Haystack
← Back to Jobs
Full time
Other
PG

SOC Detection Specialist

Powerdata Group ConsultingCanberra, Australian Capital Territory🇦🇺AustraliaPosted 6 Oct 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Canberra, Australian Capital Territory, Australia
OWASPSplunkAgileAzureBashLLMPython

Job Description

Location: Canberra, Australian Capital Territory (ACT) (remote considered)

Security Clearance: Baseline Clearance

Threat Detection Engineering
  • SIEM use case development and detection content creation
  • Detection rule development and tuning
  • SOAR playbook development
  • STRIDE
  • MITRE ATT&CK
  • Attack path analysis
  • Detection coverage assessment
  • Gap analysis
  • Threat intelligence integration and management
  • Research into emerging threats
  • Intelligence sharing across infrastructure and architecture teams
Security Operations
  • SOC operations
  • ITIL and Agile environments
AI Security (Important New Requirement)

The RFQ specifically calls for experience in:

  • AI threat modelling
  • AI-related data leakage monitoring
  • Adversarial AI activity detection
  • Security monitoring of AI platforms, services and agents

A strong candidate would typically have:

  • 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations
Hands-on experience with platforms such as:
  • Microsoft Sentinel
  • Splunk
  • QRadar
  • CrowdStrike
  • Strong understanding of MITRE ATT&CK
  • Experience integrating threat intelligence feeds
  • Good documentation and stakeholder engagement skills
Evaluation Themes to Address in a Submission

When preparing a candidate response, focus on evidence demonstrating:

  • Development of threat detection use cases and rules.
  • SIEM/EDR content engineering and tuning.
  • Threat modelling expertise using STRIDE and ATT&CK.
  • Threat intelligence integration and analysis.
  • Experience supporting incident response activities.
  • Security monitoring of cloud and on-premises environments.
  • AI security and emerging threat detection capabilities.
  • Working within Agile and ITIL environments.
Requirements

1. Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).

2. Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.

3. Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.

4. AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.

5. Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.

1. Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.

2. Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.

3. EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.

4. Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.

Similar jobs