Queensland Government

Cyber security analyst

Who might be attracted to this role?

Those with a love for technology and an innate ability to quickly grasp and apply new technical concepts. Detail-oriented and methodical thinkers with strong problem-solving abilities and a proactive mindset. Those who thrive on being hands-on with technology and staying at the forefront of the cyber security field.

Entry points

  • Digital roles: IT service centres, Network engineer, Cyber security research, IT operations, Server Support Technician, Security administration.
  • Non digital roles: Contract management, IT Auditor, Risk and Compliance Officer, Incident manager, Business Analyst.

SFIA behaviours

  • Problem solving: curiosity and ability to take on attacker mindset; able to quickly assess issues and determine effective mitigation strategies.
  • Security, privacy and ethics: a strong understanding and commitment to security, privacy, and ethics are crucial.
  • Communication: effective communication to business staff and with other teams is essential to ensure security measures are implemented effectively.
  • Adaptability: ready to handle new types of cyber incidents, and update practices according to emerging threats and technologies.

Transition points

Possible next steps include:

  • Cyber security leader
  • Security Consultant
  • Cyber security researcher
  • Incident responder
  • Penetration tester
  • Security architect.

Proficiency level

Also see related Cyber security analyst role profile.

Career story

Cyber security analyst – Foundation

Felix, Queensland Government

Tell me about your career journey up to your current role. How did you get started in your role?

I started out in the Queensland Government with a Graduate role, as part of the Queensland Government Digital Graduate Program, which enabled me to gain skills in a Security Operations Centre, which enabled me to get my current role.

What attracted you to your current role?

Conducting Digital Forensics and Incident Response investigations using the latest best practice techniques is what lead to me pursuing a Security Administrator role.

In this role, there is always something new to learn in this role and other professionals are always willing to share their knowledge and skills.

What were the key skills and job experiences from your previous career or role that helped you transition to your current role?

I had previous experience working in multi-disciplinary IT teams to achieve a common objective. I also have previous experience in IT customer support roles, which is beneficial when communicating with a variety of stakeholder

Were there any specific learning and development courses or certifications that were helpful for you to make the switch or enter this role?

  • Bachelor’s degree in Computer Science, majoring in Cyber Security
  • Cisco CCNA and CCNP for networks

What key behavioural skills are most important for this role profile?

  • Problem solving
  • Communication
  • Adaptability
  • Privacy and ethics

What key professional skills are most important?

  • Information Security (SCTY)
  • Security Operations (SCAD)
  • Digital forensics (DGFS)
  • Incident management (USUP)
  • Vulnerability assessment (VUAS)

Can you walk me through a typical day or week in your current role?

My typical workday can come in two forms:

  • Reactive, where I detect, triage, and respond to cyber security events in line with internal protocols. During this workday, I work with all stakeholders across the Queensland Government.
  • Proactive, where I undertake tasks or projects to uplift our triage and response capabilities. An example of a proactive task is hunting for emerging threats.

A challenge that I often face in my role is determining where to focus proactive efforts in a continuously evolving threat landscape.

An aspect of my role that I find rewarding is knowing that my work is helping the Queensland Government to keep Queenslander’s data safe.

What advice would you give to someone wanting to get started in or transition to a role that you are in?

Be open minded about the skills and career pathway, as cyber security is a large field, and you don’t need to go down a specific path at the start.

Having a solid grasp of IT and networking fundamentals is a must for this role, this will prove beneficial when communicating with technical stakeholders.

Professional networking is a very important part of any career pathway, make sure to utilize professional contacts and their experience/expertise to help gain knowledge and skills.