- Own detection content across Microsoft Sentinel, SentinelOne and Splunk
- Author new detections against freshly mapped techniques
- Tune false positives and improve detection precision
- Trace coverage gaps to missing log sources
- Pair with the SOC to ensure detection content works effectively in triage
- Design high-fidelity detections for subtle or evasive behaviours
- Write logic that ports cleanly across SIEMs
- Find root causes of noise in data and improve rule precision systematically
- Translate customer risk profiles into prioritized detection strategies
- Audit customer logging against intended coverage
- Map logging coverage to MITRE ATT&CK; and business risk
- Identify and communicate high-impact gaps
- Translate threat tradecraft and intelligence reporting into telemetry detections mapped to ATT&CK; techniques
- Perform SIEM-based event analysis and incident triage
- Coordinate security incidents and projects with internal and external stakeholders
- Work with threat hunters, SOC analysts and customer stakeholders remotely and onsite
- Mentor less experienced team members
Requirements
- At least 2 years of hands-on experience in detection engineering or a large-scale security operations practice
- Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk
- Proven record of reducing false positive rates
- Fluency across multiple query languages
- Ability to write productive queries over large data sets
- Ability to quickly learn unfamiliar query languages
- Solid understanding of MITRE ATT&CK; and the cyber kill chain, and how both map to business risk
- Ability to document and explain technical detail clearly to technical and non-technical audiences
- Applicants must have the unrestricted right to work in Australia
- Visa sponsorship is not available
- Role is subject to state and federal police background checks
- Computer science qualification at certificate, diploma, bachelor's or master's level (bonus)
- Current certifications such as SC-200, Blue Team Level 1 or 2, SANS Incident Responder or GIAC GCDA (bonus)
Core Competencies
Demonstrates expertise in detection engineering, with a strong focus on building and tuning detection rules across Microsoft Sentinel, SentinelOne, and Splunk. Proficient in translating threat intelligence into actionable detections while ensuring alignment with MITRE ATT&CK; frameworks and business risk.
Highest-signal resume keywords
- Detection Engineering
- Microsoft Sentinel
- Splunk
- MITRE ATT&CK;
- Query Language Proficiency