Cyber Detection Engineer
Quick Overview
Job Description
Melbourne Contract Opportunity Enterprise Cyber Security Transformation
We're partnering with a leading enterprise organisation undertaking a significant cyber security transformation and are looking for an experienced Detection Engineer to play a critical role in delivering a modern Unified SIEM capability.
This is a hands on technical position where you'll design, build and optimise detection use cases that strengthen cyber resilience, improve SOC capability and enhance threat detection across cloud and on premise environments. Working alongside Threat Engineering, Security Engineering and SOC teams, you'll help build a scalable, intelligence driven detection capability that enables faster identification and response to evolving cyber threats.
Responsibilities- Design, develop and maintain high quality detection use cases aligned to threat intelligence, MITRE ATT&CK and business risk priorities.
- Build, tune and optimise SIEM analytics, alerting logic and correlation rules.
- Improve detection quality by reducing false positives and increasing detection fidelity.
- Apply Detection as Code principles using version control and structured deployment processes.
- Support the delivery of a large scale Unified SIEM transformation, including migration and consolidation activities.
- Onboard, normalise and optimise log sources across cloud, endpoint, identity and network platforms.
- Translate threat intelligence, red/purple team findings and incident learnings into actionable detection content.
- Develop detections targeting identity attacks, endpoint compromise, malware, network threats and cloud native attack techniques.
- Partner with SOC teams to validate detections, tune alerts and develop operational playbooks.
- Assess logging requirements, identify telemetry gaps and improve overall detection coverage.
- 5+ years' experience in Detection Engineering, SIEM Engineering or advanced SOC Analytics.
- Experience delivering SIEM transformation, migration or uplift programmes.
- Strong experience with enterprise SIEM platforms such as Microsoft Sentinel, Splunk, Elastic or IBM QRadar.
- Strong query development skills using KQL, SPL and/or SQL.
- Excellent understanding of the MITRE ATT&CK Framework and modern threat detection methodologies.
- Experience analysing and correlating logs across Identity and Active Directory, endpoint security platforms, network infrastructure, Azure, AWS and Microsoft 365.
- Experience detecting identity compromise, lateral movement, malware and endpoint attacks, network based threats, cloud attacks and privilege escalation.
- Strong analytical and investigation skills with the ability to identify patterns across multiple data sources.
- Competitive contract rates with a long term programme of work.
- Opportunity to drive Detection as Code, automation and continuous improvement initiatives.
- Work with modern SIEM technologies and advanced detection engineering practices.
- Influence how cyber threats are detected across a large and complex environment.
- Collaborate with highly skilled SOC, Threat Intelligence and Security Engineering teams.
Skills
Similar jobs
Sr. Cyber/Cloud Security Specialist_Mostly Remote
Apolis · Washington, United States
21 minutes agoCyber Security Analyst 1 with Security Clearance
Keaki Technologies · Hanalei, United States
22 minutes agoFire & Security Service Engineer
Amida Consulting Solutions Ltd · Bristol, United Kingdom
50 minutes agoCyber Security Engineer
iDPP · Reading, United Kingdom
52 minutes agoSecurity Engineer
Vallum Associates Limited · Sheffield, United Kingdom
52 minutes agoAI Cyber Engineer £120k
Circle Group · Milton Keynes, United Kingdom
59 minutes ago£120k/yr