Senior Cyber Threat Analyst - Siem

It Alliance Australia

Canberra

Hybrid

AUD 110,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

It Alliance Australia seeks a Senior Cyber Threat Analyst - SIEM for a Federal Government client in Canberra. This APS6, full-time 3-year contract (12 months with 24 months extension) offers hybrid working. Baseline security clearance is required; tentative start 17 Oct 2026. You will develop detections across SIEM/EDR/SOAR and coordinate with Cyber Defence Analysts.

The role emphasizes threat modelling, content development, and threat intelligence sharing in Cloud and on-prem environments.

Qualifications

  • Minimum five years' experience in cyber security operations.
  • Experience with SIEM, SOAR and EDR platforms.
  • Ability to develop and tune detections and playbooks.
  • Familiarity with threat modelling methodologies (STRIDE, ATT&CK).
  • Knowledge of ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10.

Responsibilities

  • Develop threat detection content and use cases from threat models, risks, and intelligence.
  • Create detection rule syntax for SIEM and EDR technologies.
  • Develop playbooks for alert validation and incident response.
  • Maintain threat models using STRIDE, ATT&CK and attack path analyses.
  • Collaborate with architecture/engineering to translate models into monitoring capabilities.
  • Maintain threat intelligence integrations across the SOC stack.
  • Conduct research for new detection content and improvements.
  • Assist in threat model development and content onboarding for new data sources.

Skills

Threat detection
Threat modelling
SIEM expertise
EDR platforms
SOAR
AI security monitoring
Automation and scripting
Python
Bash
Incident response
Threat intelligence
Communication & stakeholder engagement

Education

GIAC
SANS
CISSP
GCIA
GCIH

Tools

Splunk
Microsoft Sentinel
QRadar
Elastic
CrowdStrike
Microsoft Defender for Endpoint
Carbon Black

Job description

One of our Federal Government Clients is seeking to engage a Senior Cyber Threat Analyst - SIEM - APS6

Please check below all the job details:

  • Contract Duration: 03 Years (12 Months initially + 24 Months extension)
  • Work Location: Canberra (Hybrid Working available)
  • Eligibility: You must need to have Baseline Security Clearance
  • Tentative Start Date: 17th Oct 2026
  • Working Hours: 8 hours a day/ 40 hours a week

Key duties and responsibilities:

Threat Detection Engineer develops and maintains the material required to detect threats and incidents across the SOC technology stack.

The Threat Detection Engineer (TDE) is responsible for the research, development, testing and maintenance of use case and detection rules. They are to co-ordinate with Cyber Defence Analysts in developing detection content for use in the SIEM, SOAR and EDR platforms.

As part of the detection engineering lifecycle the TDE is expected to work in an ITIL and Agile environment, developing process and engineering documentation. The TDE is also responsible for providing threat intelligence sharing to infrastructure and architecture teams in both Cloud and onpremise environments.

Key duties and responsibilities:

This position is responsible for:

  • Develop use cases based off threat models, system risks, vulnerabilities, intelligence, incident reports and industry frameworks.
  • Develop the detection rule syntax associated with use cases within the SIEM and EDR technologies.
  • Develop playbooks for alert validation by understanding the context in which the detection rule is designed.
  • Develop and maintain threat models using industry recognised methodologies such as STRIDE, ATT&CK and attack path analysis to identify detection opportunities and coverage gaps.
  • Assess emerging threats associated with Artificial Intelligence (AI) platforms, services and agents, and develop detection content to identify AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity.
  • Collaborate with architecture and engineering teams to ensure threat modelling outcomes are translated into effective monitoring, detection and response capabilities.
  • Maintain the threat intelligence integrations across the SOC technology stack.
  • Conduct in-depth research and analysis for new detection content.
  • Collaborate with Cyber Defence Analysts for detection rule tuning.
  • Assist with threat model development to inform the detection engineering strategy.
  • Assist in the identification of content shortfalls across the detection engineering practice.
  • Assist with incident response at that direction of the incident manager.
  • Assist in the onboarding of new data sources to meet requirements of use cases.
  • Provide evaluation and feedback necessary for improving intelligence production and reporting.
  • Provide support to designated exercises, planning activities, and time sensitive operations.
  • Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
  • Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
  • Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
  • AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
  • Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.
  • Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
  • Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10.
  • Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
  • EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
  • Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Analyst- Canberra-Hybrid
Senior Cyber Threat Analyst- Canberra-Hybrid

IT Alliance Australia • Canberra

Hybrid
AUD 120,000 - 160,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Canberra, Australian Capital Territory, Australia Department of Industry, Science and Resources • Canberra

Hybrid
AUD 110,000 - 150,000
Threat Detection Engineer - SIEM/EDR (APS6, Hybrid)
Threat Detection Engineer - SIEM/EDR (APS6, Hybrid)

It Alliance Australia • Canberra

Hybrid
AUD 110,000 - 140,000
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka Technology Solutions Pty Ltd • Canberra

Hybrid
AUD 150,000 - 190,000
Cyber Security Threat Engineer
Cyber Security Threat Engineer

The Network Technology Recruitment • Canberra

On-site
AUD 140,000 - 170,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Informatech Pty Ltd • Australian Capital Territory

On-site
AUD 120,000 - 180,000
PD allowance
Training leave
Client exposure
+1
Cyber Threat Investigator
Cyber Threat Investigator

Velan Consulting Pty Ltd • Canberra

Hybrid
AUD 150,000 - 190,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Client 1 • Canberra

Hybrid
AUD 140,000 - 190,000
Hybrid work arrangement
Senior SIEM Threat Detection Engineer | Hybrid, Canberra
Senior SIEM Threat Detection Engineer | Hybrid, Canberra

It Alliance Australia • Canberra

Hybrid
AUD 110,000 - 140,000