A hands-on contract role in Sydney owning the organisation's Splunk SIEM: tuning and optimising the platform, building detection use cases, correlation rules and alerts, onboarding log sources, and supporting threat hunting, incident response and SOAR integration within a security operations team.
You'll take ownership of the SIEM environment, driving detection engineering, use case development, and log source onboarding to strengthen the organisation's security monitoring and incident response capability. This is a hands-on engineering role within a broader security operations function.
Key responsibilities
Administer, tune, and optimise the SIEM platform (Splunk) for performance and coverage
Develop and maintain detection use cases, correlation rules, and alerting logic
Onboard new log sources and ensure data quality and integrity across the environment
Support threat hunting, incident response, and security analytics initiatives
Integrate SIEM with SOAR and other security tooling where applicable
Partner with SOC analysts and the broader security team to continuously mature detection capability
Document use cases, playbooks, and operational procedures to a high standard
About you
Proven hands-on experience administering and engineering Splunk (or an equivalent SIEM platform)
Strong background in detection engineering, threat hunting, or SOC operations
Experience integrating SOAR and security automation highly regarded