Haystack
← Back to Jobs
Full time
Technology

Principal Security Engineer Cyber Advisor (LH-07235)

InterproCanberra, Australian Capital Territory🇦🇺AustraliaPosted 19 Jul 2026

Quick Overview

Work Type
Hybrid
Schedule
Full Time
Level
Leader

Job Description

About the organisation

Join a leading Australian Government agency responsible for protecting Australia's national interests through advanced law enforcement, cyber security, and intelligence capabilities. The organisation delivers critical technology services that support national security, operational policing, and enterprise ICT transformation in a highly secure environment.

About the team

You'll join a specialist Cyber Security team responsible for strengthening the organisation's Security Operations Centre (SOC) capabilities and enterprise cyber defence platforms. The team designs, implements, and continuously improves security monitoring, detection engineering, incident response automation, and threat detection capabilities across complex cloud and on-premises environments.

What you'll do

As a Principal Security Engineer / Cyber Advisor, you will lead the implementation and optimisation of enterprise SIEM and SOAR capabilities while improving cyber detection, automation, and response across the organisation.

Your responsibilities will include:

  • Designing and implementing onboarding of security log sources across cloud, endpoint, identity, network, and on premises platforms
  • Developing and maintaining SIEM parsing, normalisation, and log quality standards
  • Building and enhancing SOAR workflows to automate alert triage, enrichment, containment, and response
  • Integrating SIEM/SOAR platforms with EDR, IAM, firewalls, email security, ticketing systems, and threat intelligence platforms
  • Developing, tuning, and maintaining high quality detection rules aligned with MITRE ATT&CK and organisational threats
  • Creating SOC playbooks, operational runbooks, and automated response workflows
  • Reducing false positives and improving alert quality through continuous optimisation
  • Supporting cyber incident response through log analysis, threat detection, and rapid rule development
  • Performing detection gap analysis following incidents and emerging threat intelligence
  • Monitoring SIEM/SOAR platform performance, reliability, and health
  • Developing dashboards, reporting metrics, and operational documentation
  • Mentoring team members and contributing to continuous improvement of cyber security practices
Must-have skills
  • Extensive hands on experience implementing and administering enterprise SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, Microsoft Defender, or Elastic
  • Strong experience developing SIEM detection rules, correlation logic, parsers, dashboards, and complex security queries
  • Experience designing and implementing SOAR automation and security orchestration workflows
  • Strong understanding of Security Operations Centre (SOC) processes and incident response
  • Experience integrating SIEM/SOAR with security technologies including EDR, IAM, firewalls, email security, ticketing platforms, and threat intelligence solutions
  • Experience improving detection capability, reducing false positives, and optimising alert quality
  • Strong knowledge of cyber security monitoring, threat detection, and detection engineering
  • Excellent documentation, stakeholder engagement, and mentoring skills
Nice-to-have skills
  • Experience working within highly secure Government or regulated enterprise environments
  • Knowledge of the MITRE ATT&CK framework and detection engineering best practices
  • Experience defining SOC performance metrics such as MTTD, MTTR, automation coverage, and detection effectiveness
  • Experience with cloud security monitoring across Microsoft Azure and hybrid environments
  • Experience leading technical security initiatives and mentoring cyber security teams

This is an excellent opportunity to work on enterprise scale cyber security platforms supporting nationally significant systems while contributing to the continuous improvement of advanced security operations and threat detection capabilities.

If you're interested in applying, please submit your application today. The role closes on 29/07/2026 before 12:00 pm, don't miss out!

Feel free to reach out to me for a confidential chat about the role.

Skills

Splunk
Azure

Similar jobs