A hands-on Senior Cyber Security Engineer in Sydney who designs threat detections across SIEM, EDR and XDR platforms, runs threat hunting, and builds SOAR automation in partnership with SOC, Incident Response and Threat Intelligence teams.
We are seeking an experienced Senior Cyber Security Engineer to enhance and mature enterprise cyber detection capabilities. This hands-on role focuses on developing high-quality detections, improving security monitoring, conducting threat hunting activities and strengthening the organisation's ability to identify and respond to cyber threats.
Working closely with SOC, Incident Response and Threat Intelligence teams, you will play a key role in improving security visibility and reducing cyber risk across the enterprise.
Key Responsibilities
Design and develop threat detections across SIEM, EDR and XDR platforms.
Create detection use cases aligned to adversary TTPs and the MITRE ATT&CK framework.
Conduct threat hunting activities to identify emerging threats and detection gaps.
Translate threat intelligence into actionable detection content.
Tune and optimise detection rules to improve accuracy and reduce false positives.
Partner with Incident Response teams to develop detections from real-world incidents.
Perform detection validation through attack simulation and testing activities.
Implement automation and SOAR capabilities to improve security operations efficiency.
Identify monitoring gaps and improve visibility across cloud, endpoint, identity and network environments.
Develop reporting and metrics to measure detection effectiveness and SOC maturity.
Required Experience
Strong experience in Detection Engineering, Security Operations or Security Analytics.
Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar or Elastic.
Experience developing detection rules, correlation logic and behavioural analytics.
Strong understanding of MITRE ATT&CK and modern attack techniques.
Experience with EDR/XDR platforms and threat hunting methodologies.
Scripting experience using Python, PowerShell, KQL or similar technologies.
Experience leveraging threat intelligence to improve monitoring and detections.
Strong analytical, investigative and problem-solving skills.