SOC Detection Specialist

RiseMe

Canberra

On-site

AUD 150,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Socket.dev is seeking a Threat Detection Engineer to join our remote security team. The role covers SIEM/EDR content development, detection rule tuning, SOAR playbooks, and threat modelling across MITRE ATT&CK in distributed environments.

The ideal candidate has 5+ years in SOC or cyber security operations, hands-on experience with platforms such as Microsoft Sentinel, Splunk, QRadar, or CrowdStrike, and strong skills in threat intelligence integration and AI security monitoring.

Qualifications

  • Detect and tune SIEM/EDR content and use cases.
  • Develop detection rules and content across multiple platforms.
  • Model threats using STRIDE and MITRE ATT&CK.
  • Integrate threat intelligence feeds into monitoring.
  • Support incident response and drive security monitoring.
  • Work within Agile and ITIL environments.
  • AI security monitoring and threat detection capabilities.

Responsibilities

  • Development of threat detection use cases and rules across SIEM/EDR platforms.
  • SIEM/EDR content engineering and tuning.
  • Threat modelling with STRIDE and ATT&CK.
  • Threat intelligence integration and analysis.
  • Incident response support and security monitoring.
  • Security monitoring of cloud and on-premises environments.
  • AI security and emerging threat detection capabilities.
  • Work within Agile and ITIL environments.

Skills

Detection engineering
SIEM content
EDR detection
SOAR playbooks
Threat modelling
MITRE ATT&CK
Threat intelligence
Incident response
AI security
Agile & ITIL

Tools

Microsoft Sentinel
Microsoft Defender XDR
Splunk
QRadar
CrowdStrike
Cortex XDR

Job description

This is a remote position.

Location: Canberra, Australian Capital Territory (ACT)

Security Clearance: Baseline Clearance

Threat Detection Engineering
  • SIEM use case development and detection content creation
  • Detection rule development and tuning
  • EDR detection engineering
  • SOAR playbook development
  • Alert validation processes
Threat Modelling
  • STRIDE
  • MITRE ATT&CK
  • Attack path analysis
  • Detection coverage assessment
  • Gap analysis
Threat Intelligence
  • Threat intelligence integration and management
  • Research into emerging threats
  • Intelligence sharing across infrastructure and architecture teams
Security Operations
  • SOC operations
  • Incident response support
  • Detection engineering lifecycle management
  • Data source onboarding
  • ITIL and Agile environments
AI Security (Important New Requirement)

The RFQ specifically calls for experience in:

  • AI threat modelling
  • Prompt injection detection
  • AI model abuse detection
  • AI-related data leakage monitoring
  • Adversarial AI activity detection
  • Security monitoring of AI platforms, services and agents

A strong candidate would typically have:

  • 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations
  • Hands-on experience with platforms such as:
    • Microsoft Sentinel
    • Microsoft Defender XDR
    • Splunk
    • QRadar
    • CrowdStrike
    • Palo Alto Cortex XDR
  • Experience developing KQL, SPL, Sigma, YARA, or similar detection content
  • Strong understanding of MITRE ATT&CK
  • Experience integrating threat intelligence feeds
  • Good documentation and stakeholder engagement skills
Evaluation Themes to Address in a Submission

When preparing a candidate response, focus on evidence demonstrating:

  1. Development of threat detection use cases and rules.
  2. SIEM/EDR content engineering and tuning.
  3. Threat modelling expertise using STRIDE and ATT&CK.
  4. Threat intelligence integration and analysis.
  5. Experience supporting incident response activities.
  6. Security monitoring of cloud and on-premises environments.
  7. AI security and emerging threat detection capabilities.
  8. Working within Agile and ITIL environments.
Requirements
Essential criteria
  • 1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
  • 2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
  • 3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
  • 4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
  • 5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.
Desirable criteria
  • 1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
  • 2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
  • 3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
  • 4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.

LH-07702

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka Technology Solutions Pty Ltd • Canberra

Hybrid
AUD 150,000 - 190,000
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Canberra, Australian Capital Territory, Australia Department of Industry, Science and Resources • Canberra

Hybrid
AUD 110,000 - 150,000
Cyber Threat Investigator
Cyber Threat Investigator

Velan Consulting Pty Ltd • Canberra

Hybrid
AUD 120,000 - 190,000
Threat Detection Engineer
Threat Detection Engineer

Whizdom • Canberra

Hybrid
AUD 120,000 - 170,000
Hybrid working arrangements
Senior Cyber Threat Analyst - SIEM
Senior Cyber Threat Analyst - SIEM

IT Alliance Australia • Canberra

Hybrid
AUD 110,000 - 160,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka • Canberra

Hybrid
AUD 120,000 - 160,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Informatech Pty Ltd • Canberra

On-site
AUD 120,000 - 180,000
PD allowance
Training leave
Client exposure
+1
Cyber Security Threat Engineer
Cyber Security Threat Engineer

The Network Technology Recruitment • Canberra

On-site
AUD 140,000 - 170,000
Security Detection & Response II
Security Detection & Response II

Adecco Australia Group • Sydney

On-site
AUD 120,000 - 170,000