Senior Cyber Security Engineer – Detection and Response

Blackmores

Sydney

Hybrid

AUD 150,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Blackmores is seeking a Senior Cyber Security Engineer to lead the Detection & Response capability across endpoint, cloud, identity and network environments. The role is a senior individual-contributor position with technical leadership and collaboration with vendors and internal teams.

You will drive continuous improvement of alert quality, detection effectiveness and incident response, while supporting executive reporting and post-incident reviews.

Qualifications

  • 10+ years in security operations, detection engineering, incident response or cyber defense roles.
  • Strong experience with EDR and SIEM technologies.
  • Solid understanding of attacker techniques, MITRE ATT&CK, malware behaviours and security telemetry.
  • Experience with managed security providers and SOC environments.
  • Experience with Azure and Microsoft 365 security monitoring.

Responsibilities

  • Lead the Detection & Monitoring program across endpoint, cloud, identity and network environments.
  • Tune and optimise detection and monitoring capabilities.
  • Lead investigations and incident response activities for cyber security incidents.
  • Coordinate containment, eradication and recovery during incidents.
  • Provide technical leadership during major cyber incidents and post-incident reviews.
  • Collaborate with external SOC and managed security service providers to drive improvements.
  • Define monitoring, logging and alerting requirements for new technologies.

Skills

EDR technologies
Threat hunting
MITRE ATT&CK
Threat intelligence
Windows security
PowerShell
Python
KQL

Tools

Microsoft Defender for Endpoint
Microsoft Sentinel
SOAR platforms
Azure security

Job description

Senior Cyber Security Engineer – Detection and Response

Our vision is to connect 1 billion people to the healing power of nature. A wholly owned subsidiary of Kirin Holdings, Blackmores Group is a leading natural health company with proud Australian heritage. We operate across Asia-Pacific and Greater China, delivering high-quality, evidence-based health solutions that help people live healthier lives.

Join Blackmores Group and play a critical role in protecting a trusted health and wellbeing organisation during a period of significant business and technology transformation. As our Senior Cyber Security Engineer (12 months fixed term role), you will lead the technical evolution of our Detection and Response capability across endpoint, cloud, identity, network and operational environments.

As a senior member of our Cyber Security team, you'll act as the subject matter expert for Detection & Response, partnering with technology teams, projects, vendors and managed security providers to strengthen Blackmores' security posture and response capability.

What's in it for you?

Play a key role protecting a global organisation through a significant SAP transformation program

Lead and influence cyber detection and response capabilities across endpoint, cloud, identity and network environments

Work with the modern Microsoft technology security stack.

This role reports to the Head of Cyber Governance and Operations; we are open for this person to be based in Sydney, working out either from our Surry Hills or Warriewood offices or based in Victoria, working from our Braeside Manufacturing Site. This role will follow our flexible work arrangements of working at least 3 days per week from office and 2 days per week from home.

This is a senior individual-contributor role with technical leadership responsibility. The position does not currently have direct reports but will provide technical direction to internal teams, service providers and incident-response participants.

What will you be doing?

Detection & Monitoring

Lead the development, tuning and optimisation of Blackmores' detection and monitoring capabilities

Maintain and enhance detection use cases across EDR, SIEM, cloud, identity and network security platforms

Assess monitoring coverage, identify detection gaps and improve visibility across the environment

Lead onboarding of new log sources and monitoring capabilities

Drive continuous improvement of alert quality and detection effectiveness

Lead technical investigations and response activities for cyber security incidents

Coordinate containment, eradication and recovery activities

Provide technical leadership during major cyber incidents

Support executive reporting, lessons learned and post-incident reviews

Maintain incident response procedures, runbooks and playbooks

Threat Hunting & Cyber Analytics

Lead proactive threat hunting activities across enterprise environments

Analyse emerging threats and determine relevance to Blackmores

Improve detection logic based on threat intelligence, trends and findings

Identify opportunities to strengthen cyber resilience and response readiness

Provide cyber security SME input into projects, technology initiatives and transformation programs

Define monitoring, logging, alerting and response requirements for new technologies

Develop high-level Detection & Response integration requirements and designs

Ensure new platforms can be effectively monitored and supported by Cyber Security Operations

Lead operational engagement with external SOC and managed security service providers

Review service performance and drive continuous improvement initiatives

Provide technical validation and direction during investigations and incidents

Ensure outsourced services align with Blackmores' cyber security objectives

Process & Continuous Improvement

Contribute to cyber security standards, frameworks and operational procedures

Support audit, compliance and cyber governance activities

Maintain operational documentation and response processes

Drive initiatives that improve Detection & Response capability maturity

What We're Looking For?

Experience

10+ years' experience in security operations, detection engineering, incident response or cyber defence roles

Demonstrated experience leading cyber investigations and incident response activities

Strong experience with EDR and SIEM technologies

Solid understanding of attacker techniques, MITRE ATT&CK, malware behaviours and security telemetry

Experience working with managed security providers and SOC environments

Technical Skills

Experience with Microsoft Defender for Endpoint or similar EDR platforms

Experience with Microsoft Sentinel or comparable SIEM solutions

Understanding of threat hunting, log analysis and event correlation

Working knowledge of Windows, Linux and network security concepts

Familiarity with SOAR capabilities and security automation

Experience with Azure and Microsoft 365 security monitoring

Exposure to Operational Technology (OT) environments

Scripting capability using KQL, PowerShell or Python

Personal Attributes

Strong stakeholder engagement and influencing skills

Ability to communicate complex technical concepts in business language

Excellent problem-solving and decision-making capability

High levels of ownership, accountability and professional judgement

Calm, resilient and effective during high-pressure cyber incidents

At Blackmores, you'll join a purpose-led organisation committed to helping people take control of their wellbeing. You'll have the opportunity to make a real impact, contribute to meaningful business outcomes, and grow your career within a supportive and collaborative environment.

Agencies please note: this recruitment assignment is being managed directly by the Blackmores Talent Acquisition team. We will reach out to our preferred agency partners if required. Your respect for this process is appreciated.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Engineer - Detection & Response
Senior Cyber Security Engineer - Detection & Response

Blackmores Group • Sydney

Hybrid
AUD 150,000 - 190,000
Senior Cyber Security Engineer - Detection & Response (Hybrid)
Senior Cyber Security Engineer - Detection & Response (Hybrid)

Blackmores Group • Sydney

Hybrid
AUD 150,000 - 190,000
Senior Cyber Defence Engineer
Senior Cyber Defence Engineer

Peoplebank • North Sydney Council

On-site
AUD 120,000 - 150,000
Diverse and inclusive workplace
Collaborative team environment
Senior Cyber Threat Hunt Specialist
Senior Cyber Threat Hunt Specialist

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1
Senior Detection & Response Engineer
Senior Detection & Response Engineer

HBF Health Limited • Australia

Hybrid
AUD 160,000 - 200,000
Gold hospital insurance
Wellbeing days
Parental leave (18+ weeks)
+4
Lead Spec Cyber Detect & Response CT/OT
Lead Spec Cyber Detect & Response CT/OT

Transport for NSW • Sydney

On-site
AUD 180,000 - 240,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Emmbr • Sydney

Hybrid
AUD 120,000 - 180,000
Senior Threat Detection Engineer
Senior Threat Detection Engineer

Macquarie Group • Council of the City of Sydney

Hybrid
AUD 100,000 - 130,000
Wellbeing leave days
Paid parental leave
Paid volunteer leave
+1
Threat Detection Engineer
Threat Detection Engineer

Whizdom • Canberra

Hybrid
AUD 120,000 - 170,000
Hybrid working arrangements
Cyber Security Analyst
Cyber Security Analyst

Digital Native • City of Brisbane

Hybrid
AUD 150,000 - 170,000
Dental insurance
Employee discount
Free drinks
+4