29 Aug
|
Decipher Bureau
|
Southern Sydney
29 Aug
Decipher Bureau
Southern Sydney
Guess Who's back with a brand new hack
Calling all Threat Detection & Response Engineers, if you are looking for a bigger playground, more complex threats and the chance to build detections at genuine enterprise scale, this one’s worth a look.
You’ll be joining a global cyber defence team focused on engineering the detections that identify attacker behaviour across a large, complex enterprise environment.
The core of the role is hands-on detection engineering: researching threats, developing detection logic, tuning existing content and improving coverage across endpoint, identity, cloud and network telemetry.
What you’ll be doing
- Building and tuning detections within Splunk Enterprise Security
- Developing SPL queries and improving detection fidelity
- Translating MITRE ATT&CK; techniques into practical detection logic
- Threat hunting across endpoint, identity, cloud and network telemetry
- Investigating live incidents and turning findings into new or improved detections
- Building detection content using Git and YAML
- Working with detection-as-code and CI/CD pipelines
- Testing detections against simulated attack activity
- Supporting the evolution from Splunk to a new platform
- Collaborating with threat intelligence, incident response and engineering teams globally
What we’re looking for Ideally, you’ll already be working within detection engineering,
threat detection or an advanced security operations environment.
You’ll bring
- Strong Splunk and SPL experience
- Hands-on experience building and tuning security detections
- Strong understanding of MITRE ATT&CK;
- Experience investigating real-world security incidents
- Exposure to EDR, cloud, identity and network security telemetry
- Understanding of Git, YAML and version-controlled workflows
Experience with detection-as-code, CI/CD, SOAR, Python or security automation would be highly regarded. Most importantly, this role needs someone who understands both how attackers behave and how to engineer reliable detections to identify them .
Why consider it?
- Work on genuine detection engineering rather than alert monitoring
- Build detections at enterprise scale
- Work with Splunk while gaining exposure to new technology
- Develop detection-as-code and security automation experience
- Work closely with threat intelligence, threat hunting and incident response specialists
The role is Sydney-based with three days per week in the office. Occasional weekend support may be required for major incidents or upgrades, with time in lieu provided. If you’re already building rules, improving queries and looking for better ways to detect attacker behaviour, this is an prospect to make detection engineering the core of your role.
📌 Cyber Threat Detection Engineer (Southern Sydney)
🏢 Decipher Bureau
📍 Southern Sydney