APS6 Senior Cyber Threat Analyst

Softtest pays pty ltd

Canberra

On-site

AUD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Softtest pays pty ltd is seeking a Threat Detection Engineer to develop detection content for SIEM/EDR and contribute to threat intelligence sharing across cloud and on-prem environments.

The role involves researching, developing, testing, and maintaining use cases, working in an ITIL and Agile environment, and collaborating with Cyber Defence Analysts to enhance detection capabilities.

Qualifications

  • Experience in threat detection engineering within security operations.
  • Familiarity with threat models and ATT&CK/STRIDE methodologies.
  • Experience applying ITIL and Agile practices in engineering teams.

Responsibilities

  • Develop detection use cases from threat models and incidents.
  • Create and tune detection rules for SIEM/EDR platforms.
  • Build playbooks for alert validation and response coordination.
  • Collaborate with architecture/engineering to translate threat models into monitoring.

Skills

Threat detection
SIEM
EDR
Threat intelligence
ITIL
Agile
Cross-team collaboration

Tools

SIEM
SOAR

Job description

Australian Citizens residing in Australia only respond.

Australian Citizens residing in Australia only respond.

Job details

Threat Detection Engineer develops and maintains the material required to detect threats and incidents across the SOC technology stack.

The Threat Detection Engineer (TDE) is responsible for the research, development, testing and maintenance of use case and detection rules. They are to co-ordinate with Cyber Defence Analysts in developing detection content for use in the SIEM, SOAR and EDR platforms.

As part of the detection engineering lifecycle the TDE is expected to work in an ITIL and Agile environment, developing process and engineering documentation. The TDE is also responsible for providing threat intelligence sharing to infrastructure and architecture teams in both Cloud and onpremise environments.

Key duties and responsibilities

This position is responsible for:

  • Develop use cases based off threat models, system risks, vulnerabilities, intelligence, incident reports and industry frameworks
  • Develop the detection rule syntax associated with use cases within the SIEM and EDR technologies
  • Develop playbooks for alert validation by understanding the context in which the detection rule is designed
  • Develop and maintain threat models using industry recognised methodologies such as STRIDE, ATT&CK and attack path analysis to identify detection opportunities and coverage gaps.
  • Assess emerging threats associated with Artificial Intelligence (AI) platforms, services and agents, and develop detection content to identify AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity.
  • Collaborate with architecture and engineering teams to ensure threat modelling outcomes are translated into effective monitoring, detection and response capabilities.
  • Maintain the threat intelligence integrations across the SOC technology stack
  • Conduct in-depth research and analysis for new detection content
  • Collaborate with Cyber Defence Analysts for detection rule tuning
  • Assist with threat model development to inform the detection engineering strategy
  • Assist in the identification of content shortfalls across the detection engineering practice
  • Assist with incident response at that direction of the incident manager
  • Assist in the onboarding of new data sources to meet requirements of use cases
  • Provide evaluation and feedback necessary for improving intelligence production and reporting
  • Provide support to designated exercises, planning activities, and time sensitive operations
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Emanate Technology • Canberra

On-site
AUD 90,000 - 130,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

e2 Cyber • Canberra

On-site
AUD 120,000 - 150,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka Technology Solutions Pty Ltd • Canberra

Hybrid
AUD 150,000 - 190,000
Senior Cyber Threat Analyst - SIEM
Senior Cyber Threat Analyst - SIEM

IT Alliance Australia • Canberra

Hybrid
AUD 110,000 - 160,000
Threat Detection Engineer
Threat Detection Engineer

Whizdom • Canberra

Hybrid
AUD 120,000 - 170,000
Hybrid working arrangements
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka • Canberra

Hybrid
AUD 120,000 - 160,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Informatech Pty Ltd • Canberra

On-site
AUD 120,000 - 180,000
PD allowance
Training leave
Client exposure
+1
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Client 1 • Canberra

Hybrid
AUD 140,000 - 190,000
Hybrid work arrangement
Cyber Security Threat Engineer
Cyber Security Threat Engineer

The Network • Canberra

On-site
AUD 120,000 - 160,000
Cyber Security Threat Engineer
Cyber Security Threat Engineer

The Network Technology Recruitment • Canberra

On-site
AUD 140,000 - 170,000