Detection Engineer (New South Wales)

Detection Engineer (New South Wales)

17 Sep
|
Jobtailor
|
New South Wales

17 Sep

Jobtailor

New South Wales

- Own detection content across Microsoft Sentinel, SentinelOne and Splunk
- Author new detections against freshly mapped techniques
- Tune false positives and improve detection precision
- Trace coverage gaps to missing log sources
- Pair with the SOC to ensure detection content works effectively in triage
- Design high-fidelity detections for subtle or evasive behaviours
- Write logic that ports cleanly across SIEMs
- Find root causes of noise in data and improve rule precision systematically
- Translate customer risk profiles into prioritized detection strategies
- Audit customer logging against intended coverage
- Map logging coverage to MITRE ATT&CK; and business risk
- Identify and communicate high-impact gaps
- Translate threat tradecraft and intelligence reporting into telemetry detections mapped to ATT&CK; techniques
- Perform SIEM-based event analysis and incident triage
- Coordinate security incidents and projects with internal and external stakeholders
- Work with threat hunters, SOC analysts and customer stakeholders remotely and onsite
- Mentor less experienced team members

Requirements

- At least 2 years of hands-on experience in detection engineering or a large-scale security operations practice
- Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk
- Proven record of reducing false positive rates
- Fluency across multiple query languages
- Ability to write productive queries over large data sets
- Ability to quickly learn unfamiliar query languages




- Solid understanding of MITRE ATT&CK; and the cyber kill chain, and how both map to business risk
- Ability to document and explain technical detail clearly to technical and non-technical audiences
- Applicants must have the unrestricted right to work in Australia
- Visa sponsorship is not available
- Role is subject to state and federal police background checks
- Computer science qualification at certificate, diploma, bachelor's or master's level (bonus)
- Current certifications such as SC-200, Blue Team Level 1 or 2, SANS Incident Responder or GIAC GCDA (bonus)

Core Competencies

Demonstrates expertise in detection engineering, with a strong focus on building and tuning detection rules across Microsoft Sentinel, SentinelOne, and Splunk. Proficient in translating threat intelligence into actionable detections while ensuring alignment with MITRE ATT&CK; frameworks and business risk.

Highest-signal resume keywords

- Detection Engineering
- Microsoft Sentinel
- Splunk
- MITRE ATT&CK;
- Query Language Proficiency

Hard Skills

- Detection Rule Authoring
- False Positive Reduction
- Event Analysis
- Data Querying
- Incident Triage

Soft Skills

- Communication
- Mentoring
- Collaboration

Certifications & Qualifications

- SC-200
- Blue Team Level 1
- Blue Team Level 2
- SANS Incident Responder
- GIAC GCDA

Industry Keywords

- Cyber Kill Chain
- Security Operations
- Threat Intelligence
- Logging Coverage
- Risk Assessment

Tools & Technologies

- SentinelOne
- SIEM
- Telemetry Detections

#J-18808-Ljbffr

📌 Detection Engineer (New South Wales)
🏢 Jobtailor
📍 New South Wales

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: detection engineer (new south wales) / new south wales

Subscribe to this job alert:

Get the latest job offers by email for: detection engineer (new south wales) / new south wales