/detection-lab
Phish-report - reported email triage helper
Python, Microsoft Graph API, VirusTotal API
  • Parses a reported email, extracts headers, URLs and attachment hashes, and produces a one-page summary for the analyst
  • Cut my own average triage time during the internship from about 12 minutes to about 4
  • Deliberately does not auto-close anything - it gathers, a human decides
BSides Canberra CTF 2025
Team event, 60 teams
  • Placed 9th. Wrote up the two forensics challenges I solved, including the one that took me four hours and should have taken forty minutes
Leadership and activities
  • Vice-President, UC Cyber Security Club, 2025 - 2026. Ran a weekly hands-on session; attendance went from 8 to 30
  • Volunteer, BSides Canberra 2025 - registration desk and speaker wrangling
  • Mentor, high school Cyber Explorers day, 2025
Certifications
  • CompTIA Security+ (SY0-701), January 2026
  • Microsoft SC-900: Security, Compliance and Identity Fundamentals, August 2025
  • TryHackMe SOC Level 1 pathway completed, 2025
Referees

Available on request.