SOC Detection Specialist

Powerdata Group Consulting

Canberra

Hybrid

AUD 120,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Powerdata Group Consulting is seeking an experienced Threat Detection Engineer to design and tune SIEM/EDR detections and SOAR playbooks. You will apply STRIDE and MITRE ATT&CK frameworks to identify detection gaps and drive incident response readiness.

The role requires five+ years in SOC/Threat Hunting with hands-on experience across Splunk, Sentinel, QRadar, and EDR platforms, plus scripting skills in Python and Bash. Remote-friendly in Canberra area under Baseline Clearance considerations.

Qualifications

  • Demonstrated experience developing detection content across at least two enterprise SIEM platforms.
  • Experience developing detections across SIEM, SOAR and EDR platforms, including IR automation.
  • Practical threat modelling using STRIDE, ATT&CK and related methodologies.
  • Experience integrating threat intelligence feeds into security operations and monitoring.
  • Minimum five years in cyber security operations, SOC, detection engineering or threat hunting.
  • Familiarity with AI security frameworks and monitoring for AI platforms.

Responsibilities

  • Develop SIEM use cases and detection content.
  • Tune detection rules and establish coverage.
  • Create and maintain SOAR playbooks.
  • Perform threat modelling using STRIDE and ATT&CK.
  • Integrate threat intelligence and monitor AI security risks.
  • Support incident response activities and analytics.
  • Monitor security of cloud and on-prem environments.
  • Collaborate with ITIL and Agile teams.

Skills

Threat detection engineering
SIEM use case development
Detection rule development
SOAR playbooks
STRIDE
MITRE ATT&CK
Threat intelligence integration
AI security monitoring
Incident response
Python scripting
Bash scripting
EDR & cloud/on-prem monitoring
Threat modelling
Cloud and on-premises security

Tools

Splunk
Microsoft Sentinel
QRadar
Elastic
CrowdStrike
Microsoft Defender for Endpoint
Carbon Black

Job description

Location: Canberra, Australian Capital Territory (ACT) (remote considered)

Security Clearance: Baseline Clearance

Threat Detection Engineering
  • SIEM use case development and detection content creation
  • Detection rule development and tuning
  • SOAR playbook development
  • STRIDE
  • MITRE ATT&CK
  • Attack path analysis
  • Detection coverage assessment
  • Gap analysis
  • Threat intelligence integration and management
  • Research into emerging threats
  • Intelligence sharing across infrastructure and architecture teams
Security Operations
  • SOC operations
  • ITIL and Agile environments
AI Security (Important New Requirement)

The RFQ specifically calls for experience in:

  • AI threat modelling
  • AI-related data leakage monitoring
  • Adversarial AI activity detection
  • Security monitoring of AI platforms, services and agents

A strong candidate would typically have:

  • 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations
Hands-on experience with platforms such as:
  • Microsoft Sentinel
  • Splunk
  • QRadar
  • CrowdStrike
  • Strong understanding of MITRE ATT&CK
  • Experience integrating threat intelligence feeds
  • Good documentation and stakeholder engagement skills
Evaluation Themes to Address in a Submission

When preparing a candidate response, focus on evidence demonstrating:

  • Development of threat detection use cases and rules.
  • SIEM/EDR content engineering and tuning.
  • Threat modelling expertise using STRIDE and ATT&CK.
  • Threat intelligence integration and analysis.
  • Experience supporting incident response activities.
  • Security monitoring of cloud and on-premises environments.
  • AI security and emerging threat detection capabilities.
  • Working within Agile and ITIL environments.
Requirements

1. Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).

2. Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.

3. Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.

4. AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.

5. Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.

1. Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.

2. Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.

3. EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.

4. Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Detection Specialist
SOC Detection Specialist

Powerdatagroup • Canberra

Hybrid
AUD 140,000 - 190,000
Threat Detection Engineer
Threat Detection Engineer

Everi Pty • Canberra

Hybrid
AUD 120,000 - 180,000
Hybrid work arrangement
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Canberra, Australian Capital Territory, Australia Department of Industry, Science and Resources • Canberra

On-site
AUD 110,000 - 150,000
Senior Cyber Threat Analyst- Canberra-Hybrid
Senior Cyber Threat Analyst- Canberra-Hybrid

IT Alliance • Canberra

Hybrid
AUD 120,000 - 150,000
Cyber Threat Investigator
Cyber Threat Investigator

Velan Consulting Pty Ltd • Canberra

Hybrid
AUD 150,000 - 190,000
Senior Cyber Threat Analyst- Canberra-Hybrid
Senior Cyber Threat Analyst- Canberra-Hybrid

IT Alliance Australia • Canberra

Hybrid
AUD 120,000 - 160,000
Senior Cyber Threat Analyst - Siem
Senior Cyber Threat Analyst - Siem

It Alliance Australia • Canberra

On-site
AUD 110,000 - 140,000
Remote SOC Detection Engineer - SIEM & AI Security
Remote SOC Detection Engineer - SIEM & AI Security

Powerdata Group Consulting • Canberra

Hybrid
AUD 120,000 - 150,000
Threat Detection Engineer
Threat Detection Engineer

Whizdom • Canberra

Hybrid
AUD 120,000 - 170,000
Hybrid working arrangements
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka • Canberra

On-site
AUD 120,000 - 160,000