Hybrid Detection Engineer: SIEM Expert (Sentinel, Splunk)

Orro Pty Ltd

Sydney

Hybrid

AUD 120,000 - 165,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Public holiday swaps and flexible work
Paid volunteer leave (3 days/year)
Novated leasing
Employee discounts
Wellbeing platform
Mentoring program

Job summary

Orro Pty Ltd is seeking a Detection Engineer for its Security Operations Centre. You will own detection content across Microsoft Sentinel, SentinelOne and Splunk, tune noise, and collaborate with threat hunters and SOC analysts both remotely and onsite.

The role bridges threat intel, engineering, and client-facing projects in a hybrid Australian environment. You will build detections, align to MITRE ATT&CK, and drive improvements in alert quality while maintaining strong documentation and

Qualifications

  • At least 2 years of hands-on experience in detection engineering or large-scale security operations.
  • Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk with reduced false positives.
  • Fluency across multiple query languages and writing efficient queries over large data sets.
  • Solid understanding of MITRE ATT&CK and how it maps to business risk.
  • Ability to document and explain technical detail clearly to technical and non-technical audiences.

Responsibilities

  • Design high-fidelity detections for subtle or evasive behaviors, balancing coverage against noise and cross-SIEM compatibility.
  • Tune high-volume rules by identifying root causes of noise and improving precision.
  • Translate customer risk profiles into a prioritized detection strategy.
  • Audit logging against intended coverage, map to MITRE ATT&CK and business risk, and flag gaps.
  • Convert threat intelligence into concrete telemetry checks mapped to ATT&CK techniques.
  • Perform SIEM-based event analysis and coordinate security incidents with stakeholders.

Skills

Detection engineering
Query languages
MITRE ATT&CK
Documentation

Education

Computer science qualification (certificate/diploma/bachelor/master)

Tools

Microsoft Sentinel
SentinelOne
Splunk

Job description

Orro Pty Ltd is seeking a Detection Engineer for its Security Operations Centre. You will own detection content across Microsoft Sentinel, SentinelOne and Splunk, tune noise, and collaborate with threat hunters and SOC analysts both remotely and onsite.

The role bridges threat intel, engineering, and client-facing projects in a hybrid Australian environment. You will build detections, align to MITRE ATT&CK, and drive improvements in alert quality while maintaining strong documentation and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Cyber Security Engineer: SentinelOne & SIEM Expert
Hybrid Cyber Security Engineer: SentinelOne & SIEM Expert

Orro Group • Council of the City of Sydney

Hybrid
AUD 120,000 - 160,000
Hybrid work model
SentinelOne Cyber Security Engineer - Hybrid, Client-Facing
SentinelOne Cyber Security Engineer - Hybrid, Client-Facing

Orro Group • City of Brisbane

Hybrid
AUD 100,000 - 140,000
Hybrid work model
Competitive pay + benefits
Detection Engineer — SIEM Rule Author & Threat Telemetry
Detection Engineer — SIEM Rule Author & Threat Telemetry

Jobtailor • Sydney

On-site
AUD 110,000 - 170,000
SOC Analyst - Threat Hunting & Incident Response (Hybrid)
SOC Analyst - Threat Hunting & Incident Response (Hybrid)

Orro Pty Ltd • Sydney

Hybrid
AUD 110,000 - 160,000
Hybrid work model
Competitive base salary + super + ben­
Benefits package
SentinelOne Cyber Security Engineer | Hybrid & Customer-Facing
SentinelOne Cyber Security Engineer | Hybrid & Customer-Facing

Orro Group • City of Melbourne

Hybrid
AUD 90,000 - 130,000
Hybrid work model
Competitive base salary
Superannuation
+2
SOC Analyst: Threat Hunting & IR (Hybrid)
SOC Analyst: Threat Hunting & IR (Hybrid)

Orro Pty Ltd • Sydney

Hybrid
AUD 90,000 - 140,000
Soc Analyst - Threat Hunting & Incident Response (Hybrid)
Soc Analyst - Threat Hunting & Incident Response (Hybrid)

Orro Pty Ltd • Sydney

Hybrid
AUD 90,000 - 140,000
Senior Security Operations Engineer - Hybrid Threat Detection
Senior Security Operations Engineer - Hybrid Threat Detection

GoSourcing • New South Wales

Hybrid
AUD 110,000 - 150,000
Detection Engineer
Detection Engineer

Jobtailor • Sydney

On-site
AUD 110,000 - 170,000
Cyber Threat Detection Engineer
Cyber Threat Detection Engineer

Decipher Bureau • Sydney

Hybrid
AUD 120,000 - 180,000