Threat Detection Engineer

Whizdom

Canberra

Hybrid

AUD 120,000 - 170,000

Full time

27 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid working arrangements

Job summary

Whizdom in Canberra is seeking a Senior Threat Detection Engineer to develop and maintain detection content across SIEM, SOAR and EDR platforms. You will translate threat intelligence into effective monitoring, detection and response capabilities in a fast-paced, cyber-focused environment.

The role requires five or more years in cyber security operations, hands-on experience with major SIEM tools (Splunk, Microsoft Sentinel, IBM QRadar, Elastic) and strong threat modelling skills (STRIDE, MITRE

Qualifications

  • Five years or more in cyber security operations.
  • Proven in creating detection content across at least two enterprise SIEM platforms.
  • Experience in SIEM, SOAR and EDR detections.

Responsibilities

  • Develop detection use cases based on threat models and industry frameworks.
  • Maintain detection-rule syntax across SIEM and EDR technologies.
  • Create playbooks to support alert validation, incident response and automation.
  • Maintain threat models using STRIDE, MITRE ATT&CK and attack-path analysis.
  • Identify detection opportunities and coverage gaps.
  • Collaborate with architecture and engineering teams to translate threat-modelling outcomes into detection and response capabilities.
  • Maintain threat-intelligence integrations across the SOC stack.
  • Test, tune and improve detection rules with cyber defence analysts.
  • Support onboarding of new data sources for detection use cases.

Skills

Threat detection engineering
SIEM platforms
SOAR/EDR
Threat modelling
Python
Security documentation
Stakeholder engagement

Tools

Splunk
Microsoft Sentinel
IBM QRadar
Elastic

Job description

Threat Detection Engineer
About the Organisation

Our client is a Commonwealth Government organisation supporting Australia’s economic, scientific and technological priorities. The organisation delivers secure digital services and operates a fast-paced technology environment focused on innovation, transformation and cyber resilience.

This opportunity sits within an established cyber security function responsible for protecting enterprise systems and strengthening security capabilities across cloud and on-premises environments.

About the Role

We are seeking an experienced Senior Cyber Threat Analyst with strong threat detection engineering expertise to develop and maintain the content used to detect cyber threats and security incidents across the Security Operations Centre technology stack.

You will research, develop, test and maintain detection use cases and rules across Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), and Endpoint Detection and Response (EDR) platforms.

Working in Agile and ITIL environments, you will collaborate with cyber defence analysts, architects, engineers and infrastructure teams to translate threat intelligence and threat-modelling outcomes into effective monitoring, detection and response capabilities.

The Responsibilities
  • Developing detection use cases based on threat models, system risks, vulnerabilities, intelligence, incident reports and recognised industry frameworks.
  • Developing and maintaining detection-rule syntax across SIEM and EDR technologies.
  • Creating playbooks to support alert validation, incident response and security automation.
  • Developing and maintaining threat models using recognised methodologies such as STRIDE, MITRE ATT&CK and attack-path analysis.
  • Identifying detection opportunities, monitoring requirements and coverage gaps.
  • Assessing emerging threats associated with artificial intelligence platforms, services and agents.
  • Developing detection content for AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity.
  • Collaborating with architecture and engineering teams to translate threat-modelling outcomes into effective detection and response capabilities.
  • Maintaining threat-intelligence integrations across the Security Operations Centre technology stack.
  • Conducting detailed research and analysis to develop new detection content.
  • Working with cyber defence analysts to test, tune and improve detection rules.
  • Supporting the development of the organisation’s detection engineering strategy.
  • Identifying content gaps and improvement opportunities across the detection engineering practice.
  • Assisting with incident‑response activities under the direction of the incident manager.
  • Supporting the onboarding of new data sources required for detection use cases.
  • Providing feedback to improve threat‑intelligence production and reporting.
  • Supporting cyber security exercises, planning activities and time‑sensitive operations.
  • Developing process, engineering and technical documentation within ITIL and Agile delivery environments.
What You Will Bring
  • At least five years' experience in cyber security operations.
  • Demonstrated experience developing detection content across at least two enterprise SIEM platforms, such as:
    • o Splunk
    • o Microsoft Sentinel
    • o IBM QRadar
    • o Elastic
  • Experience developing and implementing detections across SIEM, SOAR and EDR platforms.
  • Experience developing incident‑response automation and security playbooks.
  • Practical threat‑modelling experience using recognised methodologies such as STRIDE, PASTA or MITRE ATT&CK.
  • The ability to translate threat‑modelling outcomes into detection, monitoring and response requirements.
  • A strong understanding of the cyber threat‑intelligence lifecycle.
  • Experience identifying, assessing and developing monitoring controls for AI‑related security risks.
  • Experience working with enterprise AI platforms, such as Microsoft Copilot or Azure AI.
  • Strong research, analysis and technical documentation skills.
  • Excellent organisational, communication and stakeholder‑engagement capabilities.
  • The ability to work effectively with cyber analysts, architects, engineers and infrastructure teams.
Desirable Skills and Qualifications
  • Experience developing or using Sigma detection rules.
  • The ability to translate detection rules between security platforms.
  • Knowledge of AI security frameworks and guidance, including:
    • o Australian Government cyber security guidance
    • o NIST guidance
    • o MITRE ATLAS
    • o OWASP Top 10 for Large Language Model Applications
  • Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint or Carbon Black.
  • Proficiency in Python or Bash for detection engineering and security automation.
  • Relevant cyber security certifications or qualifications, including:
    • o CISSP
    • o GCIA
    • o GCIH
    • o GIAC or SANS certifications
    • o Equivalent industry‑recognised cyber security qualifications.
What’s on Offer
  • Initial 12-month contract.
  • Up to two additional 12-month extension options.
  • Senior engagement at an APS6-equivalent level.
  • Hybrid working arrangements.
Security Requirements
  • Candidates must hold a Baseline security clearance.

Submissions close COB Thursday the 1st of October 2026.

Candidates will need to be willing to undergo pre-employment screening checks which may include, ID and work rights, security clearance verification, and any other client-requested checks.

We value diversity and welcome applications from Indigenous Australians, people from diverse cultural and linguistic backgrounds and people living with a disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka Technology Solutions Pty Ltd • Canberra

Hybrid
AUD 150,000 - 190,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Informatech Pty Ltd • Canberra

On-site
AUD 120,000 - 180,000
PD allowance
Training leave
Client exposure
+1
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Pinaka • Canberra

Hybrid
AUD 120,000 - 160,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Client 1 • Canberra

Hybrid
AUD 140,000 - 190,000
Hybrid work arrangement
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Emanate Technology • Canberra

On-site
AUD 90,000 - 130,000
Senior Cyber Threat Analyst - SIEM
Senior Cyber Threat Analyst - SIEM

IT Alliance Australia • Canberra

Hybrid
AUD 110,000 - 160,000
Cyber Security Threat Engineer
Cyber Security Threat Engineer

The Network • Canberra

On-site
AUD 120,000 - 160,000
Cyber Security Threat Engineer
Cyber Security Threat Engineer

The Network Technology Recruitment • Canberra

On-site
AUD 140,000 - 170,000
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

e2 Cyber • Canberra

On-site
AUD 120,000 - 150,000
Cyber Threat Detection Engineer
Cyber Threat Detection Engineer

Decipher Bureau • Sydney

Hybrid
AUD 120,000 - 180,000