03 Aug
|
Accenture Australia
|
Canberra
03 Aug
Accenture Australia
Canberra
About Accenture
Accenture is a leading solutions and services company that helps the world’s leading enterprises reinvent by building their digital core and unleashing the power of AI to create value at speed across the enterprise. We bring together the talent of our approximately 786,000 people, our proprietary assets and platforms, and deep ecosystem relationships. Our strategy is to be the reinvention partner of choice for our clients and to be the most client‑focused, AI‑enabled, great place to work in the world.
About the Role
We are seeking an experienced SIEM Engineer to provide technical leadership and delivery accountability across enterprise SIEM, SOAR, log aggregation, threat detection, and monitoring capabilities. This role is accountable for the architecture, design, implementation, testing, and operationalisation of SIEM and SOAR platforms, working across security operations, infrastructure, application, threat intelligence, ITSM, and monitoring teams to deliver secure, scalable, and supportable outcomes.
What You’ll Be Responsible For
- Own the end‑to‑end technical delivery of SIEM and SOAR capabilities, including architecture, design, implementation, testing, and operational handover.
- Define and govern target‑state SIEM and SOAR architecture across log collection, aggregation, ingestion, parsing, enrichment, detection engineering, alerting, case management, and automation.
- Lead design and implementation of Splunk and Elastic platform capabilities, including data onboarding, index strategy, field mapping, dashboards, alerting, and operational controls.
- Define log source onboarding patterns for infrastructure, applications, security tools, cloud platforms, network devices, identity platforms, and endpoint security controls.
- Lead development of detection use cases, correlation rules, threat hunting capabilities,
and SOC monitoring content aligned to priority threats and operational requirements.
- Design and govern SOAR playbooks for triage, enrichment, escalation, containment, remediation support, evidence capture, and incident workflow automation.
- Oversee integration with ITSM systems for ticket creation, workflow management, incident escalation, service reporting, and operational traceability.
- Oversee integration of threat intelligence feeds and enrichment sources into detection, investigation, hunting, and response workflows.
- Manage integrations with upstream log sources and downstream monitoring, reporting, SOC, incident response, and governance systems.
- Provide technical leadership to SIEM developers, analysts, testers, and operational support teams.
- Manage technical risks, data quality issues, ingestion gaps, platform performance constraints, and operational readiness dependencies.
- Review and approve architecture artefacts, detailed designs, onboarding standards, use case documentation, playbooks, test evidence, and operational runbooks.
What We’re Looking For
- Demonstrated experience in SIEM engineering, security operations, security architecture, cyber detection engineering, or security platform delivery roles.
- Proven experience leading enterprise SIEM and SOAR implementations in complex environments.
- Deep understanding of log aggregation, ingestion pipelines, parsing, normalisation, enrichment, correlation, alerting, dashboards,
and operational monitoring.
- Strong experience designing detection use cases, SOC workflows, SOAR playbooks, threat intelligence integration, and threat hunting capabilities.
- 2–4 years’ experience in IAM / security engineering / related platform roles.
- 1–2+ years’ experience with Keycloak (or equivalent IdP), plus strong fundamentals in OIDC/OAuth2 and/or SAML.
- Familiarity with directory concepts and LDAP integration.
- Strong attention to detail and delivery discipline.
Security Clearance
Current Australian Government security clearance (Baseline, NV1 or higher), or eligibility and willingness to undergo security clearance. Current NV2 Security Clearance.
Work Arrangements
Must be willing to work onsite 5 days a week.
Benefits of working at Accenture
- 18 weeks paid parental leave
- Long & short‑term career break opportunities
- Structured career development program
- Local and international career opportunities
- Certified as a Family Inclusive Workplace
- Versatile Work Arrangements centered around Accenture’s Truly Human ethos
- Top 3 in last year’s Diversity & Inclusion Index
Equal Employment Opportunity Statement for Australia
Accenture is an EEO and affirmative action employer. We recognise that our people are multi‑dimensional, and we create a work environment where all people feel like they can bring their authentic selves to work, every day. Our unwavering commitment to inclusion and diversity unleashes innovation and creates a culture where everyone feels they have equal opportunity. All employment decisions shall be made without regard to age, disability status, ethnicity, gender, gender identity or expression, religion or sexual orientation, and we do not tolerate discrimination.
#J-18808-Ljbffr
📌 SIEM Engineer (Canberra)
🏢 Accenture Australia
📍 Canberra