Senior Threat Detection Engineer – Splunk / Sentinel / MDE

Hatchit Studios

Canberra

Hybrid

AUD 120,000 - 190,000

Full time

37 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Hatchit Studios is seeking an experienced Senior Cyber Threat Analyst / Threat Detection Engineer for a long-term labour hire engagement within a Federal Government Security Operations Centre. This hands-on role focuses on researching, developing, testing and maintaining detection use cases, rules and SIEM correlation logic across the SOC technology stack.

The environment centres on Splunk Cloud with SOAR, and includes Microsoft Sentinel and Defender for Endpoint.

Qualifications

  • 5+ years' experience in cyber security operations or threat detection engineering.
  • Hands-on in SIEM rule development and correlation logic.
  • Experience across at least two enterprise SIEM platforms (e.g., Splunk and Sentinel).
  • Strong Splunk hands-on experience.
  • Experience with SIEM, SOAR and EDR detections.
  • Experience with incident response automation.
  • Threat modelling experience (STRIDE, MITRE ATT&CK).

Responsibilities

  • Develop threat detection use cases from threat models and risks.
  • Develop and maintain SIEM correlation logic, detection rules and content.
  • Develop detections across SIEM, SOAR and EDR technologies.
  • Create playbooks for alert validation and incident response automation.
  • Maintain threat models (STRIDE, MITRE ATT&CK, attack path analysis).
  • Identify detection opportunities and monitoring coverage gaps.
  • Research emerging threats to create new detection content.
  • Assess AI-related security risks for platforms like Copilot/Azure AI.
  • Collaborate with defence analysts to test and tune rules.
  • Assist with incident response and onboarding new data sources.
  • Translate threat modelling outcomes to monitoring and response capabilities.

Skills

5+ years experience
SIEM rule development
Splunk
SOAR
EDR
Threat modelling
Python Bash scripting

Tools

Splunk
Microsoft Sentinel
Microsoft Defender for Endpoint
QRadar
Elastic
Sigma rules
CrowdStrike
Carbon Black

Job description

Senior Cyber Threat Analyst / Threat Detection Engineer – Splunk

Location: Canberra / Interstate candidates considered – Hybrid or remote arrangements subject to approval

Hours: Up to 40 hours per week

Security Requirement: Must be able to obtain Baseline Security Clearance

About the Opportunity

Hatchit Studios is seeking an experienced Senior Cyber Threat Analyst / Threat Detection Engineer for a long-term labour hire engagement within a Federal Government Security Operations Centre (SOC).

This is a hands-on threat detection engineering role focused on researching, developing, testing and maintaining detection use cases, rules and SIEM correlation logic across the SOC technology stack.

The environment primarily uses Splunk Cloud, with integrated SOAR capabilities, alongside Microsoft Sentinel for selected workloads and Microsoft Defender for Endpoint (MDE) for endpoint detection and response.

We are particularly interested in candidates with 5+ years' experience working within a cyber security operations centre and/or directly in threat detection engineering.

Key Responsibilities
  • Develop threat detection use cases based on threat models, system risks, vulnerabilities, threat intelligence, incidents and industry frameworks
  • Develop and maintain SIEM correlation logic, detection rules and detection content
  • Develop detections across SIEM, SOAR and EDR technologies
  • Develop playbooks for alert validation and support incident response automation
  • Develop and maintain threat models using recognised methodologies such as STRIDE, MITRE ATT&CK and attack path analysis
  • Identify detection opportunities and monitoring coverage gaps
  • Research and analyse emerging threats to develop new detection content
  • Assess emerging risks associated with AI platforms, services and agents
  • Develop detection content addressing AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity
  • Maintain threat intelligence integrations across the SOC technology stack
  • Collaborate with Cyber Defence Analysts to test, tune and improve detection rules
  • Assist with incident response and onboarding new security data sources
  • Work with architecture and engineering teams to translate threat modelling outcomes into effective monitoring, detection and response capabilities
Skills & Experience Required
  • 5+ years' experience in cyber security operations, SOC environments and/or threat detection engineering
  • Strong hands-on experience developing SIEM detection rules, use cases and correlation logic
  • Demonstrated detection engineering experience across at least two enterprise SIEM platforms, such as Splunk, Microsoft Sentinel, QRadar or Elastic
  • Strong Splunk experience is highly regarded given the target environment
  • Experience developing and implementing detections across SIEM, SOAR and EDR platforms
  • Experience with incident response automation and security playbook development
  • Practical threat modelling experience using STRIDE, PASTA, MITRE ATT&CK or similar methodologies
  • Strong understanding of the cyber threat intelligence lifecycle
  • Experience identifying and developing monitoring controls for AI-related security risks, ideally involving Microsoft Copilot, Azure AI or similar enterprise AI platforms
  • Strong communication, organisational and stakeholder engagement skills
Highly Desirable
  • Experience with Splunk Cloud
  • Experience with Microsoft Sentinel
  • Experience with Microsoft Defender for Endpoint (MDE)
  • Experience developing or using Sigma detection rules and translating detections between security platforms
  • Familiarity with AI security frameworks and guidance including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10
  • Experience with enterprise EDR technologies such as CrowdStrike or Carbon Black
  • Python and/or Bash scripting experience supporting detection engineering and security automation
  • Relevant cyber security certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent
Why Apply?
  • Initial 12-month contract with up to 24 months of extensions
  • Work within an established Security Operations Centre
  • Hands-on exposure to Splunk Cloud, Microsoft Sentinel and Microsoft Defender for Endpoint
  • Work on contemporary detection engineering, threat intelligence and AI security challenges
  • Hybrid working arrangements with interstate/remote candidates considered
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Informatech Pty Ltd • Australian Capital Territory

On-site
AUD 120,000 - 180,000
PD allowance
Training leave
Client exposure
+1
Threat Detection Engineer
Threat Detection Engineer

Whizdom • Canberra

Hybrid
AUD 120,000 - 170,000
Hybrid working arrangements
Senior Cyber Threat Analyst- Canberra-Hybrid
Senior Cyber Threat Analyst- Canberra-Hybrid

IT Alliance • Canberra

Hybrid
AUD 120,000 - 150,000
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Canberra, Australian Capital Territory, Australia Department of Industry, Science and Resources • Canberra

Hybrid
AUD 110,000 - 150,000
Senior Threat Detection Engineer: Splunk, Sentinel & MDE
Senior Threat Detection Engineer: Splunk, Sentinel & MDE

Hatchit Studios • Canberra

Hybrid
AUD 120,000 - 190,000
Senior Cyber Threat Analyst- Canberra-Hybrid
Senior Cyber Threat Analyst- Canberra-Hybrid

IT Alliance Australia • Canberra

Hybrid
AUD 120,000 - 160,000
Senior Cyber Threat Analyst - Siem
Senior Cyber Threat Analyst - Siem

It Alliance Australia • Canberra

Hybrid
AUD 110,000 - 140,000
Cyber Security Engineer
Cyber Security Engineer

Macquarie Technology Group • Canberra

On-site
AUD 90,000 - 130,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Client 1 • Canberra

Hybrid
AUD 140,000 - 190,000
Hybrid work arrangement