Cyber Engineer
Fortescue
Our Opportunity
Work Location: Fortescue’s Perth office is located on the traditional lands of the Whadjuk Noongar people.
Roster: Monday to Friday
The Cyber Engineer - Security Operations plays a critical role in protecting the organisation from evolving cyber threats through the design, implementation, optimisation and operation of security controls. Reporting to the Superintendent of Cyber Security Operations, this role will be responsible for leading the operation, optimisation and continuous improvement of the organisation's email security capabilities, while supporting security monitoring, threat detection, incident response and broader Security Operations functions across the enterprise.
Working across Cyber Security, Infrastructure and Workplace Technology teams, you will contribute to the ongoing maturity of Fortescue’s security posture through the implementation of industry-leading email security controls, threat detection capabilities and human risk reduction initiatives. This is an opportunity to work in a fast-paced and evolving environment, helping to safeguard critical business operations while supporting Fortescue’s technology and decarbonisation ambitions.
Key Responsibilities
- Support the operation, optimisation and continuous improvement of enterprise security controls, with a primary focus on email security technologies and processes.
- Configure, maintain and enhance controls designed to protect against phishing, business email compromise, spoofing, malware and other email-borne threats.
- Drive the implementation and management of email authentication and domain protection technologies, including SPF, DKIM and DMARC.
- Contribute to initiatives that improve security awareness, reduce human cyber risk through the analysis of email threat trends, user behaviours and security control effectiveness.
- Monitor, investigate and respond to security alerts, events and incidents across enterprise environments, including participation in cyber incident response activities such as triage, containment, eradication, recovery and post-incident review.
- Conduct threat analysis and investigations to identify malicious activity, emerging threats and opportunities for security improvement.
- Develop and maintain security use cases, detection logic, operational procedures and technical documentation.
- Collaborate with Technology, Infrastructure, Digital Workplace and business stakeholders to implement and improve security controls.
- Support security monitoring, threat detection and response capabilities across cloud, endpoint, network and identity domains & contribute to security engineering initiatives, control uplift programs and the ongoing development of Security Operations roadmaps.
- Assist with security assessments, control reviews and continuous improvement activities to strengthen organisational cyber resilience.
- Identify opportunities and implement operational efficiency through the adoption of artificial intelligence capabilities, automation, orchestration and integration activities.
Qualifications and Experience
- Degree / Diploma / Certificate in Information Technology, Computer Science, Cyber Security, Engineering or a related discipline.
- Demonstrated experience in Security Operations, Security Engineering, Incident Response, Systems Administration, Infrastructure Engineering, or a related role with responsibility for implementing and supporting security controls. Strong understanding of email security principles, including email authentication standards, threat protection controls and email security operations.
- Experience investigating phishing, business email compromise and other cyber security threats.
- Knowledge of security monitoring, threat detection, alert triage and incident response processes.
- Experience working with security technologies across one or more domains, including email security, SIEM, endpoint, identity, cloud or network security.
- Experience developing or maintaining security controls, detection content, operational procedures and technical documentation.
- Familiarity with automation, orchestration, artificial intelligence capabilities and API-driven integrations to improve security operations outcomes.
- Understanding of cyber security frameworks, industry best practices and modern security architectures.
- Strong analytical, problem-solving and communication skills, with the ability to work effectively both independently and as part of a multidisciplinary team.
About Us
Be part of something big. Fortescue is leading the world with our plan to decarbonise our iron ore operations, projects that harness renewable energy and the development of technology that will change our planet forever.
Our Commitment
Fortescue celebrates individual strengths and team members are encouraged to bring their whole selves to work. Our global workforce drives and promotes an inclusive culture, both within our organisation and throughout the communities we interact with. Diverse backgrounds include First Nations Peoples, people with disabilities, LGBTQ+ community, gender, neurodiverse, cultural diversity, all age groups, and those with an intersectional or multiple diverse characteristics. We encourage candidates from all backgrounds to apply.
https://fortescue.com/careers
Internal Candidates / Current Contractors please apply via Success Factors Careers Portal. For further information on how to apply please visit the Fortescue Hub.
Fortescue reserves the right to close applications early should a suitable pool of candidates be identified. Fortescue will never contact you to ask for payment of any kind, whether directly or through a third party.