17 Sep
|
Jobtailor
|
New South Wales
17 Sep
Jobtailor
New South Wales
Job Description
n
Own detection content across Microsoft Sentinel, SentinelOne and Splunk
n
Author new detections against freshly mapped techniques
n
Tune false positives and improve detection precision
n
Trace coverage gaps to missing log sources
n
Pair with the SOC to ensure detection content works effectively in triage
n
Design high-fidelity detections for subtle or evasive behaviours
n
Write logic that ports cleanly across SIEMs
n
Find root causes of noise in data and improve rule precision systematically
n
Translate customer risk profiles into prioritized detection strategies
n
Audit customer logging against intended coverage
n
Map logging coverage to MITRE ATT&CK; and business risk
n
Identify and communicate high-impact gaps
n
Translate threat tradecraft and intelligence reporting into telemetry detections mapped to ATT&CK; techniques
n
Perform SIEM-based event analysis and incident triage
n
Coordinate security incidents and projects with internal and external stakeholders
n
Work with threat hunters, SOC analysts and customer stakeholders remotely and onsite
n
Mentor less experienced team members
n
n
Requirements
n
n
At least 2 years of hands-on experience in detection engineering or a large-scale security operations practice
n
Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk
n
Proven record of reducing false positive rates
n
Fluency across multiple query languages
n
Ability to write effective queries over large data sets
n
Ability to quickly learn unfamiliar query languages
n
Solid understanding of MITRE ATT&CK; and the cyber kill chain,
and how both map to business risk
n
Ability to document and explain technical detail clearly to technical and non-technical audiences
n
Applicants must have the unrestricted right to work in Australia
n
Visa sponsorship is not available
n
Role is subject to state and federal police background checks
n
Computer science qualification at certificate, diploma, bachelor's or master's level (bonus)
n
Current certifications such as SC-200, Blue Team Level 1 or 2, SANS Incident Responder or GIAC GCDA (bonus)
n
n
Core Competencies
n
Demonstrates expertise in detection engineering, with a strong focus on building and tuning detection rules across Microsoft Sentinel, SentinelOne, and Splunk. Proficient in translating threat intelligence into actionable detections while ensuring alignment with MITRE ATT&CK; frameworks and business risk.
n
Highest-signal resume keywords
n
n
Detection Engineering
n
Microsoft Sentinel
n
Splunk
n
MITRE ATT&CK;
n
Query Language Proficiency
n
n
Hard Skills
n
n
Detection Rule Authoring
n
False Positive Reduction
n
Event Analysis
n
Data Querying
n
Incident Triage
n
n
Soft Skills
n
n
Communication
n
Mentoring
n
Collaboration
n
n
Certifications & Qualifications
n
n
SC-200
n
Blue Team Level 1
n
Blue Team Level 2
n
SANS Incident Responder
n
GIAC GCDA
n
n
Industry Keywords
n
n
Cyber Kill Chain
n
Security Operations
n
Threat Intelligence
n
Logging Coverage
n
Risk Assessment
n
n
Tools & Technologies
n
n
SentinelOne
n
SIEM
n
Telemetry Detections
n
📌 Detection Engineer (New South Wales)
🏢 Jobtailor
📍 New South Wales