Cyber Security Engineer - Detection Engineering (Microsoft Sentinel)

Pathway Search LLC.

North Sydney Council

Hybrid

AUD 144,000 - 176,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid working
Onsite three days a week

Job summary

Pathway Search LLC is seeking a Cyber Security Engineer for Detection Engineering (Microsoft Sentinel) in North Sydney. The role focuses on building and owning Microsoft Sentinel and Defender detection capabilities, not SOC triage, with collaboration across a managed SOC provider.

You will design analytics rules, write KQL queries, and improve coverage while reducing false positives across the security stack. Hybrid work with three days onsite. Australian work eligibility required.

Qualifications

  • Hands-on experience building and tuning Sentinel analytics rules and Defender detections.
  • Strong working knowledge of KQL and threat hunting techniques.
  • Solid understanding of Windows log sources and telemetry routing to SIEM.

Responsibilities

  • Design, build and tune Microsoft Sentinel analytics rules and Defender detections.
  • Write and maintain KQL queries for threat hunting and detection logic.
  • Improve platform coverage and reduce false positives across the Microsoft security stack.
  • Collaborate with the managed SOC provider and own the detection logic they operate against.

Skills

Sentinel analytics
KQL
Defender detections
Windows logs
SOC collaboration

Tools

Microsoft Sentinel

Job description

Cyber Security Engineer - Detection Engineering (Microsoft Sentinel)

Our client is one of Australia's largest private operators in critical infrastructure, based in North Sydney. They're growing out their internal security function and looking for a Cyber Security Engineer to build and own their Microsoft Sentinel and Defender detection capability.

This is an engineering role, not a SOC or triage position. The organisation runs a managed SOC for alert monitoring and response, so this role sits above that, writing and tuning detection logic, developing analytical rules, and improving platform coverage across Sentinel and Defender.

What You'll Do
  • Design, build and tune Microsoft Sentinel analytics rules and Defender custom detections
  • Write and maintain KQL queries for threat hunting, log coverage analysis and detection logic
  • Improve platform coverage and reduce false positives across the Microsoft security stack
  • Work closely with the managed SOC provider, owning the detection logic they operate against
  • Translate purple team and red team findings into new or tuned detections
  • Communicate detection and risk findings to internal technical stakeholders
About the Role

Our client is one of Australia's largest private operators in critical infrastructure, based in North Sydney. They're growing out their internal security function and looking for a Cyber Security Engineer to build and own their Microsoft Sentinel and Defender detection capability.

This is an engineering role, not a SOC or triage position. The organisation runs a managed SOC for alert monitoring and response, so this role sits above that, writing and tuning detection logic, developing analytical rules, and improving platform coverage across Sentinel and Defender.

What You'll Do
  • Design, build and tune Microsoft Sentinel analytics rules and Defender custom detections
  • Write and maintain KQL queries for threat hunting, log coverage analysis and detection logic
  • Improve platform coverage and reduce false positives across the Microsoft security stack
  • Work closely with the managed SOC provider, owning the detection logic they operate against
  • Translate purple team and red team findings into new or tuned detections
  • Communicate detection and risk findings to internal technical stakeholders
What We're Looking For
  • Hands-on experience building and tuning Sentinel analytics rules and/or Defender detections, not just responding to alerts
  • Strong working knowledge of KQL
  • Solid understanding of Windows log sources and how security telemetry actually reaches a SIEM
  • Comfortable working directly with a managed SOC provider rather than running triage yourself
  • Australian citizens or permanent residents only. We are unable to offer visa sponsorship for this role
  • Based in Sydney and able to work onsite three days a week
What's on Offer
  • $160,000 base + superannuation + 20% performance-linked STIP
  • Hybrid working, three days a week onsite in North Sydney
  • The chance to build detection capability from the ground up at a genuine critical infrastructure operator
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Microsoft Sentinel Detection Engineer (Hybrid)
Microsoft Sentinel Detection Engineer (Hybrid)

Pathway Search LLC. • North Sydney Council

Hybrid
AUD 144,000 - 176,000
Hybrid working
Onsite three days a week
Senior Cyber Detection Engineer
Senior Cyber Detection Engineer

LT Harper Group • Sydney

On-site
AUD 160,000 - 180,000
Hybrid work
2 days from home
Microsoft Sentinel Security Consultant - Contract
Microsoft Sentinel Security Consultant - Contract

The Missing Link • Perth

Hybrid
AUD 130,000 - 190,000
Flexible working
Training & certification support
Security Engineer (SIEM)
Security Engineer (SIEM)

Client 1 • City of Brisbane

Hybrid
AUD 140,000 - 180,000
Private health insurance
Generous annual leave entitlements
Annual incentive programme
+5
Senior Threat Detection Engineer – Splunk / Sentinel / MDE
Senior Threat Detection Engineer – Splunk / Sentinel / MDE

Hatchit Studios • Canberra

Hybrid
AUD 120,000 - 190,000
Cyber Security Engineer
Cyber Security Engineer

Whizdom • Sydney

On-site
AUD 168,000 - 220,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Informatech Pty Ltd • Australian Capital Territory

On-site
AUD 120,000 - 180,000
PD allowance
Training leave
Client exposure
+1
Threat Detection Engineer
Threat Detection Engineer

Whizdom • Canberra

Hybrid
AUD 120,000 - 170,000
Hybrid working arrangements
Hybrid Detection Engineer: SIEM Expert (Sentinel, Splunk)
Hybrid Detection Engineer: SIEM Expert (Sentinel, Splunk)

Orro Pty Ltd • Sydney

Hybrid
AUD 120,000 - 165,000
Public holiday swaps and flexible work
Paid volunteer leave (3 days/year)
Novated leasing
+3
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement