31 Aug
|
Decipher Bureau
|
New South Wales
31 Aug
Decipher Bureau
New South Wales
Job Description
Calling all Threat Detection & Response Engineers, if you are looking for a bigger playground, more complex threats and the chance to build detections at genuine enterprise scale, this one's worth a look.
n
You'll be joining a global cyber defence team focused on engineering the detections that identify attacker behaviour across a large, complex enterprise environment.
n
The core of the role is hands‐on detection engineering: researching threats, developing detection logic, tuning existing content and improving coverage across endpoint, identity, cloud and network telemetry.
n
What you'll be doing
n
n
- Building and tuning detections within Splunk Enterprise Security
n
- Developing SPL queries and improving detection fidelity
n
- Threat hunting across endpoint, identity, cloud and network telemetry
n
- Investigating live incidents and turning findings into current or improved detections
n
- Building detection content using Git and YAML
n
- Working with detection-as-code and CI/CD pipelines
n
- Testing detections against simulated attack activity
n
- Supporting the evolution from Splunk to a new platform
n
- Collaborating with threat intelligence, incident response and engineering teams globally
n
n
What we're looking for
n
Ideally, you'll already be working within detection engineering, threat detection or an advanced security operations environment.
n
You'll bring:
n
n
- Strong Splunk and SPL experience
n
- Hands‐on experience building and tuning security detections
n
- Strong understanding of MITRE ATT&CK;
n
- Experience investigating real-world security incidents
n
- Exposure to EDR, cloud, identity and network security telemetry
n
- Understanding of Git, YAML and version‐controlled workflows
n
n
Experience with detection-as-code, CI/CD, SOAR, Python or security automation would be highly regarded.
n
Most importantly, this role needs someone who understands both how attackers behave and how to engineer reliable detections to identify them.
n
Why consider it?
n
n
- Work on genuine detection engineering rather than alert monitoring
n
- Build detections at enterprise scale
n
- Work with Splunk while gaining exposure to new technology
n
- Develop detection-as-code and security automation experience
n
- Work closely with threat intelligence, threat hunting and incident response specialists
n
n
The role is Sydney-based with three days per week in the office. Occasional weekend support may be required for major incidents or upgrades, with time in lieu provided.
n
If you're already building rules, improving queries and looking for better ways to detect attacker behaviour, this is an opportunity to make detection engineering the core of your role.
📌 Cyber Threat Detection Engineer (New South Wales)
🏢 Decipher Bureau
📍 New South Wales