Turn this role into an interview — a resume and cover letter built around what this employer wants.
Powerdata Group Consulting is seeking an experienced Threat Detection Engineer to design and tune SIEM/EDR detections and SOAR playbooks. You will apply STRIDE and MITRE ATT&CK frameworks to identify detection gaps and drive incident response readiness.
The role requires five+ years in SOC/Threat Hunting with hands-on experience across Splunk, Sentinel, QRadar, and EDR platforms, plus scripting skills in Python and Bash. Remote-friendly in Canberra area under Baseline Clearance considerations.
Location: Canberra, Australian Capital Territory (ACT) (remote considered)
Security Clearance: Baseline Clearance
The RFQ specifically calls for experience in:
A strong candidate would typically have:
When preparing a candidate response, focus on evidence demonstrating:
1. Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
2. Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
3. Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
4. AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
5. Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.
1. Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
2. Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
3. EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
4. Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.