11 Aug
|
Australian Department of Parliamentary Services
|
Canberra
11 Aug
Australian Department of Parliamentary Services
Canberra
Australian Department of Parliamentary Services – Canberra ACT
The Department of Parliamentary Services (DPS) supports the operation of the Australian Parliament by providing secure, reliable and effective ICT services across Australian Parliament House (APH). Within the Information Services Division, the Cyber Security Branch protects DPS and APH systems, information and users from cyber security threats through governance, assurance, engineering, monitoring, detection and response activities.
The role sits within the Cyber Security Operations Centre (CSOC), which is responsible for monitoring, detecting and responding to cyber security events and incidents across DPS-supported APH environments. CSOC operates in a high-tempo and nationally significant context, supporting the security and continuity of parliamentary services by turning security telemetry, threat intelligence and operational findings into practical protective outcomes.
As the Assistant Director Detection Engineering and Technical CTI, you will lead and manage the CSOC detection lifecycle management process. This includes identifying detection gaps, developing and testing detection hypotheses, deploying and tuning analytics, maintaining technical cyber threat intelligence workflows, and ensuring detections remain current, effective and actionable as adversary tactics, techniques and procedures evolve.
The role works closely with CSOC analysts, cyber engineering, Cyber Hunt and Threat Emulation (CHATE), Cyber Intelligence and Assurance, system owners, service providers and senior stakeholders. It provides expert technical advice on detection coverage, logging requirements, telemetry gaps, alert quality, response guidance and practical uplift options that improve DPS’s ability to detect and respond to cyber security threats.
This is a unique opportunity to shape an intelligence-led detection engineering capability in a critical national institution. The successful candidate will help connect technical cyber threat intelligence with real-world monitoring and response.
The Opportunity
The Department of Parliamentary Services (DPS) supports the operation of the Australian Parliament by providing secure, reliable and effective ICT services across Australian Parliament House (APH). Within the Information Services Division, the Cyber Security Branch protects DPS and APH systems, information and users from cyber security threats through governance, assurance,
engineering, monitoring, detection and response activities.
The role sits within the Cyber Security Operations Centre (CSOC), which is responsible for monitoring, detecting and responding to cyber security events and incidents across DPS-supported APH environments. CSOC operates in a high-tempo and nationally significant context, supporting the security and continuity of parliamentary services by turning security telemetry, threat intelligence and operational findings into practical protective outcomes.
As the Assistant Director Detection Engineering and Technical CTI, you will lead and manage the CSOC detection lifecycle management process. This includes identifying detection gaps, developing and testing detection hypotheses, deploying and tuning analytics, maintaining technical cyber threat intelligence workflows, and ensuring detections remain current, effective and actionable as adversary tactics, techniques and procedures evolve.
The role works closely with CSOC analysts, cyber engineering, Cyber Hunt and Threat Emulation (CHATE), Cyber Intelligence and Assurance, system owners, service providers and senior stakeholders. It provides expert technical advice on detection coverage, logging requirements, telemetry gaps, alert quality, response guidance and practical uplift options that improve DPS’s ability to detect and respond to cyber security threats.
This is a unique opportunity to shape an intelligence-led detection engineering capability in a critical national institution. The successful candidate will help connect technical cyber threat intelligence with real-world monitoring and response.
Who we are looking for
We are looking for a technically strong, analytical and outcomes-focused cyber security professional who can translate intelligence, incident findings and adversary tradecraft into practical detection and response improvements. The ideal candidate will be comfortable working with ambiguity, prioritising competing operational demands, and producing explicit,
evidence-based advice for both technical and non-technical audiences.
The successful candidate will demonstrate:
- experience leading or contributing to detection engineering, detection lifecycle management, security monitoring or cyber security operations in a complex enterprise environment;
- the ability to convert cyber threat intelligence, adversary tactics, incident lessons, vulnerability information and threat hunting outcomes into practical detection logic, alerting, response guidance and measurable uplift;
- strong technical knowledge of security telemetry, logging, SIEM, SOAR, endpoint detection and response, cloud security monitoring and cyber threat intelligence platforms;
- sound analytical and problem-solving skills, including the ability to assess detection effectiveness, reduce false positives, identify missed detection opportunities and provide evidence-based recommendations;
- well-developed communication, stakeholder engagement and documentation skills, including the ability to brief technical and non-technical audiences and negotiate practical outcomes with system owners and service providers;
- a collaborative, curious and improvement-focused approach, with the judgement to balance operational urgency, cyber risk and business impact.
Relevant qualifications or demonstrated equivalent experience in cyber security, information technology, computer science, intelligence, security operations or a related discipline are required. Desirable experience includes working with SIEM and SOAR platforms, endpoint detection and response, cloud security monitoring, cyber threat intelligence platforms, MITRE ATT&CK;, structured threat intelligence standards and Australian Government cyber security frameworks including the ISM and PSPF.
Job Specific Requirements
- the successful applicant will be required to obtain and maintain a Negative Vetting 1 (Confidential/Highly Protected/Secret) security clearance.
At DPS, we are committed to building a diverse and inclusive workplace that ensures all our people can contribute to our shared purpose. We encourage applications from Aboriginal and Torres Strait Islander people, people with disability, people with caring responsibilities, people who identify as LGBTQIA+, people from cultural and linguistically diverse backgrounds, people who identify as neurodivergent, and mature aged people.
#J-18808-Ljbffr
📌 Cyber Threat Intelligence (CTI) Threat Engineer (Canberra)
🏢 Australian Department of Parliamentary Services
📍 Canberra