Detection Engineer — SIEM Rule Author & Threat Telemetry

Jobtailor

Sydney

On-site

AUD 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Jobtailor in Sydney, Australia is seeking a Detection Engineer to own detections across Microsoft Sentinel, SentinelOne and Splunk. You will translate threat intelligence into telemetry detections aligned with MITRE ATT&CK and map logging coverage to business risk.

You will write efficient queries, reduce false positives, document complex technical details for both technical and non-technical audiences, and mentor junior team members while coordinating with threat hunters and SOC analysts

Qualifications

  • At least 2 years of hands-on experience in detection engineering or a large-scale security operations practice.

Responsibilities

  • Own detection content across Microsoft Sentinel, SentinelOne and Splunk.

Skills

Detection Rule Authoring
False Positive Reduction
Event Analysis
Data Querying
Incident Triage

Education

Computer science degree (certificate/diploma/bachelor/master)
SC-200
Blue Team Level 1
Blue Team Level 2
SANS Incident Responder
GIAC GCDA

Tools

SentinelOne
SIEM
Telemetry Detections

Job description

Jobtailor in Sydney, Australia is seeking a Detection Engineer to own detections across Microsoft Sentinel, SentinelOne and Splunk. You will translate threat intelligence into telemetry detections aligned with MITRE ATT&CK and map logging coverage to business risk.

You will write efficient queries, reduce false positives, document complex technical details for both technical and non-technical audiences, and mentor junior team members while coordinating with threat hunters and SOC analysts

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Detection Engineer: SIEM Expert (Sentinel, Splunk)
Hybrid Detection Engineer: SIEM Expert (Sentinel, Splunk)

Orro Pty Ltd • Sydney

Hybrid
AUD 120,000 - 165,000
Public holiday swaps and flexible work
Paid volunteer leave (3 days/year)
Novated leasing
+3
Detection Engineer
Detection Engineer

Jobtailor • Sydney

On-site
AUD 110,000 - 170,000
Senior SOC Analyst: Threat Hunting & Incident Response
Senior SOC Analyst: Threat Hunting & Incident Response

Jobtailor • Sydney

On-site
AUD 90,000 - 130,000
Security Engineer — SIEM & Threat Detection (Azure Sentinel)
Security Engineer — SIEM & Threat Detection (Azure Sentinel)

Metrea • City of Brisbane

On-site
AUD 110,000 - 180,000
Private Health Insurance
Generous annual leave
Annual incentive plan
+5
Cyber Threat Detection Engineer
Cyber Threat Detection Engineer

Decipher Bureau • Sydney

Hybrid
AUD 120,000 - 180,000
Threat Detection Engineer — Enterprise-Scale Splunk
Threat Detection Engineer — Enterprise-Scale Splunk

Decipher Bureau • Sydney

Hybrid
AUD 120,000 - 180,000
SIEM Analyst (Splunk) with MITRE ATT&CK Focus
SIEM Analyst (Splunk) with MITRE ATT&CK Focus

TPG Telecom • Sydney

Hybrid
AUD 110,000 - 150,000
Flexible hybrid work
Stay Connected Mobile plan
Stay Connected NBN plan
+3
Senior Detection Engineer, SOC & Threat Hunting Lead
Senior Detection Engineer, SOC & Threat Hunting Lead

High Growth Ventures • City of Melbourne

On-site
AUD 140,000 - 190,000
Retail discounts
Health & wellbeing
Learning & growth
+1
Senior Cybersecurity Engineer: Threat Intel & IR Lead
Senior Cybersecurity Engineer: Threat Intel & IR Lead

Jobtailor • Sydney

On-site
AUD 110,000 - 150,000
Senior Security Operations Engineer - Hybrid Threat Detection
Senior Security Operations Engineer - Hybrid Threat Detection

GoSourcing • New South Wales

Hybrid
AUD 110,000 - 150,000