Detection Engineer

Orro Pty Ltd

Sydney

Hybrid

AUD 120,000 - 165,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Public holiday swaps and flexible work
Paid volunteer leave (3 days/year)
Novated leasing
Employee discounts
Wellbeing platform
Mentoring program

Job summary

Orro Pty Ltd is seeking a Detection Engineer for its Security Operations Centre. You will own detection content across Microsoft Sentinel, SentinelOne and Splunk, tune noise, and collaborate with threat hunters and SOC analysts both remotely and onsite.

The role bridges threat intel, engineering, and client-facing projects in a hybrid Australian environment. You will build detections, align to MITRE ATT&CK, and drive improvements in alert quality while maintaining strong documentation and

Qualifications

  • At least 2 years of hands-on experience in detection engineering or large-scale security operations.
  • Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk with reduced false positives.
  • Fluency across multiple query languages and writing efficient queries over large data sets.
  • Solid understanding of MITRE ATT&CK and how it maps to business risk.
  • Ability to document and explain technical detail clearly to technical and non-technical audiences.

Responsibilities

  • Design high-fidelity detections for subtle or evasive behaviors, balancing coverage against noise and cross-SIEM compatibility.
  • Tune high-volume rules by identifying root causes of noise and improving precision.
  • Translate customer risk profiles into a prioritized detection strategy.
  • Audit logging against intended coverage, map to MITRE ATT&CK and business risk, and flag gaps.
  • Convert threat intelligence into concrete telemetry checks mapped to ATT&CK techniques.
  • Perform SIEM-based event analysis and coordinate security incidents with stakeholders.

Skills

Detection engineering
Query languages
MITRE ATT&CK
Documentation

Education

Computer science qualification (certificate/diploma/bachelor/master)

Tools

Microsoft Sentinel
SentinelOne
Splunk

Job description

Sydney | Melbourne | Brisbane | Hybrid Work Model | Competitive base + super + benefits

Most detection engineering roles hand you a single SIEM and a backlog of tickets. This one hands you three platforms, a customer base that includes some of Australia's biggest brands, and a seat between the threat hunters and the SOC analysts who rely on what you build. As a Detection Engineer in our Security Operations Centre, you'll turn hunting findings and intelligence reporting into detection logic across Microsoft Sentinel, SentinelOne and Splunk, tune out the noise that costs analyst attention, and shape the structured context that lets AI make a confident first pass in triage. If you are ready to take on more, not just more of the same, this is the role.

About Orro

We're an Australian success story, now close to 500 people strong, delivering secure, end to end digital solutions across cloud, collaboration, cyber security, data services and network infrastructure, all backed by over 20 years of experience. Trusted by some of Australia's biggest brands, Orro leads the way in designing, building and operating digital infrastructure that delivers greater efficiency, agility, performance and resilience. Our solutions take the stress out of tech for more than 400 businesses and over 20 million Australians every single day.

Our mission? To create "future now" solutions making it faster, simpler and safer for people to access, store and share information, wherever they are and whoever they're with. But more than that, we know that real impact comes from connecting people, not just machines. That's why we take the time to understand our clients; how they work, what matters to them, and where they're headed so we can deliver not just what they need today, but what they'll need next.

With offices in Sydney, Melbourne, Canberra, Brisbane and Perth, and teams across New Zealand, the Philippines and the UK, Orro is known for delivering future ready solutions, backed by deep expertise, genuine human insight and lasting partnerships.

What You'll Be Doing

You'll own detection content across the platforms our customers run, whether that is Microsoft Sentinel, SentinelOne or Splunk. A typical week mixes authoring new detections against a freshly mapped technique, tuning down the false positives that consume analyst attention, tracing a coverage gap back to a missing log source, and pairing with the SOC to make sure the content you ship lands well in triage. You'll work closely with threat hunters, SOC analysts and customer stakeholders, both remotely and onsite, and you'll mentor less experienced members of the team along the way.

  • Design high fidelity detections for subtle or evasive behaviours, balancing coverage against noise and writing logic that ports cleanly across SIEMs

  • Tune the highest volume rules by finding the root cause of noise in the data, not just the rule, and improve precision systematically

  • Translate customer risk profiles into a prioritised detection strategy that closes the highest impact gaps first

  • Audit customer logging against intended coverage, map it to MITRE ATT&CK and business risk, and flag the gaps that matter most with the impact of each

  • Turn threat tradecraft and intelligence reporting into concrete things to look for in telemetry, mapped to ATT&CK techniques with reference

  • Perform SIEM based event analysis and incident triage, and coordinate security incidents and projects with internal and external stakeholders

What You'll Bring

The Essentials

  • At least 2 years of hands on experience in detection engineering or a large scale security operations practice

  • Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk, with a proven record of reducing false positive rates

  • Fluency across multiple query languages, writing efficient queries over large data sets and picking up unfamiliar languages quickly

  • Solid understanding of MITRE ATT&CK and the cyber kill chain, and how both map to business risk

  • Ability to document and explain technical detail clearly to technical and non technical audiences

Even if you don't tick every box, don't let that hold you back. If this sounds like your kind of challenge, we'd genuinely love to hear from you.

Bonus Points

  • A computer science qualification at certificate, diploma, bachelor's or master's level

  • Current certifications such as SC 200, Blue Team Level 1 or 2, SANS Incident Responder or GIAC GCDA

Why Orro?

At Orro, we're proud to support our people and the people who matter most to them in meaningful and inclusive ways. From public holiday swaps that embrace family and cultural diversity, to generous parental and caregiver leave, flexible work options, and company wide mentoring, we're here to help you thrive at every stage of life.

We also invest in the future through our Emerging Leaders Development Program, nurturing the next generation of talent from within. On top of that, you'll enjoy 3 days of paid volunteer leave each year, novated leasing, employee discounts, and full access to our wellbeing platform packed with expert fitness plans, nutrition tips, and tools to help you feel your best, inside and out.

Note: The role is subject to state and federal police background checks. Applicants must have the unrestricted right to work in Australia. Visa sponsorship is not available for this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

Orro Group • Council of the City of Sydney

Hybrid
AUD 120,000 - 160,000
Hybrid work model
Cyber Security Engineer
Cyber Security Engineer

Orro Group • City of Brisbane

Hybrid
AUD 100,000 - 140,000
Hybrid work model
Competitive pay + benefits
Cyber Security Engineer
Cyber Security Engineer

Orro Group • City of Melbourne

Hybrid
AUD 90,000 - 130,000
Hybrid work model
Competitive base salary
Superannuation
+2
SOC Analyst
SOC Analyst

Orro Group • City of Brisbane

On-site
AUD 90,000 - 130,000
Volunteer leave (3 days/year)
Novated leasing
Employee discounts
+1
SOC Analyst
SOC Analyst

Orro Group • Sydney

On-site
AUD 90,000 - 130,000
Paid volunteer leave
Novated leasing
Employee discounts
+1
SOC Analyst
SOC Analyst

Orro Group • City of Melbourne

On-site
AUD 90,000 - 130,000
Volunteer leave
Novated leasing
Employee discounts
+4
SOC Analyst
SOC Analyst

Orro Pty Ltd • Sydney

Hybrid
AUD 110,000 - 160,000
Hybrid work model
Competitive base salary + super + ben­
Benefits package
Systems Engineer
Systems Engineer

Orro Group • City of Melbourne

Hybrid
AUD 110,000 - 160,000
Hybrid work model
Superannuation
Benefits package
Systems Engineer
Systems Engineer

Orro Group • City of Brisbane

Hybrid
AUD 100,000 - 140,000
Flexible work options
3 days paid volunteer leave per year
Novated leasing
+3
Systems Engineer
Systems Engineer

Orro Group • Council of the City of Sydney

Hybrid
AUD 110,000 - 150,000
Hybrid work model
Volunteer leave
Wellbeing platform access
+1