n
- Own detection content across Microsoft Sentinel, SentinelOne and Splunk
n
- Author current detections against freshly mapped techniques
n
- Tune false positives and improve detection precision
n
- Trace coverage gaps to missing log sources
n
- Pair with the SOC to ensure detection content works effectively in triage
n
- Design high-fidelity detections for subtle or evasive behaviours
n
- Write logic that ports cleanly across SIEMs
n
- Find root causes of noise in data and improve rule precision systematically
n
- Translate customer risk profiles into prioritized detection strategies
n
- Audit customer logging against intended coverage
n
- Map logging coverage to MITRE ATT&CK; and business risk
n
- Identify and communicate high-impact gaps
n
- Translate threat tradecraft and intelligence reporting into telemetry detections mapped to ATT&CK; techniques
n
- Perform SIEM-based event analysis and incident triage
n
- Coordinate security incidents and projects with internal and external stakeholders
n
- Work with threat hunters, SOC analysts and customer stakeholders remotely and onsite
n
- Mentor less experienced team members
n
n
Requirements
n
n
- At least 2 years of hands-on experience in detection engineering or a large-scale security operations practice
n
- Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk
n
- Proven record of reducing false positive rates
n
- Fluency across multiple query languages
n
- Ability to write efficient queries over large data sets
n
- Ability to quickly learn unfamiliar query languages
n
- Solid understanding of MITRE ATT&CK; and the cyber kill chain, and how both map to business risk
n
- Ability to document and explain technical detail clearly to technical and non-technical audiences
n
- Applicants must have the unrestricted right to work in Australia
n
- Visa sponsorship is not available
n
- Role is subject to state and federal police background checks
n
- Computer science qualification at certificate, diploma, bachelor's or master's level (bonus)
n
- Current certifications such as SC-200, Blue Team Level 1 or 2, SANS Incident Responder or GIAC GCDA (bonus)
n
n
Core Competencies
n
Demonstrates expertise in detection engineering, with a strong focus on building and tuning detection rules across Microsoft Sentinel, SentinelOne, and Splunk. Proficient in translating threat intelligence into actionable detections while ensuring alignment with MITRE ATT&CK; frameworks and business risk.
n
Highest-signal resume keywords
n
n
- Detection Engineering
n
- Microsoft Sentinel
n
- Splunk
n
- MITRE ATT&CK;
n
- Query Language Proficiency
n
n
Hard Skills
n
n
- Detection Rule Authoring
n
- False Positive Reduction
n
- Event Analysis
n
- Data Querying
n
- Incident Triage
n
n
Soft Skills
n
n
- Communication
n
- Mentoring
n
- Collaboration
n
n
Certifications & Qualifications
n
n
- SC-200
n
- Blue Team Level 1
n
- Blue Team Level 2
n
- SANS Incident Responder
n
- GIAC GCDA
n
n
Industry Keywords
n
n
- Cyber Kill Chain
n
- Security Operations
n
- Threat Intelligence
n
- Logging Coverage
n
- Risk Assessment
n
n
Tools & Technologies
n
n
- SentinelOne
n
- SIEM
n
- Telemetry Detections
n
📌 Detection Engineer (New South Wales)
🏢 Jobtailor
📍 New South Wales
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.