Senior Threat Detection Engineer - SIEM/EDR & Threat Intel

XPT Software Australia

Canberra

On-site

AUD 120,000 - 160,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

XPT Software Australia is seeking a Threat Detection Engineer to develop and maintain detection content for the SOC stack. You will coordinate with Cyber Defence Analysts to create rules for SIEM, SOAR and EDR platforms and support threat intelligence sharing across cloud and on-prem environments.

The role requires researching, testing, and maintaining detection use cases, playbooks, and threat models, while contributing to process documentation in an ITIL and Agile setting.

Qualifications

  • Experience developing threat detection content.
  • Proficient with SIEM/EDR platforms.
  • Knowledge of ATT&CK/STRIDE methodologies.

Responsibilities

  • Develop use cases from threat models, risks, incidents and frameworks.
  • Create detection rule syntax for SIEM/EDR.
  • Develop playbooks for alert validation and context.
  • Maintain threat models using STRIDE/ATT&CK and attack path analysis.
  • Assess AI-related threats and content.
  • Collaborate with architecture to implement monitoring and detection.
  • Maintain threat intelligence integrations across SOC stack.
  • Conduct research for new detection content.
  • Tune detection rules with Cyber Defence Analysts.
  • Assist in threat model development and content gaps.
  • Support incident response as directed by incident manager.
  • Onboard new data sources to meet use-case requirements.
  • Provide feedback to improve intelligence production and reporting.
  • Support planned exercises and time-sensitive operations.

Skills

Threat modelling
SIEM/EDR
ATT&CK
STRIDE
Threat intel
Cloud/on‑prem
Playbooks

Tools

Detection rules

Job description

XPT Software Australia is seeking a Threat Detection Engineer to develop and maintain detection content for the SOC stack. You will coordinate with Cyber Defence Analysts to create rules for SIEM, SOAR and EDR platforms and support threat intelligence sharing across cloud and on-prem environments.

The role requires researching, testing, and maintaining detection use cases, playbooks, and threat models, while contributing to process documentation in an ITIL and Agile setting.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Detection Architect (SIEM/EDR)
Threat Detection Architect (SIEM/EDR)

e2 Cyber • Canberra

On-site
AUD 120,000 - 150,000
Senior Cyber Threat Analyst - Threat Detection Engineer
Senior Cyber Threat Analyst - Threat Detection Engineer

Softtest pays pty ltd • Canberra

On-site
AUD 120,000 - 180,000
Senior Threat Detection Engineer — SIEM/EDR & Playbooks
Senior Threat Detection Engineer — SIEM/EDR & Playbooks

Whizdom • Canberra

Hybrid
AUD 120,000 - 170,000
Hybrid working arrangements
Senior Threat Detection Engineer | SIEM/EDR/AI Security
Senior Threat Detection Engineer | SIEM/EDR/AI Security

Pinaka Technology Solutions Pty Ltd • Canberra

Hybrid
AUD 150,000 - 190,000
Threat Detection Engineer: SIEM/EDR Playbooks & AI Threats
Threat Detection Engineer: SIEM/EDR Playbooks & AI Threats

Emanate Technology • Canberra

On-site
AUD 90,000 - 130,000
Senior Threat Detection Engineer (Hybrid)
Senior Threat Detection Engineer (Hybrid)

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
SIEM Security Engineer - Hybrid Threat Detection
SIEM Security Engineer - Hybrid Threat Detection

Australia Post • City of Melbourne

Hybrid
AUD 120,000 - 160,000
Exclusive team member discounts and…
Health and wellbeing resources
Hybrid work model
Threat Detection Engineer
Threat Detection Engineer

Whizdom • Canberra

Hybrid
AUD 120,000 - 170,000
Hybrid working arrangements
Detection Engineer: SIEM, Threat Hunting & Triage (Hybrid)
Detection Engineer: SIEM, Threat Hunting & Triage (Hybrid)

Orro Group • City of Brisbane

Hybrid
AUD 120,000 - 170,000
Hybrid work model
Competitive base + super + benefits