Security Engineer (SIEM)

Metrea

City of Brisbane

On-site

AUD 120,000 - 170,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Private Health Insurance
Annual Leave
Incentive Plan
Parental Leave
Life Insurance
Income Protection
Employee Assistance
Novated Car Leasing

Job summary

Metrea is seeking a skilled Security Engineer to join its Australian team in Brisbane. The role centers on designing, implementing, and refining security monitoring across a classified Azure environment with a focus on Microsoft Sentinel, Azure Log Analytics, and automation.

You will develop detection use cases, tune alerts, and lead threat hunting efforts while collaborating with security operations and IT teams to strengthen incident response and governance.

Qualifications

  • 5+ years in cyber security, security operations, detection engineering, or SIEM administration.
  • Experience managing enterprise-scale SIEM platforms and security monitoring services.
  • Experience improving security monitoring and incident response maturity.
  • Experience in government, defence, critical infrastructure, or regulated environments.
  • Knowledge of ISM/PSPF requirements is highly desirable.
  • Advanced knowledge of Azure Log Analytics and KQL.
  • Experience designing SIEM use cases, analytics, dashboards, and data connectors.
  • Familiarity with Microsoft Defender XDR and related security technologies.
  • Experience in cloud-first or hybrid environments.
  • Experience onboarding log sources from cloud, on-prem, and third-party sources.
  • Strong grasp of MITRE ATT&CK and corresponding detection strategies.
  • Understanding of SOAR principles and security automation.

Responsibilities

  • Administer and maintain Microsoft Sentinel and Azure monitoring platforms.
  • Design and improve SIEM detection use cases and analytics rules.
  • Perform alert tuning to reduce false positives.
  • Develop automated response playbooks using Azure Logic Apps.
  • Conduct threat hunting with Microsoft Sentinel and KQL.
  • Investigate and support response to security incidents and alerts.
  • Develop dashboards, workbooks, and operational security reporting.
  • Onboard new data sources to improve visibility across the estate.
  • Map detections to MITRE ATT&CK techniques.
  • Collaborate with infra and application teams to mitigate risks.
  • Support security audits and compliance activities.

Skills

Azure Log Analytics
KQL
SIEM
Threat Hunting
Security Monitoring
Cloud Security
SOAR
MITRE ATT&CK
Threat Intelligence
Automation / Playbooks

Education

Bachelor's degree in Cyber Security or related field

Tools

Microsoft Defender XDR
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud
Azure AD / Entra ID
Kusto Query Language (KQL)

Job description

Company Overview

Metrea delivers effects-as-a-service to national security partners across five domains and more than a dozen mission areas. These include airborne ISR, electronic warfare, secure communications, aerial refueling, special air missions, aerial firefighting, and advanced simulation. We own the whole stack: designing, building, and operating turnkey capabilities that give our partners decisive, asymmetric advantage against rapidly evolving threats.


Our operating model is built around three interlocking pillars. The Support Groups provide a global shared-service – spanning people, finance, platform, operations, legal, and engagement. This frees up our Core Groups, who develop and own mission capabilities end-to-end, to focus entirely on delivery. The Market Groups apply a regional lens, ensuring that our agile and adaptable capabilities remain aligned to the wicked problems that matter most to our partners across the Americas, EMEA, and Asia-Pacific.


At the heart of our model is a simple but powerful idea: be a true partner with skin in the game. Our partners need effects, not just equipment. By owning the full stack – from the lab to the field – we are able to drive a continuous cycle of innovation that keeps our partners ahead. It’s a fast-moving, intellectually demanding environment where talented people are given real responsibility, work on problems that matter, and contribute to an enterprise that is growing quickly and deliberately.


Headquartered in Washington, DC, with facilities across the United States, the United Kingdom, as well as Continental Europe and Asia-Pacific.


GroupOverview

Metrea is actively building its presence in Australia as part of a deliberate, globally coordinated expansion into the Asia-Pacific region. Our Asia-Pacific Market Group, headquartered in Brisbane with an additional office in Perth, is the enterprise’s dedicated regional interface — connecting Australia’s national security community with Metrea’s full suite of capabilities across three core domains: Aerospace, Electromagnetic & Cyber, and Digital & Synthetic. Metrea is now bringing that same depth of mission expertise and proven operating model to Australia.
Underpinning these capabilities is a global network of Support Groups spanning people, finance, platform, operations, legal, and engagement — ensuring that as we grow in Australia, we do so with the full weight of an established global enterprise behind us.
Metrea’s solutions are built for elegance: effective, efficient, and evolving — enabling our partners to scale capacity and achieve asymmetric advantage against rapidly evolving threats.


Position Summary

We are seeking a skilled and motivated Security Engineer to join our Australian team. This role is responsible for the design, documentation, implementation, optimisation, and ongoing management of security monitoring and detection capabilities across a classified Microsoft Azure environment.


The Security Engineer will play a key role in the administration and continuous improvement of the organisation’s Microsoft Sentinel SIEM platform, Azure Log Analytics workspaces, security automation, and detection engineering capabilities. Working closely with security operations, infrastructure and application teams, the role will focus on enhancing visibility, reducing risk, improving threat detection coverage, and supporting effective incident response outcomes.


The successful candidate will be responsible for SIEM architecture and configuration, use case development, alert tuning, threat hunting, playbook automation, and the investigation of security events and incidents. They will leverage the Microsoft security ecosystem to develop and maintain effective monitoring and response capabilities aligned with evolving cyber threats and business requirements.


This position requires strong technical expertise in cloud security, security monitoring, and detection engineering, combined with a proactive approach to continuous improvement and cyber defence.


What You’ll Do

Design, implement, and continuously improve security monitoring and detection capabilities within Microsoft Sentinel and Azure Log Analytics, ensuring effective visibility across the organisation’s technology environment. Develop and optimise SIEM use cases, analytics rules, and automated response playbooks while investigating security events and enhancing the organisation’s threat detection and incident response capabilities. Responsibilities fall into the following main areas:



  • Administer, configure, and maintain Microsoft Sentinel and supporting Azure security monitoring platforms.

  • Design, implement, and continuously improve SIEM detection use cases and analytics rules.

  • Perform alert tuning and optimisation to improve detection fidelity and reduce false positives.

  • Develop and maintain automated response playbooks using Azure Logic Apps and Sentinel automation capabilities.

  • Conduct threat hunting activities using Microsoft Sentinel, KQL, and threat intelligence sources.

  • Investigate, analyse, and support the response to cyber security incidents and alerts.

  • Develop and maintain security monitoring dashboards, workbooks, and operational reporting.

  • Integrate and onboard new data sources to improve visibility across the technology estate.

  • Map detections and use cases to MITRE ATT&CK techniques and threat-based frameworks.

  • Collaborate with infrastructure and application teams to address identified security risks.

  • Identify opportunities to improve detection coverage, monitoring effectiveness, and incident response processes.

  • Support security audits, compliance activities, and cyber security assessments as required.


What You Bring

The successful candidate will have the following key qualifications, skills, and experiences:



  • 5+ years of experience in cyber security, security operations, detection engineering, or SIEM administration roles.

  • Demonstrated experience managing enterprise-scale SIEM platforms and security monitoring services.

  • Experience leading technical initiatives related to security monitoring, detection improvement, and incident response maturity.

  • Experience working in government, Defence, critical infrastructure, or highly regulated environments.

  • Experience supporting and authorising systems operating at PROTECTED, or higher security classifications is highly desirable.

  • Demonstrated experience applying ISM and PSPF requirements within operational environments.

  • Advanced knowledge of Azure Log Analytics, Kusto Query Language (KQL), and data ingestion architecture.

  • Experience designing, implementing, and maintaining SIEM use cases, analytics rules, workbooks, watchlists, and data connectors.

  • Proven ability to analyse complex security events and translate findings into actionable improvements.

  • Familiarity with Microsoft security technologies including:

    • Microsoft Defender XDR

    • Microsoft Defender for Endpoint

    • Microsoft Defender for Identity

    • Microsoft Defender for Cloud

    • Microsoft Entra ID (Azure AD)



  • Experience working within cloud-first or hybrid enterprise environments.

  • Experience onboarding and integrating log sources from cloud, infrastructure, network, and third-party security platforms.

  • Strong understanding of cyber security monitoring, threat detection, incident response, and security operations practices.

  • Knowledge of common attack frameworks such as MITRE ATT&CK and their application to detection and threat hunting activities.

  • Understanding of security automation, orchestration, and response (SOAR) principles.

  • Experience creating dashboards, workbooks, reporting, and operational metrics for security monitoring and compliance.


AdditionalEligibilityQualifications


  • Bachelor or higher degree in Cyber Security, Information Technology, Computer Science, Information Systems, Engineering, or relevant industry experience


The below certifications are highly desirable.



  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)

  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)

  • Microsoft Certified: Azure Administrator Associate (AZ-104)

  • equivalent Azure administration experience may be considered

  • CompTIA Security+

  • CCSP, GCDA, GCIA or other related security certification would be highly regarded


Benefits


  • Private Health Insurance

  • Generous annual leave

  • Annual incentive plan

  • Paid parental leave

  • Life and disability insurance

  • Income Protection Insurance

  • Employee Assistance Program

  • Novated Car Leasing


Work Authorisation / Security Clearance

Ability to obtain and maintain an AGSVA Security Clearance.


Inclusion Statement

We are committed to building a team that reflects a broad range of backgrounds, experiences and perspectives. We welcome applications from all qualified candidates and make hiring decisions based on capability, potential and alignment with our values. If you require any adjustments throughout the recruitment process, please let us know.


Our Firmware

At Metrea, our single core value is Rooted in Humility, and our four cornerstone attributes are Entrepreneurial, Systematic, Discerning, and Over-Deliver. These form what we call our Teammate Firmware. Just like technical firmware connects software and hardware, our Firmware is the constant interface between our mission and our people. It defines how we show up, how we work together, and how we solve complex problems.


Our team Firmware creates a web-like, hyper-collaborative, dynamically hierarchical way of working that helps us adapt quickly, communicate openly, and distribute decision-making to where expertise actually lives. It enables groups to self-organize around hard problems, shift fluidly as priorities evolve, and operate with the trust, curiosity, and discipline required in a complex mission space. This foundation allows us to deliver elegant, effective solutions and uphold our purpose: protecting our precious inheritance.

"
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Systems Administrator
IT Systems Administrator

Metrea • City of Brisbane

On-site
AUD 85,000 - 120,000
Private Health Insurance
Generous Annual Leave
Annual incentive plan
+5
Cyber Governance, Risk and Compliance Specialist
Cyber Governance, Risk and Compliance Specialist

Metrea • City of Brisbane

On-site
AUD 110,000 - 170,000
Private Health Insurance
Generous Annual Leave
Annual incentive plan
+5
Software Engineering Manager
Software Engineering Manager

Metrea • City of Brisbane

On-site
AUD 140,000 - 190,000
Private Health Insurance
Generous PTO
Annual incentive plan
+5
Global Logistics and Customs Specialist
Global Logistics and Customs Specialist

Metrea • City of Brisbane

On-site
AUD 90,000 - 130,000
Private Health Insurance
Generous Annual Leave Entitlements
Annual incentive plan
+5
Software Engineer
Software Engineer

Metrea • Australia

On-site
AUD 90,000 - 120,000
Head of Flight Operations
Head of Flight Operations

Metrea • City of Brisbane

On-site
AUD 180,000 - 240,000
Private Health Insurance
Annual incentive plan
Paid parental leave
+3
Program Accountant
Program Accountant

Metrea • City of Brisbane

On-site
AUD 90,000 - 130,000
PrivateHealthInsurance
Generous annual leave
Annual incentive plan
+5
Supply Chain and Logistics Lead
Supply Chain and Logistics Lead

Metrea • City of Brisbane

On-site
AUD 130,000 - 180,000
Private Health Insurance
Annual incentive plan
Paid parental leave
+4
AIC & Supplier Development Specialist
AIC & Supplier Development Specialist

Metrea • City of Brisbane

On-site
AUD 120,000 - 180,000
Private Health Insurance
Generous Annual Leave
Annual Incentive Plan
+5
Senior Platform Engineer
Senior Platform Engineer

Metrea • Western Australia

On-site
AUD 120,000 - 150,000