Senior Cyber Threat Analyst

Pinaka

Canberra

Hybrid

AUD 120,000 - 160,000

Full time

42 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Pinaka seeks a Senior Cyber Threat Analyst to lead detection engineering across SIEM/EDR platforms. You will develop and maintain use cases, threat models and automation to detect and respond to advanced threats in hybrid environments.

The role requires extensive security operations experience, strong collaboration with engineering teams, and the ability to translate threats into actionable monitoring. The successful candidate will work within a fast-paced government-focused team, contributing

Qualifications

  • Demonstrated experience developing detection content across enterprise SIEMs.
  • Experience implementing detections across SIEM, SOAR, and EDR with incident response playbooks.
  • Practical threat modelling using STRIDE, ATT&CK and related methodologies.
  • Experience monitoring AI-related security risks and deployments.
  • Minimum five years in cyber security operations with stakeholder engagement.
  • Experience developing or using Sigma detection rules.
  • Familiarity with AI security frameworks (NIST, ASD/ACSC, MITRE ATLAS).
  • Experience with EDR technologies (CrowdStrike, Defender for Endpoint, Carbon Black).
  • Proficiency in scripting (Python, Bash) for automation and security workflows.

Responsibilities

  • Develop detection content based on threat models and risks.
  • Create and tune detection rules for SIEM/EDR technologies.
  • Draft playbooks for alert validation and response.
  • Maintain threat models using STRIDE, ATT&CK and related methods.
  • Assess AI-related threats and implement monitoring controls.
  • Collaborate with architecture/engineering to implement monitoring.
  • Maintain threat intelligence integrations across SOC stack.
  • Provide incident response support as directed by incident manager.
  • Assist onboarding of new data sources for detections.
  • Contribute to intelligence production and reporting improvements.

Skills

Threat content development
SIEM/EDR expertise
Threat modelling
AI security monitoring
Cyber security operations
Sigma rules
AI security frameworks
EDR platforms
Automation & scripting

Tools

Splunk
Microsoft Sentinel
QRadar
Elastic
CrowdStrike
Microsoft Defender for Endpoint
Carbon Black
Python
Bash

Job description

Senior Cyber Threat Analyst
Australian citizenship required. Must be able to obtain Baseline security clearance.
Location: ACT (Hybrid).
What to Submit
  • A tailored resume in docx format
  • A one page (5000 character) summary response to the selection criteria below.
  • RFQ ID: LH-07702
  • Agency: Department of Industry, Science and Resources
  • Closing Date: Friday, 02 October 2026 – 11:59pm (Canberra time)
  • Initial Contract Duration: 12 months
  • Extension Term: 12 months
  • Number of Extensions: 2
  • Experience Level: Senior - APS6 equivalent
  • Security Clearance: Must be able to obtain Baseline security clearance
  • Location of Work: ACT
  • Working Arrangements: Hybrid. Flexible work is generally supported. Remote working arrangements may be considered on a case-by-case basis in consultation with the supervising manager, subject to business needs. Please indicate clearly in your response the candidates desired work location if outside ACT/Canberra.
  • Maximum Hours: 40 hours per week

Threat Detection Engineer develops and maintains the material required to detect threats and incidents across the SOC technology stack.
The Threat Detection Engineer (TDE) is responsible for the research, development, testing and maintenance of use case and detection rules. They are to co-ordinate with Cyber Defence Analysts in developing detection content for use in the SIEM, SOAR and EDR platforms.
As part of the detection engineering lifecycle the TDE is expected to work in an ITIL and Agile environment, developing process and engineering documentation. The TDE is also responsible for providing threat intelligence sharing to infrastructure and architecture teams in both Cloud and onpremise environments.

Key Duties and Responsibilities
  • Develop use cases based off threat models, system risks, vulnerabilities, intelligence, incident reports and industry frameworks
  • Develop the detection rule syntax associated with use cases within the SIEM and EDR technologies
  • Develop playbooks for alert validation by understanding the context in which the detection rule is designed
  • Develop and maintain threat models using industry recognised methodologies such as STRIDE, ATT&CK and attack path analysis to identify detection opportunities and coverage gaps.
  • Assess emerging threats associated with Artificial Intelligence (AI) platforms, services and agents, and develop detection content to identify AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity.
  • Collaborate with architecture and engineering teams to ensure threat modelling outcomes are translated into effective monitoring, detection and response capabilities.
  • Maintain the threat intelligence integrations across the SOC technology stack
  • Conduct in-depth research and analysis for new detection content
  • Collaborate with Cyber Defence Analysts for detection rule tuning
  • Assist with threat model development to inform the detection engineering strategy
  • Assist in the identification of content shortfalls across the detection engineering practice
  • Assist with incident response at that direction of the incident manager
  • Assist in the onboarding of new data sources to meet requirements of use cases
  • Provide evaluation and feedback necessary for improving intelligence production and reporting
  • Provide support to designated exercises, planning activities, and time sensitive operations
About the Team

The Chief Information Officer Division (CIO Division) is an exciting, fast-paced division that drives the digital agenda for the Department of Industry, Science and Resources. Leading the delivery of the department’s digital offerings, the CIO Division partners with business areas and stakeholders to:

  • Realise the digital policy objectives of the Department
  • Define the Departments digital landscape
  • Drive the innovation and transformation of its IT services
    The Cyber Security team is responsible for oversight and management of cyber security within the department. The team is made up of 4 streams including: Governance, Risk and Compliance, Security Operations Centre, Project Advisory and Assurance and Cyber Engagement.
About the Organisation

The Department of Industry, Science and Resources and our broader portfolio are integral to the Australian Government’s economic agenda. Our purpose is to help the government build a better future for all Australians through enabling a productive, resilient and sustainable economy, enriched by science and technology. We do this by:

  • Growing innovative & competitive businesses, industries and regions
  • Investing in science and technology
  • Strengthening the resources sector.
Selection Criteria

The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters.

  • Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
  • Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
  • Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
  • AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
  • Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.
  • Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
  • Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
  • EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
  • Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.
How you are paid...

You choose what's best for you.

  • PAYG through Pinaka
  • Third-party payroll
  • Self-employed (own ABN)
BETTER TOGETHER
  • Refer a friend - Earn $1/hr per successful referral as long as you both with us. Refer as many friends as you want; no caps.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka Technology Solutions Pty Ltd • Canberra

Hybrid
AUD 150,000 - 190,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Informatech Pty Ltd • Canberra

On-site
AUD 120,000 - 180,000
PD allowance
Training leave
Client exposure
+1
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

e2 Cyber • Canberra

On-site
AUD 120,000 - 150,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Emanate Technology • Canberra

On-site
AUD 90,000 - 130,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Client 1 • Canberra

Hybrid
AUD 140,000 - 190,000
Hybrid work arrangement
Senior Cyber Threat Analyst - SIEM
Senior Cyber Threat Analyst - SIEM

IT Alliance Australia • Canberra

Hybrid
AUD 110,000 - 160,000
Senior Cyber Threat Hunt Specialist
Senior Cyber Threat Hunt Specialist

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1
Senior Threat Hunt & Emulation Lead (SOC, Govt)
Senior Threat Hunt & Emulation Lead (SOC, Govt)

Client 1 • Canberra

On-site
AUD 150,000 - 190,000
Specialised cyber security environment
Exposure to advanced investigations
Leadership and mentoring
+1
Cyber Security Threat Engineer
Cyber Security Threat Engineer

The Network • Canberra

On-site
AUD 120,000 - 160,000
Cyber Security SOC Analyst
Cyber Security SOC Analyst

C4I Solutions Pty • Sydney

On-site
AUD 110,000 - 160,000
Long Service Leave
Health & wellbeing allowance
First year leave (5 days)
+6