Cyber Security Operations Analyst (SIEM / Detection Engineering)

Countersight

Canberra

On-site

AUD 100,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Countersight is a Canberra-based cybersecurity specialist delivering security research, capability development and consulting. We seek a Senior Cyber Security Operations Analyst (SIEM / Detection Engineering) to work hands-on with SIEM tooling, onboarding logs, tuning content, and optimising platform performance across client environments.

The role focuses on hands-on SIEM engineering, detecting events, and collaborating with client SOC teams to improve telemetry, data quality and detection

Qualifications

  • 3+ years’ hands-on experience in SIEM engineering, SOC operations, or cyber security operations roles.
  • Strong experience onboarding, parsing, normalising, and structuring logs from diverse sources.
  • Experience designing, building, and maintaining SIEM content including correlation rules, dashboards, reports, alerts and detection logic.
  • Experience monitoring and managing log ingestion, data quality, and platform performance.
  • Ability to analyse ingestion trends and identify optimisation opportunities.
  • Strong stakeholder engagement and communication skills.
  • Australian Government security clearance (NV1 minimum) or the ability to maintain one.

Responsibilities

  • Monitoring and maintaining SIEM platform health, ensuring availability and fitness for use by SOC analysts
  • Onboarding and integrating log sources across network, endpoint, cloud and application environments
  • Improving log fidelity, structure, and consistency to maximise detection effectiveness
  • Monitoring and analysing log ingestion rates and trends
  • Identifying and implementing optimisation opportunities to improve performance and reduce storage/ingestion costs
  • Developing and tuning correlation rules, alerts, dashboards and reports to reduce false positives and improve detection coverage
  • Maintaining and enhancing SIEM integrations, including threat intelligence feeds and API‑based connections
  • Supporting incident response and remediation activities in collaboration with SOC teams
  • Developing and maintaining standard operating procedures for cyber security tooling
  • Engaging with system owners and stakeholders to uplift logging maturity and support ongoing capability improvements

Skills

SIEM engineering
SOC operations
Detection engineering
Log onboarding
Stakeholder engagement

Tools

Google SecOps
Chronicle
BindPlane

Job description

Description

Who we are

Countersight is a specialist cybersecurity company delivering security research, capability development and consulting services to clients within government and across the private sector. We are independent, Australian, and Canberra-based but with the flexibility to operate Australia-wide.

Our team works on interesting problems across the entire technology stack, from embedded systems to web and mobile applications, finding creative ways to deliver the capability our clients need.

The Role

Role Title: Senior Cyber Security Operations Analyst (SIEM / Detection Engineering)

Hours: Full-time

Salary: $100,000 – $180,000 (plus super) based on experience

Our Senior Cyber Security Operations Analysts work closely with client Cyber Security Operations Centres (CSOCs) to ensure SIEM and supporting security platforms are operational, optimised, and continuously improving.

This role is focused on hands‑on SIEM engineering and operations, including onboarding log sources, improving data quality, tuning detection content, and optimising platform performance and cost.

Working as an embedded subject matter expert within client environments, you will collaborate with infrastructure, cloud, application and business teams to ensure security telemetry is fit‑for‑purpose and supports effective detection and response outcomes.

Typical responsibilities include:

  • Monitoring and maintaining SIEM platform health, ensuring availability and fitness for use by SOC analysts
  • Onboarding and integrating log sources across network, endpoint, cloud and application environments
  • Improving log fidelity, structure, and consistency to maximise detection effectiveness
  • Monitoring and analysing log ingestion rates and trends
  • Identifying and implementing optimisation opportunities to improve performance and reduce storage/ingestion costs
  • Developing and tuning correlation rules, alerts, dashboards and reports to reduce false positives and improve detection coverage
  • Maintaining and enhancing SIEM integrations, including threat intelligence feeds and API‑based connections
  • Supporting incident response and remediation activities in collaboration with SOC teams
  • Developing and maintaining standard operating procedures for cyber security tooling
  • Engaging with system owners and stakeholders to uplift logging maturity and support ongoing capability improvements
What we are looking for

We are looking for experienced cyber security professionals with a strong background in SIEM, security operations, or detection engineering, particularly those who enjoy working at the intersection of security operations, data engineering, and platform optimisation.

Must-have
  • 3+ years’ hands‑on experience in SIEM engineering, SOC operations, or cyber security operations roles.
  • Strong experience onboarding, parsing, normalising, and structuring logs from diverse sources.
  • Experience designing, building, and maintaining SIEM content including correlation rules, dashboards, reports, alerts and detection logic.
  • Experience monitoring and managing log ingestion, data quality, and platform performance.
  • Ability to analyse ingestion trends and identify optimisation opportunities.
  • Strong stakeholder engagement and communication skills.
  • Australian Government security clearance (NV1 minimum) or the ability to maintain one.
Nice-to-have
  • Experience with Google SecOps, Chronicle, or similar SIEM platforms.
  • Experience with log forwarding and pipelines (e.g. Bindplane or equivalent).
  • Understanding of detection engineering practices and threat‑informed defence.
  • Familiarity with threat tactics, techniques and procedures (TTPs).
  • Experience supporting incident response and threat hunting.
  • Exposure to EDR, XDR, SOAR and related technologies.
  • Understanding of cloud platforms, APIs, and modern application architectures.
  • Familiarity with Australian Government environments and compliance frameworks.
Why work for Countersight

As a small company, we prioritise supporting our team and fostering a positive, flexible, and enjoyable work culture. Collaboration, continuous learning and the latitude to experiment are the heart of our approach.

Our main office is located a short walk from Braddon and some of Canberra’s most popular cafes, restaurants, breweries and coffee roasters, and is also convenient for public transport, including light rail.

Our work and client focus allows us to directly contribute to the security and success of our community, and we believe that security is the key ingredient in opening up the promise of technology.

We thrive on deep technical challenges and relish the opportunity to extend our knowledge and explore the limits of the technologies we work with.

We enjoy what we do, and we think you will too.

To be eligible to apply for this position you must meet the below eligibility criteria
  • Be an Australian Citizen.
  • Hold or be eligible to hold a NV1 security clearance (minimum).
  • Satisfy pre‑employment screening.
Application Procedure

Please provide a current resume along with a covering letter highlighting your relevant experience and any publicly available examples of your work.

Please feel free to get in touch with any questions you may have about this role via careers@countersight.co.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SIEM Operations & Detection Engineer
Senior SIEM Operations & Detection Engineer

Countersight • Canberra

On-site
AUD 100,000 - 180,000
Security Operations Engineer/ Analyst
Security Operations Engineer/ Analyst

Talent • Canberra

Hybrid
AUD 120,000 - 180,000
Cyber Security Engineer - Microsoft Sentinel & SIEM
Cyber Security Engineer - Microsoft Sentinel & SIEM

Balance Recruitment • Council of the City of Sydney

On-site
AUD 120,000 - 180,000
Cyber Security Operations Engineer
Cyber Security Operations Engineer

Compas • Canberra

Hybrid
AUD 120,000 - 160,000
Security Analyst
Security Analyst

Decipher Bureau • City of Brisbane

Hybrid
AUD 120,000 - 130,000
Hybrid work model
Paid professional development
Bonuses
+2
Cyber Security Engineer
Cyber Security Engineer

Macquarie Technology Group • Canberra

On-site
AUD 90,000 - 130,000
SIEM Engineer- AU Citizen with Security Clearance
SIEM Engineer- AU Citizen with Security Clearance

Accenture • City of Melbourne

On-site
AUD 120,000 - 150,000
Security Analyst
Security Analyst

CyberCX • City of Melbourne

Hybrid
AUD 70,000 - 110,000
Flexible hybrid working
Retail & lifestyle discounts
SIEM Engineer- AU Citizen with Security Clearance
SIEM Engineer- AU Citizen with Security Clearance

Accenture • City of Brisbane

On-site
AUD 120,000 - 180,000
Parental leave – 18 weeks
Career development program
Flexible work arrangements
+1
SIEM Engineer- AU Citizen with Security Clearance
SIEM Engineer- AU Citizen with Security Clearance

Accenture Australia • Council of the City of Sydney

On-site
AUD 120,000 - 170,000
WORK180 Endorsed Employer