Security Operations Lead

Secure Agility

Sydney

On-site

AUD 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Secure Agility is seeking a senior Security Operations Lead in Australia to own detection engineering, CrowdStrike Falcon, Next-Gen SIEM, threat exposure management and technical leadership across enterprise and government customers.

You will stay hands-on while driving automated response, threat detection content, and clear risk communication to customers and senior stakeholders.

Qualifications

  • Six or more years of experience across security operations, detection engineering, threat hunting, or incident response.
  • Experience with SIEM, EDR/XDR, and detection engineering is required.
  • Ability to translate vulnerability data into remediation priorities and communicate risk to customers.

Responsibilities

  • Develop, test, and improve detection use cases and content.
  • Lead complex investigations and support threat hunting activities.
  • Develop automation using Falcon Fusion, SOAR, and platform integrations.
  • Mentor SOC analysts and improve investigation standards and playbooks.
  • Present findings and risk recommendations to CIOs and CISOs.
  • Drive security operations reviews and technical workshops.

Skills

Security operations
Detection engineering
Threat hunting
Incident response
Customer-facing
Communication

Tools

CrowdStrike Falcon
SOAR
SIEM

Job description

About Secure Agility

Secure Agility is an Australian technology services and cybersecurity provider delivering managed security, cloud, infrastructure, networking and digital services to enterprise and government customers.

Our cybersecurity capability spans:

  • Managed Detection & Response
  • Security Operations
  • CrowdStrike Falcon
  • Detection Engineering
  • Vulnerability Management
  • Identity Security
  • SSE and SASE
  • Penetration Testing

We operate across complex customer environments and are continuing to invest heavily in our managed security and SOC capability.

Job Summary

Senior hands-on Security Operations Lead responsible for detection engineering, CrowdStrike Falcon, Next-Gen SIEM, threat exposure management and technical leadership across enterprise and government customers.

The Opportunity

We are looking for a senior Security Operations Lead who can combine deep technical security operations experience with customer-facing consulting capability.

This is not a traditional SOC Manager position where you step away from the technology.

You will remain hands-on while taking technical ownership of how we detect threats, engineer security content, automate response, identify exposure and communicate risk to customers.

You will help set the technical standard for our SOC and act as an escalation point for analysts and customers.

The ideal candidate is likely to have built their career within a global Systems Integrator, MSSP, MDR provider, MSP, cybersecurity consultancy or large enterprise SOC.

You will
  • Develop, test and improve detection use cases and content.
  • Improve detection coverage, signal quality and false-positive management.
  • Lead complex investigations and support threat-hunting activities.
  • Develop automation using Falcon Fusion, SOAR and platform integrations.
  • Help customers prioritise vulnerabilities and exposures based on genuine business risk.
  • Mentor SOC analysts and improve investigation standards and playbooks.
  • Lead technical workshops and security operations reviews.
  • Present technical findings and risk recommendations to senior stakeholders, including CIOs and CISOs.
  • Help shape our approach to emerging security risks, including AI-related exposure.
What you’ll bring

You will typically have six or more years’ experience across security operations, detection engineering, threat hunting, incident response or related cyber defence disciplines, including experience at a senior, L3, lead or principal level.

You will also bring:

  • Strong practical experience with SIEM, EDR/XDR and detection engineering.
  • Experience developing and tuning detections—not simply responding to alerts.
  • Strong incident investigation and threat-hunting capability.
  • Experience translating vulnerability and exposure data into clear remediation priorities.
  • Confidence working directly with customers and senior stakeholders.
  • Strong written communication, consulting and report-writing skills.
  • The ability to explain complex security issues clearly to technical and non-technical audiences.

Experience within an MSSP, MDR provider, systems integrator, MSP, cybersecurity consultancy or multi-customer SOC will be highly regarded.

Strong practical experience with CrowdStrike Falcon, particularly Falcon Next-Gen SIEM, EDR and Falcon Fusion, is important. CrowdStrike certifications such as CCFA, CCFR or CCSE will be highly regarded; however, certification support may be considered for exceptional candidates with strong practical experience.

Experience with technologies such as Netskope, ExtraHop, Proofpoint, Microsoft Sentinel, Splunk, Palo Alto Networks, Entra ID, AWS, Azure, SOAR, Python, PowerShell or API integrations will also be valued.

An Australian Government NV1 security clearance, or eligibility to obtain one, is highly regarded.

Why Join Secure Agility
  • Remain hands-on while leading and mentoring others.
  • Influence the future direction of our managed security capability.
  • Work across complex enterprise and government environments.
  • Build new detections, automation, processes and security services.
  • Work closely with CrowdStrike and other strategic security vendors.
  • Receive support for relevant technical development and certifications.
  • Work directly with senior technical and business leaders.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Baidam Pty Ltd • Sydney

Hybrid
AUD 120,000 - 180,000
Hybrid work across Sydney, Brisbane &/
Training & certifications
Career progression
Security Engineer
Security Engineer

Baidam Pty Ltd • City of Brisbane

Hybrid
AUD 140,000 - 210,000
Competitive salary package
Training & certification investment
Hybrid working across Australia
+1
Security Engineer
Security Engineer

Baidam Pty Ltd • City of Melbourne

Hybrid
AUD 120,000 - 180,000
Senior Cyber Threat Hunt Specialist
Senior Cyber Threat Hunt Specialist

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1
Senior Threat Hunt & Emulation Lead (SOC, Govt)
Senior Threat Hunt & Emulation Lead (SOC, Govt)

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
Mid Level Security Operation Analyst
Mid Level Security Operation Analyst

M&T Resources • City of Brisbane

On-site
AUD 90,000 - 130,000
6 Month contract
Brisbane CBD location
Enterprise security exposure
+1
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Decipher Bureau • Sydney

On-site
AUD 120,000 - 200,000
Cyber Security Architect
Cyber Security Architect

Macquarietechnologygroup • Sydney

On-site
AUD 180,000 - 260,000
Senior Security Operations Engineer | SIEM, XDR & Cloud
Senior Security Operations Engineer | SIEM, XDR & Cloud

c4isolutions • Sydney

On-site
AUD 150,000 - 190,000
Long Service Leave
Health & wellbeing allowance
First year leave (5 days)
+6