You'll take ownership of the SIEM environment, driving detection engineering, use case development, and log source onboarding to strengthen the organisation's security monitoring and incident response capability. This is a hands-on engineering role within a broader security operations function.
Key responsibilities
- Administer, tune, and optimise the SIEM platform (Splunk) for performance and coverage
- Develop and maintain detection use cases, correlation rules, and alerting logic
- Onboard new log sources and ensure data quality and integrity across the environment
- Support threat hunting, incident response, and security analytics initiatives
- Integrate SIEM with SOAR and other security tooling where applicable
- Partner with SOC analysts and the broader security team to continuously mature detection capability
- Document use cases, playbooks,
and operational procedures to a high standard
About you
- Proven hands-on experience administering and engineering Splunk (or an equivalent SIEM platform)
- Strong background in detection engineering, threat hunting, or SOC operations
- Experience integrating SOAR and security automation highly regarded
- Relevant certifications (Splunk certifications, CompTIA CySA+, GIAC, CISSP, etc.) highly regarded
- Australian citizenship, permanent residency, or NZ citizenship required (security clearance eligibility)
- Robust stakeholder communication and documentation skills
How to apply
Click "Apply Now" or call us on 02 8999 8*** to know more.
📌 Splunk/SIEM Cyber Security Engineer (Sydney)
🏢 Torch Professional Services
📍 Sydney
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.