Contract SOC Engineer? Or already deep in SIEM/SOAR and want to build instead of babysit alerts?
This one's a 12-month contract for someone who actually engineers detection logic, not just triages tickets. If you're the person on your team who gets asked to build the correlation rule rather than just respond to the alert, keep reading.
? What's in it for you:
- $1,200/day inc. super (or $1,200 + GST if you're on an ABN)
- 12-month contract, east coast Australia
- Genuine build-and-migrate work - not maintaining someone else's mess
- Exposure to one of the most active platforms in the detection engineering space right now
The role: You'll be working SOC modernisation projects, taking clients off legacy SIEM/SOAR setups and onto a unified detection and response platform. Think onboarding current log sources, building custom parsers, running workshops to turn client use cases into actual correlation logic, and engineering automation playbooks that replace manual analyst work.
You'll also tune endpoint policy and alert logic to cut noise without losing signal, then hand over clean "as-built" documentation once it's live.
This isn't an analyst gig watching a queue. It's engineering.
What you'll need:
- Solid SIEM/SOAR/XDR background - Cortex, Splunk, Microsoft Sentinel, CrowdStrike, Datadog, or QRadar all count (XSIAM, XDR, or XSOAR)
- Detection engineering chops - correlation rules, IOCs, BIOCs (client calls it "stitching")
- Comfortable with Python for scripting and custom integrations
- Confident running client workshops and translating technical detail for non-technical stakeholders
- NV1 clearance is a big plus if you want a shot at gov/defence work - AU Citizens at a min.
Sound like your lane? Send your CV to
[email protected] or give me a call on 0452 564 644 and we'll have a chat.
📌 Contract SOC Engineer - Detection Engineering | 12 Months | East Coast AU (Sydney)
🏢 Decipher Bureau
📍 Sydney