Security Operations Engineer/ Analyst

Talent

Canberra

Hybrid

AUD 120,000 - 180,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Talent is seeking a Security Operations Engineer/Specialist to operate hands-on across detection engineering, investigation and incident response in an ACT hybrid environment. You will use Microsoft Defender and Sentinel to investigate events, tune detections and drive improvements in cloud and on-premise systems.

The role requires NV1 security clearance and collaboration with DevOps and security teams to strengthen detection coverage and resilience through tooling and automation.

Qualifications

  • Hands-on cyber security operations experience in enterprise or cloud environments.
  • Experience with SIEM/SOAR, preferably Microsoft Sentinel, including queries and dashboards.
  • Understanding of government cyber security frameworks such as ISM and Essential Eight.

Responsibilities

  • Develop and tune security monitoring, analytics rules, dashboards and detection use cases across SIEM/SOAR platforms.
  • Conduct proactive threat hunting and investigate security events from triage through containment, eradication, recovery and root cause analysis.
  • Build automation playbooks and scripts that improve response times, while supporting vulnerability management and remediation activities.
  • Work with DevOps, development and security teams to strengthen detection coverage, security controls and operational resilience.

Skills

Threat hunting
Incident response
Security monitoring

Tools

Microsoft Sentinel
KQL
Azure
SOAR

Job description

Security Operations Engineer / Specialist | Security Operations, Detection Engineering & Incident Response

  • Location: ACT (Hybrid)
  • Security Clearance: NV1 Cleared (Mandatory)
  • Contract Length: 12 Months + 2 x 12 Month Extensions (Based on the discretion of the Department)

About the Position:

This is a hands-on cyber security role.

The focus is on actively finding, understanding and responding to threats, while continuously improving how they are detected in the first place.

Working across cloud-hosted and enterprise environments, you'll use platforms such as Microsoft Sentinel and Defender to investigate security events, develop and tune detection use cases, conduct threat hunting and support incident response. You'll also work closely with development, DevOps and security teams so operational learnings can feed back into system design and security controls.

The distinction here is important. This isn't primarily a coordination or operational management position. The requirement is for someone who remains technically hands-on across detection engineering, investigation, response and security tooling.

What You'll Do:

  • Develop and tune security monitoring, analytics rules, dashboards and detection use cases across SIEM/SOAR platforms.
  • Conduct proactive threat hunting and investigate security events from initial triage through containment, eradication, recovery and root cause analysis.
  • Build automation playbooks and scripts that improve response times, while supporting vulnerability management and remediation activities.
  • Work with DevOps, development and security teams to strengthen detection coverage, security controls and operational resilience.

What We Are Looking For:

  • Strong hands-on cyber security operations experience across monitoring, threat analysis, investigation and incident response in enterprise or cloud environments.
  • Practical SIEM/SOAR capability, preferably Microsoft Sentinel, including KQL queries, analytics rules, alert tuning and dashboards.
  • Experience with security automation and scripting, together with cloud security monitoring and controls, preferably across Microsoft Azure.
  • Understanding of government cyber security frameworks and practices, including the ISM and Essential Eight.

Technology & Environment:

  • KQL, SIEM/SOAR & Security Automation
  • Microsoft Azure, Cloud Security & DevOps
  • Threat Hunting, Incident Response & Vulnerability Management

A Quick Note Before You Apply:

This role is unlikely to suit candidates whose recent experience has moved primarily into cyber coordination, governance or management without continued hands-on involvement in security operations.

The environment calls for someone comfortable getting into the detail: investigating alerts, querying telemetry, developing detections, hunting for threats and improving the tooling and controls around them.

Applicants must be Australian Citizens and hold a minimum NV1 Security Clearance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer - Microsoft Sentinel & SIEM
Cyber Security Engineer - Microsoft Sentinel & SIEM

Balance Recruitment • Council of the City of Sydney

On-site
AUD 120,000 - 180,000
Cyber Security Operations Engineer
Cyber Security Operations Engineer

Compas • Canberra

Hybrid
AUD 120,000 - 160,000
Cyber Security Operations Analyst (SIEM / Detection Engineering)
Cyber Security Operations Analyst (SIEM / Detection Engineering)

Countersight • Canberra

On-site
AUD 100,000 - 180,000
Senior Cyber Analyst
Senior Cyber Analyst

Compas PTY • Canberra

On-site
AUD 120,000 - 140,000
Security Engineer
Security Engineer

Sirius. • Council of the City of Sydney

On-site
AUD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Leidos Australia • City of Knox

On-site
AUD 100,000 - 130,000
Cyber Security Engineer
Cyber Security Engineer

HorizonOne Recruitment • Canberra

On-site
AUD 150,000 - 165,000
14% Super
Cyber Security Engineer
Cyber Security Engineer

Macquarie Technology Group • Canberra

On-site
AUD 90,000 - 130,000
Principal Cyber Threat Analyst
Principal Cyber Threat Analyst

Experis Australia • Canberra

Hybrid
AUD 100,000 - 140,000
Security Analyst
Security Analyst

CyberCX • City of Melbourne

Hybrid
AUD 70,000 - 110,000
Flexible hybrid working
Retail & lifestyle discounts