Detection Engineer

Jobtailor

Sydney

On-site

AUD 110,000 - 170,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Jobtailor in Sydney, Australia is seeking a Detection Engineer to own detections across Microsoft Sentinel, SentinelOne and Splunk. You will translate threat intelligence into telemetry detections aligned with MITRE ATT&CK and map logging coverage to business risk.

You will write efficient queries, reduce false positives, document complex technical details for both technical and non-technical audiences, and mentor junior team members while coordinating with threat hunters and SOC analysts

Qualifications

  • At least 2 years of hands-on experience in detection engineering or a large-scale security operations practice.

Responsibilities

  • Own detection content across Microsoft Sentinel, SentinelOne and Splunk.

Skills

Detection Rule Authoring
False Positive Reduction
Event Analysis
Data Querying
Incident Triage

Education

Computer science degree (certificate/diploma/bachelor/master)
SC-200
Blue Team Level 1
Blue Team Level 2
SANS Incident Responder
GIAC GCDA

Tools

SentinelOne
SIEM
Telemetry Detections

Job description

  • Own detection content across Microsoft Sentinel, SentinelOne and Splunk
  • Author new detections against freshly mapped techniques
  • Tune false positives and improve detection precision
  • Trace coverage gaps to missing log sources
  • Pair with the SOC to ensure detection content works effectively in triage
  • Design high-fidelity detections for subtle or evasive behaviours
  • Write logic that ports cleanly across SIEMs
  • Find root causes of noise in data and improve rule precision systematically
  • Translate customer risk profiles into prioritized detection strategies
  • Audit customer logging against intended coverage
  • Map logging coverage to MITRE ATT&CK and business risk
  • Identify and communicate high-impact gaps
  • Translate threat tradecraft and intelligence reporting into telemetry detections mapped to ATT&CK techniques
  • Perform SIEM-based event analysis and incident triage
  • Coordinate security incidents and projects with internal and external stakeholders
  • Work with threat hunters, SOC analysts and customer stakeholders remotely and onsite
  • Mentor less experienced team members
Requirements
  • At least 2 years of hands-on experience in detection engineering or a large-scale security operations practice
  • Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk
  • Proven record of reducing false positive rates
  • Fluency across multiple query languages
  • Ability to write efficient queries over large data sets
  • Ability to quickly learn unfamiliar query languages
  • Solid understanding of MITRE ATT&CK and the cyber kill chain, and how both map to business risk
  • Ability to document and explain technical detail clearly to technical and non-technical audiences
  • Applicants must have the unrestricted right to work in Australia
  • Visa sponsorship is not available
  • Role is subject to state and federal police background checks
  • Computer science qualification at certificate, diploma, bachelor's or master's level (bonus)
  • Current certifications such as SC-200, Blue Team Level 1 or 2, SANS Incident Responder or GIAC GCDA (bonus)
Core Competencies

Demonstrates expertise in detection engineering, with a strong focus on building and tuning detection rules across Microsoft Sentinel, SentinelOne, and Splunk. Proficient in translating threat intelligence into actionable detections while ensuring alignment with MITRE ATT&CK frameworks and business risk.

Highest-signal resume keywords
  • Detection Engineering
  • Microsoft Sentinel
  • Splunk
  • MITRE ATT&CK
  • Query Language Proficiency
Hard Skills
  • Detection Rule Authoring
  • False Positive Reduction
  • Event Analysis
  • Data Querying
  • Incident Triage
Soft Skills
  • Communication
  • Mentoring
  • Collaboration
Certifications & Qualifications
  • SC-200
  • Blue Team Level 1
  • Blue Team Level 2
  • SANS Incident Responder
  • GIAC GCDA
Industry Keywords
  • Cyber Kill Chain
  • Security Operations
  • Threat Intelligence
  • Logging Coverage
  • Risk Assessment
Tools & Technologies
  • SentinelOne
  • SIEM
  • Telemetry Detections
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Detection Engineer
Cyber Threat Detection Engineer

Decipher Bureau • Sydney

Hybrid
AUD 120,000 - 180,000
Detection Engineer — SIEM Rule Author & Threat Telemetry
Detection Engineer — SIEM Rule Author & Threat Telemetry

Jobtailor • Sydney

On-site
AUD 110,000 - 170,000
SOC Analyst
SOC Analyst

Jobtailor • Sydney

On-site
AUD 90,000 - 130,000
Threat Detection Engineer — Enterprise-Scale Splunk
Threat Detection Engineer — Enterprise-Scale Splunk

Decipher Bureau • Sydney

Hybrid
AUD 120,000 - 180,000
Hybrid Detection Engineer: SIEM Expert (Sentinel, Splunk)
Hybrid Detection Engineer: SIEM Expert (Sentinel, Splunk)

Orro Pty Ltd • Sydney

Hybrid
AUD 120,000 - 165,000
Public holiday swaps and flexible work
Paid volunteer leave (3 days/year)
Novated leasing
+3
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Jobtailor • Sydney

On-site
AUD 110,000 - 150,000
Detection And Soar Engineer, Mandiant Consulting, Google Cloud
Detection And Soar Engineer, Mandiant Consulting, Google Cloud

Everi Pty • City of Melbourne

On-site
AUD 120,000 - 180,000
Senior Security Operations Analyst
Senior Security Operations Analyst

High Growth Ventures • City of Melbourne

On-site
AUD 140,000 - 190,000
Retail discounts
Health & wellbeing
Learning & growth
+1
Senior Cyber Threat Hunt Specialist
Senior Cyber Threat Hunt Specialist

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1
Associate MDR Cyber Security Analyst
Associate MDR Cyber Security Analyst

SentinelOne • City of Melbourne

On-site
AUD 70,000 - 110,000
RSUs
ESPP
Leave benefits
+6