Role Title
Security Engineer (SIEM)
Location
Brisbane, QLD (hybrid)
Working Arrangement
Full-time
Clearance Required
Baseline AGSVA clearance or above.
Company Overview
Our client is a leading organisation supporting national security and defence-related missions through advanced cyber, digital, and technology capabilities. Operating within highly secure and complex environments, they are committed to delivering innovative solutions that enhance resilience, security, and operational effectiveness.
Job Description
We are seeking an experienced Security Engineer (SIEM) to join a growing cyber security team in Brisbane. This position will be responsible for the design, implementation, optimisation, and ongoing management of security monitoring and detection capabilities within a classified Microsoft Azure environment.
The successful candidate will play a key role in enhancing visibility across the enterprise, improving threat detection capabilities, reducing risk, and supporting effective incident response. Working closely with security operations, infrastructure, and application teams, you will contribute to the continuous improvement of cyber defence capabilities through SIEM engineering, threat hunting, security automation, and detection engineering.
Duties and Responsibilities
- Administer, configure, and maintain Microsoft Sentinel and supporting Azure security monitoring platforms.
- Design, implement, and optimise SIEM detection use cases and analytics rules.
- Tune alerts and detection logic to improve accuracy and reduce false positives.
- Develop and maintain automated response playbooks using Azure Logic Apps and Sentinel automation capabilities.
- Conduct threat hunting activities using Microsoft Sentinel, KQL, and threat intelligence sources.
- Investigate security alerts, incidents, and suspicious activity.
- Develop dashboards, workbooks, and operational reporting for stakeholders.
- Integrate and onboard new log sources across cloud, infrastructure, network, and third-party platforms.
- Map detections and use cases to MITRE ATT&CK techniques.
- Collaborate with infrastructure and application teams to address security risks.
- Improve monitoring coverage, incident response processes, and detection effectiveness.
- Support cyber security audits, compliance activities, and security assessments.
Education/Certifications Required
- Bachelor's degree in Cyber Security, Information Technology, Computer Science, Engineering, Information Systems, or equivalent industry experience.
Highly desirable certifications:
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- CompTIA Security+
- CCSP, GCIA, GCDA, or other relevant cyber security certifications
Knowledge/Skills Required
- Minimum 5 years' experience in cyber security, security operations, detection engineering, or SIEM administration.
- Strong experience administering enterprise-scale SIEM platforms.
- Hands‑on experience with Microsoft Sentinel, Azure Log Analytics, and Kusto Query Language (KQL).
- Knowledge of Microsoft Defender suite technologies and Microsoft Entra ID.
- Experience designing and maintaining analytics rules, workbooks, watchlists, data connectors, and monitoring dashboards.
- Strong understanding of cyber security monitoring, threat detection, incident response, and security operations.
- Experience with SOAR and security automation technologies.
- Familiarity with MITRE ATT&CK and threat hunting methodologies.
- Experience within Defence, Government, Critical Infrastructure, or highly regulated environments is highly regarded.
- Knowledge of Australian security frameworks including ISM and PSPF is desirable.
- Strong communication and stakeholder engagement skills.
Employment Benefits
- Private health insurance
- Generous annual leave entitlements
- Annual incentive programme
- Paid parental leave
- Life and disability insurance
- Income protection insurance
- Employee Assistance Programme
- Novated leasing options
Diversity and Inclusion
Our client is committed to creating an inclusive workplace where everyone can contribute and succeed. Applications are encouraged from individuals of all backgrounds, experiences, and perspectives. A fair, equitable, and accessible recruitment process is central to their values.
Veterans
Veterans, reservists, and transitioning Defence personnel are strongly encouraged to apply. Experience gained within military, intelligence, security, or operational environments is highly valued.