30 Aug
|
Decipher Bureau
|
New South Wales
30 Aug
Decipher Bureau
New South Wales
Calling all Threat Detection & Response Engineers, if you are looking for a bigger playground, more complex threats and the chance to build detections at genuine enterprise scale, this one's worth a look.
You'll be joining a global cyber defence team focused on engineering the detections that identify attacker behaviour across a large, complex enterprise setting.
The core of the role is hands‐on detection engineering: researching threats, developing detection logic, tuning existing content and improving coverage across endpoint, identity, cloud and network telemetry.
What you'll be doing
Building and tuning detections within Splunk Enterprise Security
Developing SPL queries and improving detection fidelity
Threat hunting across endpoint, identity, cloud and network telemetry
Investigating live incidents and turning findings into new or improved detections
Building detection content using Git and YAML
Working with detection-as-code and CI/CD pipelines
Testing detections against simulated attack activity
Supporting the evolution from Splunk to a current platform
Collaborating with threat intelligence, incident response and engineering teams globally
What we're looking for
Ideally, you'll already be working within detection engineering, threat detection or an advanced security operations environment.
You'll bring:
Strong Splunk and SPL experience
Hands‐on experience building and tuning security detections
Strong understanding of MITRE ATT&CK;
Experience investigating real-world security incidents
Exposure to EDR, cloud, identity and network security telemetry
Understanding of Git, YAML and version‐controlled workflows
Experience with detection-as-code, CI/CD, SOAR, Python or security automation would be highly regarded.
Most importantly, this role needs someone who understands both
how attackers behave and how to engineer reliable detections to identify them
.
Why consider it?
Work on genuine detection engineering rather than alert monitoring
Build detections at enterprise scale
Work with Splunk while gaining exposure to new technology
Develop detection-as-code and security automation experience
Work closely with threat intelligence, threat hunting and incident response specialists
The role is Sydney-based with three days per week in the office. Occasional weekend support may be required for major incidents or upgrades, with time in lieu provided.
If you're already building rules, improving queries and looking for better ways to detect attacker behaviour, this is an opportunity to make detection engineering the core of your role.
#J-*****-Ljbffr
📌 Cyber Threat Detection Engineer (New South Wales)
🏢 Decipher Bureau
📍 New South Wales