Cyber security specialist: MDR/MSIEM with options. (Brisbane)

Cyber security specialist: MDR/MSIEM with options. (Brisbane)

17 Sep
|
dotSec
|
Brisbane

17 Sep

dotSec

Brisbane

Technical Security Analyst dotSec · Brisbane · Full time

If you can look at an Entra ID sign-in log and tell the difference between a user on a new laptop and a replayed token, without pasting it into a chatbot first, then keep reading!

We run a 24x7 managed SIEM on ISO 27001 and PCI DSS-compliant infrastructure, using Splunk Enterprise Security for Australian clients, and we’ve been doing it for 15 years. We also conduct almost any kind of testing and assessment exercise you can think of, and our comprehensive GRC services span IRAP, 27001 and PCI DSS.

We’re looking for an independent, polite, experienced and collaborative expert to join our team of like-minded professionals.

What you will actually do

You'll be busy!

- Onboard messy client data sources that don't come with a tidy plugin or structure. Write the transforms yourself, normalise to CIM, and make the data useful to the SIEM.

- Write detection content in SPL from a blank page, map it to ATT&CK;, and tune correlation searches until the false positives stop without killing the information we need to see.

- Triage real notable events against our SLA. Decide whether an event is malicious and if so, escalate it, and be confident to defend your call.

- Keep Splunk running on Linux in AWS. Diagnose ingestion faults across CloudTrail, CrowdStrike Falcon, the M365 unified audit log and Entra ID.

- Get on the front foot and discover improvements. Help to run purple team test cases, find the gap where nothing fired, then close the gaps yourself.

- Review client Microsoft 365, Entra ID, Windows and AWS configurations against CIS Benchmarks and the Essential Eight, and write findings someone can act on straight away.

The details of your work will vary based on demand but an average week will look like: Roughly 50% managed SIEM and detection engineering, 35% configuration hardening and review, testing and assessment, threat hunting and purple team, 15% keeping our own ISO 27001 ISMS and related infrastructure in top notch condition.

The Microsoft part: It's important dotSec's own infrastructure (on prem and SaaS) runs on Linux and AWS but the buld of what we look at for our clients, the bulk of the telemetry we monitor, and most of the configurations we assess, are based on Microsoft tech. This is really important, so read this section properly.

You need to be able to read the logs and say what happened:

- Windows. Security event logs on Windows Server and Windows 11. Logon types and what they imply, privilege assignment, process creation, service and scheduled task installs, what a 4625 storm actually means… and when it means nothing.





- Active Directory. As an attack surface, not an org chart. Kerberos behaviour, delegation, replication, group membership changes, GPO and Bloodhound.

- Entra ID. Sign-in and audit logs, Conditional Access evaluation results, CAP reviews and improvements, authentication methods, device identity, risk detections. Enough to separate a genuine new device from token theft.

- Microsoft 365. The Unified Audit Log during a suspected compromise. Inbox rules and forwarding, BEC, mailbox delegation, OAuth consent grants, SharePoint and OneDrive file access, anonymous sharing links, bulk download.

- Azure. Activity logs, NSGs and flow logs, resource-level RBAC, AzureHound, Prowler, and Azure Lighthouse delegated access into client tenants.

Then the two steps that matter most:

- Confirm the shortcoming. How do you go and prove a control is missing, misconfigured or being bypassed. Not "the tool flagged it", but "I checked, here is the evidence, here is what it lets an attacker do, and here’s what we need to do to reduce the risk."

- Recommend the remediation. The specific setting, policy or configuration change, written so the client's Windows admin can action it without twenty ticket iterations for never-ending clarification.

On the LLM question, since it will come up

You can use AI/LLM tooling at dotSec in accordance with our policies. But first, you need to be able to show that you can do this kind of work unaided. Why? Because when a client is on the phone and looking for help because something is really going wrong, the critical thinking and evaluation of options has to come from you.

Think about it: If we could actually rely on an LLM to figure things out reliably, we wouldn't be hiring a human! But we can't, so we are!!

Our technical interview will be conducted on the basis that you won’t have access to an LLM; you'll agree to that in writing, so don’t continue with this ad if that thought makes you uneasy.

What else we are asking for

We care about what you have done yourself, not what your team did around you, and we want to know that you, personally, have:

- Onboarded a source that had no supported app and got it parsing properly.

- Written a search from scratch, not just run one someone else saved.





- Taken a noisy detection and made it quiet without making it useless, and can explain exactly what you changed.

- Investigated something suspicious and worked through to a defensible conclusion and written that conclusion down, and had it reviewed, accepted and actioned. Not just escalated a problem to a higher-tier support.

- Experience with and are comfortable using a Linux command line when something is broken and there is no runbook for it.

- Write script (Bash, PowerShell or Python) to avoid doing the boring part twice.

Between 2 to 4 years in IT or security, at least one of them hands-on in a SOC, MSSP or security engineering role. Splunk preferred. Real depth in Sentinel, Elastic or QRadar counts, and SPL is learnable if the fundamentals are there.

Note because it's important: The Microsoft knowledge outlined above is not learnable on the job at the pace we need it, so you’ll need to bring those skills to the table on day one.

Worth knowing before you apply

This is a Brisbane based job. There is an after-hours on-call roster, shared across the team. You get to do some WFH after you get through probation. There are no WFH long-weekends.

- You will report to the director. Architecture and SLA accountability sit with senior staff, and client deliverables are peer reviewed before release. We run a supporting and collaborative workplace so while you get room to make decisions, you won't end up left alone with them.

- Certifications are sponsored, and we’ll cover agreed costs and on-the-job study time. Splunk, AWS, CrowdStrike, SC-200, BSCP, ISO 27001.

- You must have, before you reply to this ad, the right to work in Australia, and you must be willing to undergo a background and criminal history check.

How to apply

Send your CV and a few paragraphs about one thing you built, broke or fixed yourself. A detection you wrote. An ingestion fault you chased down. A Windows or M365 finding you confirmed and got remediated. Tell us what was wrong, what you tried, and what worked.

And you should skip the tool and buzzwords lists; we have all those already!

Shortlisted candidates will be invited to take part in a technical interview exercise and write a one-page report: We will give you three configuration review findings, and you will turn them into risk-rated recommendations with a short executive summary. Then a technical interview where we go deep on what you have done.

If you got this far and started thinking about the last sign-in log you pulled apart, then apply!

We’d love to hear from you.

📌 Cyber security specialist: MDR/MSIEM with options. (Brisbane)
🏢 dotSec
📍 Brisbane

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber security specialist: mdr/msiem with options. (brisbane) / brisbane

Subscribe to this job alert:

Get the latest job offers by email for: cyber security specialist: mdr/msiem with options. (brisbane) / brisbane