Investigate and coordinate containment of security incidents to protect BNZ systems and data.

About the Role

Here at BNZ, it's about more than just banking. We work together in an agile, energising environment to create innovative solutions through our promise "If you can imagine a better future, let's find a way."

We support wellbeing, flexible working and have a generous leave offering. There is the opportunity for growth, learning and career development. No two days are the same.

At the heart of BNZ's digital resilience is our cyber team – a passionate, high performing group of experts who protect our systems, data, and people from evolving cyber threats. Be part of one. In our Cyber Defence function, we combine cutting-edge technology with deep expertise to defend against real-world attacks, ensuring the trust of our customers and integrity of our operations.

You'll collaborate across security operations, threat intelligence, incident response, and security engineering contributing to a culture of vigilance, innovation and continuous improvement.

If you're driven by purpose, thrive in high-stakes situations, and want to work alongside some of the best minds in cyber security – this is the team for you.

This role can be based in Auckland or Wellington. It is a hybrid role with three days in the office – Monday, Tuesday and Thursday – and two days with the option to work flexibly.

Team Culture and Environment

The Cyber Defence team operates in a collaborative, supportive, and fast‑paced environment where people work closely together to protect the bank. The team values teamwork, continuous learning, and open communication. There is a strong focus on supporting one another during incidents and sharing knowledge to collectively improve outcomes, while maintaining a calm and disciplined approach during high‑pressure situations.

Daily Tasks

  • Monitor and triage security alerts across SIEM, EDR and other security tooling, identifying potential threats and prioritising events for investigation.
  • Design, build and maintain detection use cases across SIEM, EDR and relevant cloud telemetry to improve signal quality and coverage.
  • Support incident response activities, including investigation, containment, evidence collection and documentation, following established playbooks and procedures.
  • Analyse security telemetry such as logs, network traffic and endpoint activity to identify malicious behaviour or indicators of compromise.
  • Engage with internal teams (e.g. technology, engineering, risk) during incidents to support remediation and recovery activities.
  • Continuously learn and uplift capability, including improving investigation techniques and using AI‑enabled security tooling to support alert triage and analysis.

Exciting Opportunity

You will be working on real cyber security incidents that matter, helping protect the bank, its customers, and its information. The role offers the opportunity to learn from experienced cyber defence specialists, work with modern security tooling (including AI‑enabled capabilities), and build a strong foundation across SOC operations and incident response in a highly regulated, meaningful environment.

Attributes for Success

A successful Specialist will be curious, analytical, and reliable. They will be comfortable working in a Cyber Defence environment, following processes, and remaining calm under pressure. They will show a strong willingness to learn, good attention to detail, and a collaborative mindset. Clear communication, accountability, and an interest in using modern and AI‑assisted security tools to improve efficiency and outcomes will be key to their success. This is a crucial role in uncovering attack methodologies, identifying root causes, and strengthening BNZs cyber resilience. Capable of responding to cyber incidents across the BNZ environment.

Technical Skills Required

  • Experience in Cyber Defence operations and/or incident response in an enterprise environment.
  • Expertise with SIEM and EDR platforms, including detection logic, alert tuning and telemetry analysis.
  • Working knowledge of incident response fundamentals, including containment, eradication and recovery concepts.
  • Ability to analyse logs, alerts, and basic network or endpoint artefacts.
  • Familiarity with common threat types and attack techniques; MITRE ATT&CK awareness is beneficial.
  • Interest in leveraging AI‑assisted security tools responsibly to improve investigation efficiency and decision‑making.

Closing Date: 13 August 2026

Applications will be reviewed regularly across the advertising period, but we do reserve the right to close applications early.